Overview
Join a Challenger
Full job description
Join a Challenger At EQ, we're remaking banking so every Canadian gets ahead, every day. Serving nearly 4 million Canadians from coast to coast, we offer a wide variety of financial services from banking and lending, to trust and credit union solutions.
We've been at this since 1970, challenging the conventions of traditional banking with smarter, faster, and more connected financial experiences.
What's kept us moving? The people behind it all: challengers who ask better questions, push back on old assumptions, and look for a better way forward.
If you're driven to help reshape how banking works for Canadians and the businesses that power our economy, this could be your next big opportunity.
We can’t wait to get to know you!
Design, implement, and operate security controls for AI platforms, generative AI solutions, AI agents, machine learning environments, and supporting cloud services. Partner with the AI Centre of Enablement, AI Engineering, Data Engineering, and Technology teams to embed security requirements into AI solutions across the delivery lifecycle. Build and automate AI security guardrails and policy enforcement across approved and emerging AI technologies, including enterprise copilots, AI coding assistants, model platforms, orchestration frameworks, agentic AI platforms, and third-party AI services. Support security assessment and enablement for platforms and frameworks such as Microsoft 365 Copilot, Copilot Studio, GitHub Copilot, Azure AI services, Enterprise Gemini, Cursor AI, OpenAI, Anthropic, LangChain, LangGraph, LangFuse, and future enterprise-approved AI technologies. Implement data protection controls for AI training, grounding, and inference in partnership with Data Governance and Privacy teams. Configure and maintain identity, access, and model access controls for AI platforms, APIs, agents, and integrations. Develop and maintain security standards, implementation patterns, and technical guidance for the secure adoption of AI technologies. Review solution designs and provide practical security guidance to address risks, control gaps, and regulatory requirements. Work as a collaborative security partner across Cyber, Architecture, Data, Engineering, AI Engineering, and business teams to enable secure delivery with minimal unnecessary friction. Perform and support adversarial testing of AI solutions, and work with engineering teams to prioritize and remediate security weaknesses. Develop security monitoring requirements and detection capabilities for AI-related security events, misuse, and unapproved AI usage. Assess security risk in the AI supply chain, including models, plug-ins, agents, and third-party AI services. Support governance, compliance, audit, and risk management activities related to AI, including the AI control library and AI intake and lifecycle processes. Create and maintain technical documentation, standards, procedures, and implementation guidance. Mentor engineers, architects, and delivery teams on practical AI security patterns, risks, and control implementation.
A college diploma or university degree in computer science, engineering, information security, or a related technical field is required. 7-9 years of experience in cyber security, software engineering, cloud engineering, or platform engineering, including a minimum of 4 years in a cyber security role. Expert level knowledge of AI and cloud security controls, sufficient to act as the internal subject matter expert others rely on for direction. Experience designing, implementing, and supporting security controls within cloud-native and enterprise technology environments. Strong understanding of AI technologies, including generative AI, large language models (LLMs), AI agents, retrieval-augmented generation, machine learning platforms, model integrations, and AI-enabled business solutions. Strong understanding of AI-specific security risks, including prompt injection and indirect prompt injection, sensitive information disclosure, data and model poisoning, insecure output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, and AI supply chain risk. Experience securing cloud platforms and services, preferably Microsoft Azure; experience with GCP or OCI is an asset. Experience securing one or more enterprise AI platforms, copilots, AI coding assistants, model providers, orchestration frameworks, or agentic AI technologies. Experience with Microsoft AI services, Enterprise Gemini, Cursor AI, OpenAI, Anthropic, LangChain, LangGraph, LangFuse, or similar platforms is considered an asset. Strong knowledge of application security, API security, identity and access management, secrets management, encryption, and secure software development practices. Experience developing automation, integrations, or security tooling using modern programming and scripting languages such as Python or PowerShell. Experience working with CI/CD pipelines, Infrastructure-as-Code, containers, and cloud-native technologies. Strong understanding of security monitoring, logging, detection, and incident response concepts. Working knowledge of AI and security frameworks, including NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST CSF, and CIS Controls. Ability to review technical designs and provide practical security guidance that balances risk management with business objectives. Curiosity and a continuous learning mindset, with the ability to stay current as AI security threats, controls, platforms, and regulatory expectations evolve. Pragmatic judgment with the ability to balance security risk, regulatory expectations, delivery timelines, and business value. Strong analytical and problem-solving skills with the ability to assess complex technical environments and identify effective solutions. Demonstrated ability to influence technical decisions without direct authority and help teams adopt secure patterns rather than simply identifying gaps. Relevant industry certifications such as CISSP, CCSP, GIAC, Microsoft Azure Security Engineer, Google Professional Cloud Security Engineer, or equivalent are considered an asset. Communication Skills: Moderately complex: provides technical information and guidance, conducts working sessions and design reviews, and influences groups of technical and business stakeholders across the bank. Produces clear documentation, standards, patterns, and implementation guides intended for reuse by other teams. Translates technical AI risk into business language for management, governance forums, and delivery partners. Collaborates as an embedded partner across Cyber, Architecture, Data, Engineering, AI Engineering, and business teams, using practical guidance and influence to enable secure outcomes. Coaches and mentors technical and non-technical stakeholders to improve enterprise understanding of AI security risks and controls. Engages with vendors and external partners to exchange technical information and validate security capabilities.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Eqbank (lever) →