Post Job Free
Sign in

Senior Cloud & AI Security Engineer

Location:
Ottawa, ON, Canada
Posted:
July 13, 2026

Contact this candidate

Resume:

PLACIDO MACOSSO

Ottawa, ON 613-***-**** *********@*****.*** https://github.com/mpucka

CONTRACT AVAILABILITY

Incorporated Canadian Security Consultant available for contract and consulting engagements. Holds an active Government of Canada Secret Security Clearance. SENIOR INFRASTRUCTURE SECURITY

ENGINEER AI SECURITY CLOUD

SECURITY DEVSECOPS

Security Engineer with 10+ years of experience designing, implementing, and operating security controls across cloud, infrastructure, Kubernetes, AI-enabled environments, and enterprise security operations. Proven expertise in cloud security architecture, DevSecOps, incident response, vulnerability management, security automation, AI security assessments, threat detection, and security engineering. Experienced securing AWS environments, Kubernetes platforms, CI/CD pipelines, and AI systems through risk-based security controls, automation, and continuous monitoring. AWS Certified Security – Specialty with extensive experience using Sentinel, QRadar, CrowdStrike, Cortex XDR, Tenable, Rapid7, Security Hub, GuardDuty, CloudTrail, AWS Config, AWS WAF, Python, and Bash. Strong knowledge of NIST CSF, NIST AI RMF, SOC 2, MITRE ATT&CK, security governance, and enterprise risk management. CORE COMPETENCIES

Infrastructure & Cloud Security

AWS Security • Kubernetes Security • Container Security • Infrastructure Security • Cloud Security Architecture • Cloud Security Engineering • Network Security • Zero Trust DevSecOps & Automation

DevSecOps • CI/CD Security • Security Pipeline Integration • Security Automation • Infrastructure Security Automation • Python • Bash • Secure SDLC AI Security

AI Security • AI Risk Assessments • AI Red Teaming • Adversarial Testing • Prompt Injection Testing • Secure AI Deployment • AI Governance • AI Threat Modeling Security Engineering

Security Controls Engineering • Security Architecture • Security Tooling • Detection Engineering

• Security Monitoring • Threat Detection • Security Hardening Incident Response & Security Operations

Incident Response • Threat Hunting • Alert Triage • Security Investigations • Root Cause Analysis • Digital Forensics • Security Analytics

Security Platforms

Microsoft Sentinel • IBM QRadar • CrowdStrike Falcon • Cortex XDR • Microsoft Defender • SIEM • EDR/XDR • Security Analytics

Vulnerability Management

Tenable • Rapid7 • Microsoft Defender Vulnerability Management • Vulnerability Assessments • Risk Prioritization • Remediation Management

Governance, Risk & Compliance

NIST CSF • NIST AI RMF • SOC 2 • MITRE ATT&CK • Risk Assessments • Security Audits • Security Policies • Security Documentation

PROFESSIONAL EXPERIENCE

CIRA Ottawa, ON

Senior Security Engineer Jan 2024 – Present

● Led the design and implementation of cloud governance and security controls across AWS environments, establishing security baselines, centralized monitoring, and compliance guardrails that enabled secure cloud adoption at scale.

● Architected and operationalized AWS security capabilities including Security Hub, GuardDuty, CloudTrail, AWS Config, IAM, and AWS WAF, improving threat detection, compliance visibility, and audit readiness across cloud workloads.

● Implemented Kubernetes security and container hardening controls, including RBAC governance, least-privilege access, workload protection, and configuration validation to reduce platform risk and strengthen cluster security posture.

● Embedded security controls throughout CI/CD pipelines by integrating automated vulnerability scanning, infrastructure-as-code validation, container security scanning, and deployment security gates, advancing DevSecOps maturity and reducing manual security reviews.

● Conducted cloud security architecture reviews, threat modeling exercises, and risk assessments for cloud and infrastructure initiatives, influencing security design decisions across engineering teams.

● Performed AI security assessments and adversarial testing focused on prompt injection, sensitive data exposure, model misuse, trust boundary violations, and emerging risks associated with generative AI systems.

● Partnered with platform, infrastructure, and engineering teams to implement security-by-design principles, establish governance standards, and drive adoption of secure cloud and Kubernetes practices.

● Developed security standards, reference architectures, and implementation guidance supporting compliance requirements, audit readiness, and enterprise security governance objectives.

Verra Mobility Ottawa, ON

Senior Security Engineer (SOC & Incident Response) Nov 2023 – Nov 2025

● Lead investigation, containment, and remediation of security incidents across cloud, infrastructure, and Kubernetes environments using Microsoft Sentinel, CrowdStrike Falcon, and Cortex XDR.

● Monitor and analyze security events from SIEM, EDR, cloud-native security tools, and containerized platforms to identify threats and coordinate response activities.

● Perform root-cause analysis and produce detailed incident reports, timelines, and lessons learned documentation supporting governance and audit requirements.

● Partner with cloud, infrastructure, and engineering teams to improve detection capabilities, security controls, and incident response processes.

● Support vulnerability management initiatives by validating findings, prioritizing remediation efforts, and reducing organizational risk exposure.

● Drive operational improvements through security automation, process optimization, and development of security runbooks and operational playbooks.

● Contribute to DevSecOps initiatives by validating security controls within development and deployment workflows.

Innodata Remote

AI Security Specialist (Contract) 2025

● Performed security assessments of AI-enabled systems, identifying risks related to prompt injection, sensitive data exposure, adversarial manipulation, excessive agent permissions, and AI misuse scenarios.

● Conducted AI red-team exercises and adversarial testing to evaluate vulnerabilities across AI workflows, models, and operational processes.

● Assessed trust boundaries between AI systems, external data sources, and supporting infrastructure to identify security risks and mitigation opportunities.

● Produced risk assessments, security findings, and technical documentation supporting secure adoption of AI technologies.

● Developed recommendations for secure AI deployment, monitoring, governance, and operational controls aligned with emerging AI security practices.

● Collaborated with engineering and security teams to strengthen AI security controls and improve risk management processes.

Central 1 Remote, Canada

Information Security Engineer (Contract) 2024

● Security Implementation

● Develop and implement security measures for the protection of computer systems, networks, and information.

● Conduct thorough risk assessments to identify vulnerabilities and strategize mitigation approaches.

● Define system security requirements and prepare comprehensive reports on findings.

● Document and review standard operating procedures and protocols.

● Prepare detailed reports with findings, outcomes, and recommendations for enhancing system security.

● Utilize commercial off-the-shelf testing tools (e.g., vulnerability scanners, intercepting proxies) and create exploits using chosen programming languages

● Strategic Planning:

● Develop and maintain processes to support Threat Modelling and Risk Assessments at both the product and project levels.

● Lead the planning and design of enterprise security architecture, coordinating with system owners, control providers, and stakeholders to allocate security controls effectively.

● Create and maintain enterprise security documents, including architecture blueprints, policies, standards, baselines, guidelines, and procedures.

● Oversee and contribute to the design and deployment of technology solutions to ensure they adhere to industry best practices.

● Acquisition and Deployment:

● Design tools and platforms to enhance capabilities within the Information Security domain.

● Establish and maintain partnerships with security vendors to support organizational goals.

● Stay updated on the latest in information security, including new or improved security solutions, processes, and emerging threat vectors.

● Recommend enhancements or new security solutions to improve overall enterprise security.

● Develop secure testing strategies to ensure project readiness.

● Operational Management:

● Participate in investigations of problematic activities, prioritize vulnerabilities, and validate fixes for existing security issues.

● Lead the design and execution of vulnerability assessments and penetration tests.

● Conduct security reviews, identify gaps in security architecture, and develop risk management plans.

● Provide security input for statements of work and other project documents.

● Evaluate security architectures and designs to ensure adequacy in response to project requirements.

IBM Ottawa, ON

Security Engineer (SOC & Cloud Security) Feb 2020 – Oct 2023

● Designed, implemented, and operated security controls across AWS cloud environments utilizing Security Hub, GuardDuty, IAM, CloudTrail, AWS Config, and AWS WAF.

● Integrated security controls into CI/CD pipelines, enabling automated vulnerability scanning, security testing, compliance validation, and deployment security checks.

● Automated security monitoring, alert enrichment, reporting, and investigation workflows using Python and Bash scripting.

● Conducted vulnerability assessments and remediation validation using Tenable, Rapid7, and Microsoft Defender Vulnerability Management.

● Investigated and responded to security incidents affecting cloud, infrastructure, and enterprise environments while coordinating remediation with engineering teams.

● Supported threat detection engineering activities using QRadar, Microsoft Sentinel, CrowdStrike Falcon, and Cortex XDR.

● Developed incident response playbooks, security standards, operational runbooks, and technical documentation supporting enterprise security operations.

● Collaborated with cloud and infrastructure teams to implement least-privilege access models and strengthen security architecture.

IBM Ottawa, ON

Security Analyst / Technical Solutions Engineer Jan 2017 – Feb 2020

● Performed security monitoring, threat detection, alert triage, and incident investigation activities within large enterprise environments.

● Investigated security events using SIEM technologies and enterprise security tools while escalating critical findings according to incident response procedures.

● Maintained incident documentation, investigation records, and reporting processes supporting compliance and audit readiness.

● Assisted with threat analysis, vulnerability investigations, and detection engineering activities.

● Contributed to security knowledge bases, operational procedures, incident response documentation, and security playbooks.

● Supported governance and compliance initiatives requiring adherence to organizational security standards and policies.

CENGN Ottawa, ON

Security Engineer 2016

● Supported security monitoring, logging, and visibility initiatives across enterprise environments.

● Developed Python and Bash automation scripts for data collection, security analysis, and operational process improvements.

● Assisted with vulnerability assessments, security testing, and remediation validation activities.

● Contributed to security reporting, documentation, and operational security initiatives.

● Collaborated with engineering teams to improve monitoring capabilities and security controls.

Embateq Consulting Ottawa, ON

System Administrator 2013 – 2016

● Managed identity and access controls, ensuring proper authentication, authorization, and least-privilege access practices.

● Monitored infrastructure systems, investigated operational issues, and supported incident response activities.

● Assisted with implementation and validation of security controls across enterprise infrastructure environments.

● Maintained system logs, monitoring solutions, and operational procedures supporting security investigations.

● Provided technical support aligned with organizational security requirements and operational standards.

SECURITY ENGINEERING PROJECTS

Kubernetes Security & Container Hardening

● Designed and implemented a Kubernetes security program across cloud-hosted environments, establishing RBAC governance, least-privilege access controls, workload isolation, admission control policies, and container runtime security monitoring.

● Partnered with platform and engineering teams to standardize secure deployment patterns, reduce configuration drift, and improve security posture across containerized workloads.

● Integrated security validation into the Kubernetes deployment lifecycle to proactively identify misconfigurations, excessive permissions, and policy violations before production deployment.

DevSecOps Security Integration

● Led the integration of security controls into enterprise CI/CD pipelines, embedding automated SAST, dependency scanning, container image scanning, infrastructure-as-code validation, and compliance checks directly into development workflows.

● Shifted security testing earlier in the software development lifecycle, reducing manual security reviews and enabling developers to identify and remediate vulnerabilities before production release.

● Established security gates and risk-based deployment controls that balanced security requirements with engineering velocity.

AWS Security Architecture

● Designed and implemented cloud security governance controls across a multi-account AWS environment using AWS Organizations, Security Hub, GuardDuty, CloudTrail, IAM, AWS Config, and AWS WAF.

● Built centralized visibility and continuous compliance monitoring capabilities, enabling proactive detection of security misconfigurations, policy violations, and cloud risks.

● Implemented preventative and detective security controls that strengthened governance, improved audit readiness, and supported secure cloud adoption at scale. Security Automation & Enterprise Patching Modernization

● Designed and implemented an automated patch management solution using Python and Ansible to streamline operating system and security patch deployment across enterprise Linux and cloud-hosted environments.

● Developed automated workflows for patch discovery, deployment scheduling, pre-deployment validation, compliance verification, and post-deployment reporting, reducing manual intervention and operational risk.

● Implemented automated health checks and rollback validation procedures to improve deployment reliability and minimize service disruption during maintenance windows.

● Reduced patch deployment time by 50%, decreasing maintenance activities from approximately 12 hours to 6 hours, while improving patch compliance and reducing exposure to known vulnerabilities.

● Collaborated with infrastructure, operations, and application teams to coordinate maintenance windows, validate application compatibility, and ensure successful adoption of the automated patching framework.

AI Security Assessment & Adversarial Testing

● Performed security assessments of generative AI and machine learning systems, evaluating risks related to prompt injection, sensitive data exposure, model misuse, trust boundary violations, and insecure integrations.

● Conducted adversarial testing exercises to identify weaknesses in AI-enabled applications and assess the effectiveness of security controls protecting AI workloads.

● Provided security recommendations and risk mitigation strategies aligned with emerging AI security frameworks and responsible AI practices. EDUCATION

Bachelor of Information Technology / Computer Science Carleton University

CERTIFICATIONS

AWS Certified Security – Specialty



Contact this candidate