JOBSEARCHER

Principal Cloud Security Engineer

BMODallas, TXL6 LeadSeptember 11th, 2026
Senior Cloud, AI & Data Security EngineerWe are seeking an enthusiastic and passionate professional for a Senior Cloud, AI & Data Security Engineer role who wants to design and implement security solutions for systems and services across AWS, Azure, and AI/ML platforms. We need someone who can establish the highest standards that meet and exceed security governance solutions and practices, provide assurance to management and auditors, and ensure sustained protection by embedding controls in operational and DevOps (CI/CD) practices with a focus on automation.We are looking for someone who has a high level of technical security expertise and who takes seriously the responsibility of monitoring, detecting, protecting, and maintaining the security of data, AI/ML systems, cloud platforms, and networks.You are a leader with a strong technical background. You have demonstrated strength in:Developing and implementing secure cloud and AI/ML architectures using a risk-based cybersecurity and data privacy strategyDefining security patterns, roadmaps, and operating models that leverage collaborationFacilitating industry-standard information security governanceAdvising senior leadership on cybersecurity, AI risk, and privacy risks, threats, and investment strategiesDocumenting appropriate policies and procedures to manage information security risks, including those unique to AI/ML systems and sensitive data assetsAs a qualified candidate, you will be part of the team driving BMO's Cloud, AI, and Data Security implementation. As a member of this team, you should possess the ability to inspire yourself and all of our team. Based on your previous experiences, you will inject new knowledge and skills into an already high-performing team, thus elevating our efforts to new heights.Your ResponsibilitiesCloud SecurityAssess, design, implement, automate, and document security solutions, controls, and processes for Amazon Web Services (AWS) and Microsoft Azure cloud platformsDevelop and maintain security patterns for cloud platforms and services; assess all cloud patterns to ensure adherence to best security practices and controlsDesign and implement security baseline controls for Cloud Services for integration into the CI/CD processBuild and deliver policies as code, automating security controls and best practicesReview and approve code and changes with security implications (e.g., IAM Roles and Policies, Security Groups, etc.)Be the cloud security subject matter expert for the Cloud Engineering group and its partners in any IaaS, PaaS, and SaaS implementationsAI & Machine Learning SecurityDefine and implement a security framework for AI/ML systems, covering the full model lifecycle from data ingestion and training to deployment and monitoringAssess and mitigate AI-specific threats including adversarial attacks, model inversion, data poisoning, prompt injection, and model theftEvaluate and secure AI/ML platforms and tools (e.g., Amazon SageMaker, Azure Machine Learning, Hugging Face, OpenAI APIs) against organizational risk standardsCollaborate with data science and AI engineering teams to integrate security controls into MLOps pipelines, ensuring model integrity, access controls, and auditabilityMonitor emerging AI threat landscapes and regulatory developments (e.g., EU AI Act, NIST AI RMF) and translate these into actionable organizational controlsData SecurityImplement and manage data security posture management (DSPM) tools to continuously monitor sensitive data exposure across cloud environmentsEstablish controls for structured and unstructured data stores, including databases, data lakes, data warehouses (e.g., Snowflake, AWS S3, Azure Data Lake), and file sharing platformsDrive the adoption of data-centric security practices within application development and analytics teamsGeneral Security LeadershipProvide subject matter expertise on architecture, authentication, and systems security based on a clear understanding of the engineering stack, services, and data flowLead focused and continuous cybersecurity risk assessments of new and existing technologies - including AI/ML systems and data platforms - to identify risks and appropriate controls that balance security and operabilityProvide effective and pragmatic cybersecurity guidance upfront in major technology projects to enable the business to innovate securelyAssist in the investigation and remediation of security incidents and issues, including those involving AI model compromise or data breachesWork closely with Information Security, product, and software development teams to assess cybersecurity risk and recommend solutions in cloud, AI, and data environmentsYour MindsetYou are a self-starter, driven, and can handle multiple projects and prioritiesYou are passionate about driving the DevSecOps and MLSecOps mindset and culture in a fast-paced, challenging environment where you get the opportunity to work with the latest tools and technologiesYou understand the intersection of security, AI, and data, and actively seek to build bridges between these disciplinesYou are actively looking to improve the solutions you implement, understand the efficacy of collaboration, and are keen to work in a team of CI/CD, infrastructure, AI, and data specialistsYou are energized by the rapidly evolving AI threat landscape and bring intellectual curiosity and practical judgment to navigating ambiguityAs a member of this team, you will inject new knowledge and skills into an already high-performing team, elevating our collective efforts to new heightsRequired Core SkillsFoundationalA university degree in Engineering, Computer Science, Information Technology, or a related field7-10 years of experience developing and implementing security architectures and/or engineering, with demonstrated breadth across cloud, data, and/or AI security domainsSecurity certifications such as CISSP, CCSP, CCSK, or any Cloud Security Specialty certification (e.g., AWS Certified Security Specialty, Microsoft Certified: Azure Security Engineer Associate)Emerging/preferred: Certifications or demonstrated knowledge in AI security (e.g., CDAI, CompTIA AI+, or equivalent vendor-specific AI security training) or data security (e.g., CDPSE, CIPP)Cloud SecurityDemonstrated knowledge of cloud architecture, cloud operations, cloud-based identity and access management, security automation, and orchestrationExtensive experience with cloud-native security solutions and tools (e.g., AWS Security Hub, AWS GuardDuty, Microsoft Defender for Cloud, Azure Sentinel)Knowledge of technical security control environments and compliance frameworks including CSA CCM, ISO 27001, ISO 27017, and NIST CSFAI & ML SecurityWorking knowledge of AI/ML development frameworks and platforms (e.g., TensorFlow, PyTorch, SageMaker, Azure ML) and associated security risksFamiliarity with the OWASP Top 10 for LLMs, MITRE ATLAS, and NIST AI Risk Management Framework (AI RMF)Understanding of MLOps pipeline security, including securing model registries, feature stores, training environments, and inference endpointsKnowledge of Generative AI security risks, including prompt injection, jailbreaking, data leakage via LLMs, and supply chain risks in AI model dependenciesData SecurityExperience implementing data loss prevention (DLP), data classification, and data access governance solutions in enterprise environmentsKnowledge of DSPM tools and practicesUnderstanding of data encryption at rest and in transit, tokenization, and key management for large-scale data environmentsFamiliarity with data privacy regulations (e.g., PIPEDA, GDPR, CCPA) and their technical implementation requirementsExperience securing cloud-based data platforms such as Snowflake, Databricks, AWS Redshift, Azure Synapse, or equivalentTechnical SkillsFirm grasp of networking protocols and operations; comfortable with packet analysis tools such as Wireshark, Burp Suite, nmap, Nessus, and MetasploitKnowledge of theoretical and applied cryptography, key management, and cryptographic algorithms (RSA, AES, TLS, PKI, etc.)Knowledge of Identity and Access Management (IAM) concepts including SSO, SAML, federated identity,