EQ Bank | Equitable Bank
Staff Engineer, AI Security
Toronto, Ontario · Hybrid · Posted today
Opens jobs.lever.co
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- Hybrid
- Source
- Lever (employer's hiring system)
Skills mentioned
Azure, Machine Learning, LLM, Generative AI, Cloud Security, Supply Chain, Python, Data Engineering
About the role
Join a Challenger
At EQ, we're remaking banking so every Canadian gets ahead, every day. Serving nearly 4 million Canadians from coast to coast, we offer a wide variety of financial services from banking and lending, to trust and credit union solutions.
We've been at this since 1970, challenging the conventions of traditional banking with smarter, faster, and more connected financial experiences.
What's kept us moving? The people behind it all: challengers who ask better questions, push back on old assumptions, and look for a better way forward.
If you're driven to help reshape how banking works for Canadians and the businesses that power our economy, this could be your next big opportunity.
We can’t wait to get to know you!
The Work
This role leads the design, implementation, and operation of security controls for Artificial Intelligence (AI), generative AI, machine learning, AI agents, copilots, automation platforms, agentic AI platforms, orchestration frameworks, model providers, and the cloud services that support them.
Reporting to the Senior Director, Cyber Security Engineering & Operations and working as a fully dedicated, embedded security partner to the AI Centre of Enablement and the Enterprise Technology, Data & AI organization, the incumbent provides senior technical leadership to ensure AI solutions are delivered securely and in line with enterprise security standards and regulatory expectations.
The incumbent develops reusable security patterns, guardrails, control implementations, automation, and detection capabilities that support enterprise AI adoption while protecting the bank from data leakage, model misuse, insecure integrations, excessive permissions, unsafe automation, and unapproved use of AI technologies. The role enables teams through practical, reusable guardrails and secure patterns rather than relying only on review and enforcement. This is a senior individual contributor role with no direct reports.
The Core Responsibilities!
-
Design, implement, and operate security controls for AI platforms, generative AI solutions, AI agents, machine learning environments, and supporting cloud services.
-
Partner with the AI Centre of Enablement, AI Engineering, Data Engineering, and Technology teams to embed security requirements into AI solutions across the delivery lifecycle.
-
Build and automate AI security guardrails and policy enforcement across approved and emerging AI technologies, including enterprise copilots, AI coding assistants, model platforms, orchestration frameworks, agentic AI platforms, and third-party AI services.
-
Support security assessment and enablement for platforms and frameworks such as Microsoft 365 Copilot, Copilot Studio, GitHub Copilot, Azure AI services, Enterprise Gemini, Cursor AI, OpenAI, Anthropic, LangChain, LangGraph, LangFuse, and future enterprise-approved AI technologies.
-
Implement data protection controls for AI training, grounding, and inference in partnership with Data Governance and Privacy teams.
-
Configure and maintain identity, access, and model access controls for AI platforms, APIs, agents, and integrations.
-
Develop and maintain security standards, implementation patterns, and technical guidance for the secure adoption of AI technologies.
-
Review solution designs and provide practical security guidance to address risks, control gaps, and regulatory requirements.
-
Work as a collaborative security partner across Cyber, Architecture, Data, Engineering, AI Engineering, and business teams to enable secure delivery with minimal unnecessary friction.
-
Perform and support adversarial testing of AI solutions, and work with engineering teams to prioritize and remediate security weaknesses.
-
Develop security monitoring requirements and detection capabilities for AI-related security events, misuse, and unapproved AI usage.
-
Assess security risk in the AI supply chain, including models, plug-ins, agents, and third-party AI services.
-
Support governance, compliance, audit, and risk management activities related to AI, including the AI control library and AI intake and lifecycle processes.
-
Create and maintain technical documentation, standards, procedures, and implementation guidance.
-
Mentor engineers, architects, and delivery teams on practical AI security patterns, risks, and control implementation.
Let's Talk About You!
-
A college diploma or university degree in computer science, engineering, information security, or a related technical field is required.
-
7-9 years of experience in cyber security, software engineering, cloud engineering, or platform engineering, including a minimum of 4 years in a cyber security role.
-
Expert level knowledge of AI and cloud security controls, sufficient to act as the internal subject matter expert others rely on for direction.
-
Experience designing, implementing, and supporting security controls within cloud-native and enterprise technology environments.
-
Strong understanding of AI technologies, including generative AI, large language models (LLMs), AI agents, retrieval-augmented generation, machine learning platforms, model integrations, and AI-enabled business solutions.
-
Strong understanding of AI-specific security risks, including prompt injection and indirect prompt injection, sensitive information disclosure, data and model poisoning, insecure output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, and AI supply chain risk.
-
Experience securing cloud platforms and services, preferably Microsoft Azure; experience with GCP or OCI is an asset.
-
Experience securing one or more enterprise AI platforms, copilots, AI coding assistants, model providers, orchestration frameworks, or agentic AI technologies. Experience with Microsoft AI services, Enterprise Gemini, Cursor AI, OpenAI, Anthropic, LangChain, LangGraph, LangFuse, or similar platforms is considered an asset.
-
Strong knowledge of application security, API security, identity and access management, secrets management, encryption, and secure software development practices.
-
Experience developing automation, integrations, or security tooling using modern programming and scripting languages such as Python or PowerShell.
-
Experience working with CI/CD pipelines, Infrastructure-as-Code, containers, and cloud-native technologies.
-
Strong understanding of security monitoring, logging, detection, and incident response concepts.
-
Working knowledge of AI and security frameworks, including NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST CSF, and CIS Controls.
-
Ability to review technical designs and provide practical security guidance that balances risk management with business objectives.
-
Curiosity and a continuous learning mindset, with the ability to stay current as AI security threats, controls, platforms, and regulatory expectations evolve.
-
Pragmatic judgment with the ability to balance security risk, regulatory expectations, delivery timelines, and business value.
-
Strong analytical and problem-solving skills with the ability to assess complex technical environments and identify effective solutions.
-
Demonstrated ability to influence technical decisions without direct authority and help teams adopt secure patterns rather than simply identifying gaps.
-
Relevant industry certifications such as CISSP, CCSP, GIAC, Microsoft Azure Security Engineer, Google Professional Cloud Security Engineer, or equivalent are considered an asset.
-
Moderately complex: provides technical information and guidance, conducts working sessions and design reviews, and influences groups of technical and business stakeholders across the bank.
-
Produces clear documentation, standards, patterns, and implementation guides intended for reuse by other teams.
-
Translates technical AI risk into business language for management, governance forums, and delivery partners.
-
Collaborates as an embedded partner across Cyber, Architecture, Data, Engineering, AI Engineering, and business teams, using practical guidance and influence to enable secure outcomes.
-
Coaches and mentors technical and non-technical stakeholders to improve enterprise understanding of AI security risks and controls.
-
Engages with vendors and external partners to exchange technical information and validate security capabilities.
Communication Skills:
What we offer [For full-time permanent roles]
💰 Competitive discretionary bonus
✨ Market leading RRSP match program
🩺 Medical, dental, vision, life, and disability benefits
📝 Employee Share Purchase Plan
👶🏽 Maternity/Parental top-up while you care for your little one
🏝 Generous vacation policy and personal days
🖥 Virtual events to connect with your fellow colleagues
🎓 Professional development and comprehensive Career Development program
💛 A fulfilling opportunity to join one of the top FinTechs and help create a new kind of banking experience
The incumbent will be working hybrid and in office time will be spent working from EQ Bank’s additional office space located at 2200-25 Ontario Street, Toronto, ON.
Equity, Diversity & Inclusion
EQ is committed to building an inclusive, accessible environment where every employee feels valued, respected, and supported. We believe our organization is stronger — and our people thrive — when we honour and celebrate diverse experiences, identities, and perspectives. We’re equally committed to supporting your growth, both professionally and personally.
We provide a barrier‑free recruitment process and work environment. If you require accommodations at any stage, we will work with you to ensure you can bring your best self to the process and beyond.
As part of our recruitment process, EQ uses AI to help screen, assess, and/or select applicants for this position. All AI-enabled outputs are reviewed and validated by our talent team. All candidates considered for hire must successfully complete a criminal background check and credit check. While we appreciate every application, an EQ recruiter will contact only those whose skills and experience most closely match the requirements of the role.
EQB Inc. (TSX: EQB) is the parent company of Equitable Bank, the country's seventh-largest Schedule I bank by assets, which operates EQ Bank, Canada's Challenger Bank™. EQB Inc. serves nearly 4 million Canadians and manages approximately $150 billion in combined assets under management and administration.
To learn more, visit eqb.investorroom.com and eqbank.ca.
Job ID lv-eqbank-8ee9bdeb-8d39-45e7-8545-65fd3652f551 · Original posting ↗
Similar jobs
- Senior Front End EngineerNewMejuriToronto, Ontario
- Senior Software Engineer - Platforms & InfrastructureNewTubi - CanadaToronto, Ontario · Hybrid
- Engineering Manager, Voyager (Applied AI & Innovation)NewRelayToronto, Ontario · Hybrid
Business Intelligence EngineerNewOpenTableToronto, Ontario
Business Intelligence EngineerNewOpenTableToronto, Ontario