Location: Toronto, Ontario, Canada
Work Model: Hybrid (3 days onsite)
Salary Range: $110,000 – $120,000 CAD
Employment Type: Fulltime
Experience Level: MidSenior (5+ years)
Required Technology Focus: Microsoft 365, Azure, Microsoft Security Stack
Keywords: Cloud Security Engineer, Azure Security Engineer, Microsoft 365 Security
The Cloud Security Engineer is responsible for designing, implementing, and maintaining security controls across Microsoft Azure and Microsoft 365 environments. This role supports Zero Trust architecture, cloud security posture management, endpoint security, identity and access management, threat detection, SIEM/SOAR, and compliance frameworks.
This position requires handson experience with Microsoft security services, including Microsoft Defender, Sentinel, Intune, Entra ID (Azure AD), and Azure Security services.
-
Design, implement, and maintain Zero Trust security architecture in Azure and Microsoft 365
-
Secure cloud infrastructure using Azure Security Center / Defender for Cloud
-
Implement Azure RBAC
-
Manage Microsoft Entra ID (Azure Active Directory)
-
Configure Conditional Access, MFA, SSO, PIM (Privileged Identity Management)
-
Implement identity governance and access reviews
-
Implement and manage Microsoft Intune
-
Enforce device compliance policies, endpoint security policies, and app protection
-
Support modern endpoint management (Windows, mobile devices)
-
Deploy and optimize Microsoft Defender for Endpoint, Defender for Cloud, Defender for Identity
-
Support Microsoft Sentinel (SIEM/SOAR), with partner.
-
Participate in incident response, investigations, and remediation
-
Support and secure Azure Firewalls, WAFs, VPNs, NSGs
-
Collaborate on secure cloud network design
-
Automate security tasks using PowerShell, Azure CLI, Terraform, Python
-
Support vulnerability management and system hardening
-
Perform security posture assessments and risk analysis
-
Support compliance frameworks including CIS, NIST, ISO 27001, GDPR
-
Assist in audit preparation, governance, and compliance reporting
-
Support Microsoft Purview and compliance tooling
-
5+ years of experience in Cloud Security Engineering
-
Strong handson experience with Microsoft Azure and Microsoft 365 security
-
Demonstrated experience with:
-
Microsoft Intune
-
Microsoft Defender (Cloud, Endpoint, Identity)
-
Azure AD / Entra ID
-
Conditional Access, MFA, PIM
-
Security Baselines
-
VPNs, Firewalls, Web Application Firewalls (WAF)
-
Experience with:
-
Incident Response in Azure and M365
-
Vulnerability management
-
Security automation and scripting
-
Strong verbal and written communication skills
-
Experience with Qualys, Lansweeper, Global Secure Access
-
Security automation and scripting
-
Exposure to DevSecOps practices
-
AZ500: Microsoft Azure Security Technologies
-
SC200: Microsoft Security Operations Analyst
-
SC100: Microsoft Cybersecurity Architect
-
Microsoft Certified: Endpoint Administrator / Intune Specialist
TPH operates 60+ production centres across Canada, enabling local, sustainable, and efficient print production. TPH has been recognized as North America's most forestfriendly printer and one of Canada's Greenest Employers.
TPH is an equal opportunity employer committed to diversity, inclusion, and accessibility. Accommodation is available throughout the recruitment process upon request.