Skip to main content
D

Senior IT Security Engineer

Draganfly Innovations Inc.
23 hours ago
On-site
Burnaby, BC, Canada
Indeed

About Draganfly: Draganfly Inc. (the “Company”) has been a recognized technology leader within the commercial UAV space for over two decades. We helped establish the commercial market & adoption of multi-rotor helicopters for public safety, agriculture, aerial imaging, & more. As a leader who helped shape the industry, Draganfly’s focus is on the sale of drone products and services, contract engineering & custom integration product development, and health monitoring products and services. About The Role: The Senior IT Security Engineer builds, operates, and improves security across Draganfly’s cloud-first IT environment. This hands-on role combines Microsoft 365 and cloud security engineering with incident response, automation, audit readiness, and delivery of IT Steering Committee-approved security initiatives. This is a full-time, hybrid role based in Burnaby, British Columbia, reporting to the Director of IT. Key Responsibilities; Identity, Access, Endpoint & Cloud Security Manage Microsoft Entra ID controls, including MFA, Conditional Access, least privilege, administrative access, SSO, access reviews, service identities, and joiner/mover/leaver processes. Configure Microsoft 365 endpoint, email, information protection, secure sharing, retention, and DLP controls. Secure AWS IaaS/PaaS workloads through network controls, logging, encryption, secrets management, and configuration monitoring. Manage Intune compliance policies, security baselines, encryption, endpoint protection, patching, and BYOD controls. Automate security checks, reporting, and remediation using PowerShell and approved AI tools, and partner with Software Engineering on DevSecOps. Detection, Incident Response & Resilience Investigate security incidents including risky sign-ins, compromised accounts, malicious email, endpoint alerts, and unauthorized access. Coordinate incident triage, containment, recovery, escalation, monitoring, and evidence preservation with managed security providers. Conduct vulnerability assessments, prioritize and coordinate remediation, and retest fixes. Support business continuity, disaster recovery testing, tabletop exercises, and crisis response. Vendor & Technology Risk Manage security assessments for vendors, SaaS platforms, cloud services, and AI tools. Review SOC 2 reports, ISO/IEC 27001 certifications, architecture, data handling, subcontractors, and security controls. Assess new technologies, track risks and remediation, and partner with procurement, legal, and business owners on security requirements. Security Governance & Risk Translate security policies into technical standards and procedures and support security awareness and change management. Maintain the security risk register, including ownership, treatment plans, evidence, and exceptions. Map controls and improvements to SOC 2, ISO/IEC 27001, NIST CSF, and applicable requirements. Security Projects, Roadmap & Assurance Lead security projects from design and hands-on implementation through testing, troubleshooting, and operational handover. Deliver ITSC-approved initiatives, managing milestones, dependencies, resources, risks, stakeholders, vendors, change plans, and reporting. Conduct internal security audits and control testing, document findings, coordinate corrective actions, and retest remediation. Lead external audit readiness, including IT general controls and applicable COSO-related requirements. Who are you really? Hands-on security engineer who can design, configure, troubleshoot, and improve controls. Uses risk, evidence, and business impact to prioritize work and make practical decisions. Takes ownership of projects, incidents, audits, and remediation through completion. Communicates clearly and collaborates effectively across technical, business, vendor, and audit teams. Qualifications Five or more years of relevant IT or information security experience, including hands-on Microsoft 365 and cloud security engineering. Experience …

View the full posting and apply