Forward Deployed Engineer / Implementation Engineer
Remote, Montreal, QC, Canada. Full time.
Working hours in Eastern, Central or Pacific time. Travel up to 25 percent: team meetings, customer site visits when a customer asks for one, and occasional industry events.
About CWS
CWS builds and runs the security and cloud infrastructure companies depend on. We design, deploy, tune and operate production platforms across Montreal, QC, Canada: SIEM onboarding and detection engineering, cloud identity and access, edge and firewall platforms, security programs, data protection, and secure cloud environments built as code. We do not hand off at go-live. We run the managed service on top of what we build, so the systems we deploy stay tuned and defensible.
We work through technology partners and directly with customers. Every engineer here works directly with the founders and owns a real customer outcome from day one.
Role & Responsibilities
As a Forward Deployed Engineer, you own the customer engagement end to end: you scope the work, architect the solution, build and configure it, prove it holds up, and hand over a system the customer's team can run without you. You are both the engineer and the person accountable for the result.
You carry one to three engagements at a time, spanning cloud and infrastructure delivery (AWS, Google Cloud, infrastructure as code, networking, edge and firewall platforms) and security delivery (tool implementation, tuning, and assessments).
- Deploy, configure and integrate security and cloud platforms in customer environments, and prove they work before you hand them over.
- Plan and run your engagements: milestones, dependencies, acceptance criteria, and a weekly status the customer can read in two minutes.
- Raise risks early, and bring options and a recommendation with them.
- Write the as-built documentation and runbooks, run the knowledge transfer, and train the customer's team so they can operate without you.
- Contribute to managed-service work on platforms we run: health checks, tuning, and renewal assessments.
- Help scope new work: effort estimates, technical input to statements of work, and kickoff material.
- After each engagement, write down what changed between the plan and what it took, and turn it into an asset the team reuses.
Qualifications
- Three to five years in security engineering, DevSecOps or platform engineering, or software engineering, including at least one year delivering into environments you did not own.
- Hands-on AWS, and working knowledge of Azure or Google Cloud: identity, networking, compute, storage, logging.
- Networking you can troubleshoot: DNS, routing, VPN, firewalls, load balancing, TLS.
- Infrastructure as code (Terraform or similar) and version control as daily habits.
- Python or TypeScript at a level where you build your own tooling.
- Security fundamentals across identity, endpoint, network and cloud posture, and the ability to explain a finding to a non-technical owner.
- Clear written and spoken English. You write your own status updates, as-builts and runbooks.
- Comfort working on your own. You take an ambiguous problem, break it down, decide what to build and what to configure, and ask for help early when you need it.
You do not need to match every line. If you meet most of them and you learn fast, apply.
Nice to have:
- Certifications: a cloud provider certification (security specialty preferred), a firewall or edge platform certification, a SIEM or security operations certification, CISSP, Security+ or a GIAC certification, or Kubernetes.
- Delivery experience in a consulting, professional services or managed security firm, where you owned a schedule and a customer relationship.
- French, spoken and written. Part of our delivery is in French.
- Detection engineering or security automation.
- Compliance context: SOC 2, ISO 27001, HIPAA, PCI DSS.
Compensation and benefits
- Competitive salary
- Unlimited paid time off
- Dedicated mental health days
- Performance bonuses
- Learning and certification stipend
- Home office equipment