Role Description
As a DevSecOps Engineer, this professional will lead the integration of security into software development, continuous integration, continuous delivery (CI/CD), and cloud operations. They will design and maintain secure CI/CD pipelines, automate security controls ("shifting security left"), manage cloud infrastructure, and ensure system scalability, high availability, and compliance. The DevSecOps Engineer will also mentor team members on secure coding and infrastructure practices, leading cross-functional alignment between engineering, security, and operations teams.
-
Lead the design, implementation, and maintenance of secure CI/CD pipelines, automating security scanning (SAST, DAST, SCA) alongside build, test, and deployment processes.
-
Architect, manage, and harden scalable, highly available, and compliant cloud infrastructure.
-
Implement and manage container security and orchestration technologies (e.g., Docker, Kubernetes) to optimize deployment and runtime safety.
-
Stay up to date with emerging industry trends, security standards, and best practices in DevSecOps, cloud security, and vulnerability management.
-
Provide guidance, training, and mentorship to team members on secure development lifecycle (SDLC) practices and Infrastructure as Code (IaC) security.
Qualifications
-
Bachelorβs degree in Computer Science, Cyber Security, Engineering, related field, or relevant equivalent experience.
-
7+ years of experience in DevOps, DevSecOps, or Infrastructure Engineering with a strong security focus.
-
Extensive experience integrating automated security gates into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
-
Expertise in scripting and automation languages (e.g., Python, Bash, Go).
-
Expertise with major cloud platforms (AWS, Azure, or GCP) and cloud security tooling (e.g., IAM, Security Hub, GuardDuty).
-
In-depth knowledge of infrastructure as code tools.
-
Excellent communication, incident handling, and cross-team collaboration skills.
Requirements
-
Implement automated static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and secrets detection into existing build pipelines to catch vulnerabilities early.
-
Design, deploy, and manage enterprise secrets management solutions (e.g., HashiCorp Vault, AWS Secrets Manager) and enforce strict Least Privilege Access via IAM policies and Zero Trust architecture.
-
Establish continuous vulnerability assessment processes across cloud instances, container registries, and software dependencies; collaborate with development teams to triage and patch vulnerabilities based on risk priority.
-
Partner with Security Operations (SecOps) to build automated threat monitoring, anomaly detection, audit logging, and response capabilities across cloud environments and delivery pipelines.
Benefits
-
Plenty of opportunities to grow your career
-
Comprehensive medical, dental, and vision benefits
-
3 weeks of vacation plus 5 personal days to recharge
-
Employee stock ownership, RRSP program, 401k + matching
-
A chance to give back through community involvement
-
Flexible work arrangements to suit your lifestyle
Salary Range
$130,000 - 140,000