
DevSecOps Engineer
- Toronto, ON
- Permanent
- Full-time
- Embed security controls into CI/CD pipelines, source code repositories, and containerization platforms.
- Develop and maintain automated security testing tools for static (SAST), dynamic (DAST), and dependency (SCA) analysis.
- Perform threat modeling and secure code reviews for cloud-native and microservices architectures.
- Partner with DevOps and engineering teams to build infrastructure as code (IaC) with secure baselines.
- Define and enforce security requirements in build and deployment processes.
- Monitor security metrics across development pipelines and respond to incidents related to application security.
- Strong experience with CI/CD platforms (i.e. - GitHub Actions, GitLab, Jenkins, etc.).
- Hands-on knowledge of IaC (i.e. - Terraform, CloudFormation) and container security (i.e. - Docker, Kubernetes).
- Familiarity with common security vulnerabilities (OWASP Top 10) and secure coding practices.
- Experience using AWS and Google Cloud