Retour à la recherche
PL
Pengcorp Ltd.Source d’offres vérifiée

Development Security Specialist

Offre en anglais

Integrate security controls into the software development lifecycle and manage secure CI/CD pipelines for industrial applications. Conduct penetration testing, manage vulnerabilities, and implement cybersecurity controls aligned with industrial standards like IEC 62443.

  • Hybride
  • Calgary, AB
  • Publié 21 juill. 2026
  • Postuler avant le 20 août 2026
  • 1 poste

Résumé du poste

Role: Development Security Specialist (DevSecOps) Reports To: Manager, Application & Software Development Department: Digitization Position Type: Full Term Location: Calgary, Alberta (Hybrid) About the Company Pengcorp is a consortium of highly dedicated and talented engineers providing specialized services to industrial enterprises throughout North and South America. Our expertise has been embedded in mid- to large-scale projects across Western Canada and around the world. We are recognized for delivering innovative solutions that optimize industrial processes while meeting the needs of all stakeholders. Our services span multiple industrial technology disciplines, including Electrical & Instrumentation, Industrial Ethernet, Cybersecurity, Automation Integration, Data Visualization & Analytics, and Field Maintenance Support. As we continue to grow, we are seeking experienced professionals who are passionate about advancing secure and reliable industrial operations. What You Will Do We are seeking a highly skilled DevSecOps Engineer to support the secure design, development, deployment, and operation of industrial software applications used within the Oil & Gas sector. This role combines software engineering, cybersecurity, DevOps, and industrial control system (ICS) security to ensure that mission-critical applications are protected against cyber threats while maintaining operational reliability, safety, and regulatory compliance. The ideal candidate will have experience implementing secure software development practices, cloud and on-premises infrastructure security, industrial cybersecurity standards, and automated security controls throughout the software development lifecycle (SDLC). Key Responsibilities DevSecOps & Application Security Integrate security controls into all phases of the Software Development Lifecycle (SDLC). Design, implement, and maintain secure CI/CD pipelines. Automate security testing, code scanning, vulnerability management, and compliance checks. Conduct secure code reviews and identify security vulnerabilities in application code. Implement Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Infrastructure as Code (IaC) scanning. Develop secure deployment standards for cloud, on-premise, and hybrid environments. Manage secrets, encryption keys, certificates, and privileged access controls. Ensure secure integration between industrial applications, enterprise systems, and operational technology (OT) environments. Penetration Testing Conduct and coordinate: Web application and API security testing to identify and remediate vulnerabilities. Cloud, container, and Kubernetes security assessments to evaluate risks and security controls. Annual third-party penetration testing, including remediation tracking and validation of findings. Industrial Cybersecurity Responsibilities Design and maintain cybersecurity controls protecting Oil & Gas operational applications. Implement security architectures aligned with: IEC 62443 NIST Cybersecurity Framework (CSF) NIST SP 800-82 ISA/IEC Industrial Automation Security Standards ISO 27001 Support cybersecurity risk assessments for industrial applications and supporting infrastructure. Develop secure interfaces between SCADA systems, historians, PLCs, RTUs, IIoT devices, and enterprise applications. Identify and mitigate cybersecurity threats affecting industrial operations. Implement segmentation strategies between IT and OT environments. Assist in the deployment and maintenance of Zero Trust security principles across industrial systems. Conduct threat modeling for critical operational applications. Vulnerability Management & Security Monitoring Perform regular vulnerability assessments and remediation tracking. Analyze application and infrastructure security findings. Coordinate security patch management activities. Monitor security events using SIEM and security monitoring platforms. Investigate cybersecurity incidents affecting development environments and industrial applications. Participate in incident response exercises and post-incident reviews. Develop automated security alerting and compliance reporting. Cloud & Infrastructure Security Secure AWS, Azure, or private cloud infrastructures hosting industrial applications. Implement infrastructure hardening standards. Manage container security for Docker and Kubernetes environments. Establish secure network architectures including firewalls, VPNs, reverse proxies, and micro-segmentation. Secure APIs and application integrations. Governance, Risk & Compliance Support audits and compliance activities. Maintain cybersecurity policies, standards, and procedures. Document security architectures, risk assessments, and remediation plans. Ensure compliance with customer, industry, and regulatory cybersecurity requirements. Track cybersecurity KPIs and risk metrics. Required Qualifications Education Bachelor's Degree in: Computer Science Software Engineering Cybersecurity Computer Engineering Related Technical Field Experience 5+ years of software development, DevOps, cybersecurity, or DevSecOps experience. 3+ years securing industrial, operational technology (OT), or critical infrastructure systems. Experience supporting Oil & Gas, Energy, Utilities, Manufacturing, or Industrial Automation environments. Technical Skills CI/CD Platforms: Azure DevOps GitHub Actions Jenkins GitLab CI/CD Programming & Scripting: Python PowerShell Bash C# JavaScript Cloud Platforms: Microsoft Azure AWS Google Cloud Platform (GCP) Security Tools: Microsoft Defender Suite Microsoft Sentinel Splunk Qradar Securonix CrowdStrike Qualys Tenable SonarQube Checkmarx Veracode Snyk Containers & Infrastructure: Docker Kubernetes Terraform Ansible OT Technologies: SCADA Systems PLCs Historians OPC UA Modbus DNP3 Industrial Networks Preferred Certifications CISSP (Certified Information Systems Security Professional) GICSP (Global Industrial Cyber Security Professional) CSSLP (Certified Secure Software Lifecycle Professional) CISM (Certified Information Security Manager) Certified Kubernetes Security Specialist (CKS) Microsoft Cybersecurity Architect Expert AWS Certified DevOps Engineer-Professional AWS Certified Security - Specialty Azure Security Engineer Associate GIAC Industrial Cyber Security Certifications ISA/IEC 62443 Cybersecurity Certificate Key Competencies Secure Software Development Industrial Cybersecurity DevSecOps Automation Risk Management Threat Modeling Incident Response Vulnerability Management Cloud Security OT/IT Convergence Security Analytical Problem Solving Communication and Collaboration Success Measures The successful candidate will: Reduce application security vulnerabilities and remediation times. Improve security automation coverage across CI/CD pipelines. Maintain compliance with industrial cybersecurity standards. Successfully secure critical Oil & Gas operational applications. Minimize cybersecurity risk to production and operational environments. Enhance resilience against cyber threats targeting industrial operations. Typical Applications Protected Production Management Systems Pipeline Monitoring Applications Asset Integrity Platforms Predictive Maintenance Systems SCADA and HMI Interfaces Digital Oilfield Applications Field Data Collection Systems Emissions Monitoring Applications Industrial IoT Platforms Operational Analytics and Reporting Systems This role is critical to ensuring that industrial software applications remain secure, reliable, and resilient while supporting safe and efficient Oil & Gas operations. Why Join Us? Work on mission-critical OT and cybersecurity projects supporting industrial operations across North and South America. Join a team of highly skilled engineers delivering innovative solutions to complex industrial challenges. Competitive compensation and comprehensive benefits package. Hybrid work environment with flexibility and autonomy. Opportunities for career growth, technical leadership, and professional development. Exposure to leading OT networking, cybersecurity, and industrial automation technologies.

Ce que vous ferez

Integrate security controls into the software development lifecycle and manage secure CI/CD pipelines for industrial applications. Conduct penetration testing, manage vulnerabilities, and implement cybersecurity controls aligned with industrial standards like IEC 62443.

Exigences

Requires a bachelor's degree in a technical field and over 5 years of experience in software development, DevOps, or cybersecurity. Candidates must have at least 3 years of experience securing industrial, operational technology, or critical infrastructure systems.

Avantages

• Competitive compensation • Comprehensive benefits package

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • DevSecOps
  • Application Security
  • CI/CD
  • Penetration Testing
  • Vulnerability Management
  • Cloud Security
  • Industrial Cybersecurity
  • OT/IT Convergence
  • Python
  • Azure DevOps
  • Kubernetes
  • Docker
  • Terraform
  • SCADA
  • IEC 62443
  • NIST Framework

Domaines d’emploi

  • Security & Safety
  • Software
  • Energy
  • Technology
  • Engineering

Renseignements supplémentaires

Formation minimale
Baccalauréat
Expérience minimale
5+ ans
Postuler avant le
20 août 2026
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Niveau d’expérience
Mid-Senior level
Mode de candidature
La candidature directe est offerte