Retour à la recherche
S
SPECTRAFORCESource d’offres vérifiée

DevSecOps Engineer

Offre en anglais

Title: SecOps Engineer/ Cloud Security Engineer Duration: 6+ months Contract (possible extension) Location: Canada (100% remote) Experience Level: 5-7 years This is a hands-on DevSecOps Security role focused on securing CI/CD pipelines and ensuring DevOps processes meet enterprise security standards. Key responsibilities: Assess CI/CD pipelines (Jenkins, GitHub Actions, GitLab, Azure DevOps) for security gaps. Validate and evaluate security tools such as Snyk, Checkmarx, Veracode, SonarQube, Wiz, or Prisma Cloud. Implement and verify security controls like SAST, SCA, secret scanning, contain…

  • Télétravail
  • ["Canada"]
  • Publié 25 juin 2026
  • 1 poste

Résumé du poste

Title: SecOps Engineer/ Cloud Security Engineer Duration: 6+ months Contract (possible extension) Location: Canada (100% remote) Experience Level: 5-7 years This is a hands-on DevSecOps Security role focused on securing CI/CD pipelines and ensuring DevOps processes meet enterprise security standards. Key responsibilities: Assess CI/CD pipelines (Jenkins, GitHub Actions, GitLab, Azure DevOps) for security gaps. Validate and evaluate security tools such as Snyk, Checkmarx, Veracode, SonarQube, Wiz, or Prisma Cloud. Implement and verify security controls like SAST, SCA, secret scanning, container scanning, and IaC scanning. Document findings, track remediation efforts, and support governance/reporting activities. Work closely with Application Security, Platform Engineering, and DevOps teams. Ideal candidate: Strong DevOps + Security background (not just one or the other). Experience with CI/CD security assessments and DevSecOps practices. Knowledge of cloud platforms (AWS/Azure/GCP), Kubernetes, Docker, and Terraform. Experience integrating security tools into development pipelines. Must-have: Hands-on experience securing CI/CD pipelines (Jenkins/GitHub Actions/GitLab/Azure DevOps) using DevSecOps security controls (SAST, SCA, container & secret scanning) and security tools like Snyk, Checkmarx, Veracode, or SonarQube, preferably in a cloud environment (AWS/Azure/GCP).

Ce que vous ferez

The role involves assessing CI/CD pipelines for security gaps and validating security tools. The engineer will implement security controls and document findings while collaborating with various teams.

Exigences

Candidates should have a strong background in both DevOps and security, with experience in CI/CD security assessments. Knowledge of cloud platforms and experience integrating security tools into development pipelines is essential.

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • DevSecOps
  • CI/CD
  • Security
  • Jenkins
  • GitHub Actions
  • GitLab
  • Azure DevOps
  • Snyk
  • Checkmarx
  • Veracode
  • SonarQube
  • Wiz
  • Prisma Cloud
  • AWS
  • Azure
  • GCP

Renseignements supplémentaires

Expérience minimale
5+ ans