AI Security & DevOps Engineer securing AI systems from prototype to production for Casper Studios, an AI services firm. Owning security standards, platform controls, and enterprise client approvals.
Responsibilities
Own Casper's dev-to-production security standard
Define and run security gates including threat models, design reviews, and release decisions
Harden identity and authentication, secrets management, data protection, egress controls, and agent security
Own security-dependent platform work including CI/CD, automated repository scanning and review, infrastructure-as-code, environment and access management, logging, and telemetry
Audit internal repositories and systems and remediate findings
Lead client security engagements, gather requirements, map approved and unapproved vendors, and produce threat models and evidence packs
Establish preferred vendors for authentication, secrets, telemetry, and scanning
Incorporate security validation timelines into project scoping and production roadmaps
Raise engineering security standards through reviews, pairing, and written guidance
Work across client engagements, primarily with regulated enterprises using Microsoft stacks
Requirements
Deep hands-on application and product security experience, including threat modeling, finding vulnerabilities, and writing fixes
DevOps and platform experience with CI/CD, infrastructure-as-code, cloud (especially Azure, plus AWS/GCP), secrets management, and observability
Identity and authentication expertise: OAuth/OIDC, SSO/SCIM, RBAC, conditional access, and Microsoft Entra
LLM and agent security expertise: prompt injection, excessive agency, tool and connector permissioning, insecure output handling, retrieval abuse, and AI supply chain risk
Secure SDLC experience with SAST/DAST/SCA, dependency and supply chain controls, and automated review
Judgment to right-size controls to the stage and stakes
Client-facing credibility with enterprise security teams and ability to translate risk for executives
Daily use of modern AI tooling with customized workflows
Strong writing and high agency
Experience in regulated industries, consulting/agency/forward-deployed environments, OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, ISO 42001, SOC 2 or ISO 27001, AI red teaming, adversarial testing, or abuse-case analysis are nice to have
Must be based in the US or Canada
Must provide a GitHub profile with private contributions enabled
Senior DevOps Engineer automating cloud and on - premise infrastructure for Keyfactor’s cryptographic identity security platform. Improving Kubernetes, CI/CD, and Infrastructure as Code delivery.
Student Site Reliability Analyst supporting Sun Life’s financial - services technology reliability and monitoring. Building dashboards, analyzing performance, and helping prevent outages across global 24x7 services.
DevOps co - op interns implementing software fixes, cloud configurations, and automated deployments for Canadian insurer Intact. Roles based in Toronto, Vancouver, and Montréal.
Reliability Engineering Co - Op testing optical switching products and components at Lumentum. Analyzing failures, reliability data, and regulatory qualification results in Ottawa.
Senior DevOps Engineer operating secure AWS infrastructure and CI/CD for SOVRA’s public procurement platform. Improving reliability, observability, compliance, and AI - enabled operations.
Forward Deployed Engineer deploying CruxOCM’s heavy - industry automation software in complex operational technology environments. Integrating customer systems, commissioning solutions, and translating field learnings into product improvements.