Développeur.euse en sécurité cloud protégeant l’infrastructure et les applications de nesto. Contribution à la modernisation du financement hypothécaire canadien grâce aux solutions DevSecOps.
Responsibilities
Design, implement, and maintain cloud security solutions to protect cloud-based systems and applications.
Implement and maintain robust security controls for cloud infrastructure and applications.
Identify, remediate, and validate security issues across the cloud infrastructure.
Conduct architecture and design reviews from a security perspective and provide actionable requirements and recommendations.
Collaborate with security leadership, compliance, development, and engineering teams to execute security strategies.
Build, deploy, and manage security tools such as WAFs, IDS/IPS, workload protection, GCP Security Command Center, and Azure Security Center.
Propose and contribute to security and compliance improvements for CI/CD pipelines and deployment processes.
Automate infrastructure provisioning and deployment using IaC tools such as Terraform or Pulumi.
Design and operate scalable processes for provisioning cloud access and maintaining the principle of least privilege.
Participate in incident detection and response by improving observability and alerting and supporting the incident response team.
Self-organize and independently prioritize activities.
Support audits and first-party security questionnaires.
Lead and oversee security assessments and threat modeling exercises.
Implement security controls within Kubernetes.
Build DevSecOps tools and integrations.
Requirements
5+ years of experience working on an infrastructure- and/or security-focused team.
5+ years of development experience, ideally with Go and TypeScript/JavaScript.
Knowledge of common web application vulnerabilities and the OWASP Top 10 framework.
Ability to analyze and act on DAST and SAST tool results (e.g., Tenable, Snyk).
Strong understanding of DevSecOps principles and familiarity with CI/CD pipelines (GitHub Actions, Argo CD, Azure DevOps) for conducting automated security testing.
Experience deploying and customizing security tools, including vulnerability scanners, static analyzers, web application firewalls (WAFs), intrusion detection/prevention systems (IDS/IPS), and endpoint security monitoring.
In-depth understanding of cloud and network security, including extensive knowledge of Kubernetes.
Experience with GCP, specifically one or more of the following services: Security Command Center, GKE, Cloud IDS, Cloud Armor, and Secret Manager.
Experience with Azure, specifically one or more of the following services: Security Center, Azure PaaS App Services, VMs, Azure SQL, Front Door, and Key Vault.
Experience writing infrastructure as code using tools such as Terraform, Pulumi, and Helm.
Knowledge of common security frameworks and benchmarks such as CIS, NIST, and MITRE ATT&CK.
Understanding of identity and access management (IAM) principles and cloud-native IAM solutions.
Passion for continuous learning and knowledge sharing.
Staff Security Engineer securing identity, cloud access, and AI platforms for GitLab’s DevSecOps platform. Engineering automated governance across Okta, GCP, AWS, and non - human identities.
Product Security Engineer using frontier AI to discover vulnerabilities and red - team AI systems at Coinbase. Building offensive security tooling and automating vulnerability response workflows.
Desjardins Red Team advisor conducting adversary simulations and offensive cybersecurity operations. Developing stealth tools, attack chains and tradecraft to strengthen cyber defence.
Expert Security Engineer building anti - cheat systems for Activision’s Call of Duty franchise. Strengthening game security, detection, performance, and fair play across studios.
Expert systèmes, réseaux et sécurité déployant et administrant les solutions de cybersécurité d’I - TRACING. Maintien des infrastructures critiques, gestion des incidents et automatisation des opérations à Montréal.