DevOps Info Security Engineer
Location: Toronto (Hybrid – 200 Bay Street)
Engagement: One-year contract with potential for conversion to full-time
Openings: 1
​
Overview
We are seeking an experienced DevOps Info Security Engineer to help design, implement, and maintain security controls across cloud-native and enterprise environments. This role focuses on strengthening security posture through defense-in-depth strategies, compliance alignment, vulnerability management, and secure infrastructure practices in modern DevOps and Kubernetes-based platforms.
​
Key Qualifications and Experience
-
Bachelor’s degree in Computer Science, Systems Analysis, or a related field, or equivalent practical experience
-
CISSP certification (endorsement phase fully completed)
-
5+ years of demonstrated experience across at least four CISSP domains
-
Experience working with compliance and regulatory frameworks such as PCI-DSS and SOC 2
-
Strong understanding of defense-in-depth strategies and implementation of technical controls across enterprise systems
-
Proven ability to assess security gaps and risk across computing systems and operational processes
-
Experience developing and enforcing information security governance, standards, policies, and procedures
-
Hands-on experience conducting vulnerability assessments, including penetration testing, scanning, remediation, and validation
-
Strong experience with cloud-native technologies, particularly Kubernetes, and public cloud environments
-
Solid understanding of networking concepts, protocols, and architectures
-
Strong understanding of security principles related to PKI, TLS, and encryption
-
Experience using host-based and network-based security and assessment tools
-
Experience with identity and access management technologies, including IAM, SSO, RBAC, and AuthN/AuthZ systems
-
Familiarity with CVE databases, vulnerability scoring systems (e.g., CVSS), and security standards such as ISO 27001 and NIST
-
Strong proficiency with Linux/Unix-based operating systems
-
Proficiency in Python and shell scripting for automation and security tooling
Preferred Qualifications
-
Additional security certifications such as CISA, CISM, CGRC, or CRISC
-
Prior experience in a technical or security team lead capacity
