BeyondTrust Logo

BeyondTrust

Staff DevSecOps Engineer

Reposted 14 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in Canada
Senior level
Remote
Hiring Remotely in Canada
Senior level
As a Staff DevSecOps Engineer, you will lead the implementation of security practices across the software development lifecycle, focusing on CI/CD secure pipelines and automation, while collaborating with various teams to enhance security measures and compliance.
The summary above was generated by AI

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cyber security SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

As a Staff DevSecOps Engineer, you will help develop and implement our Engineering team’s DevSecOps strategy, with a strong focus on Static Application Security Testing (SAST) and CI/CD tooling. You will architect, implement, and scale security practices across our software development lifecycle, enabling secure and seamless deployments while maintaining compliance and governance standards. This role demands technical leadership, collaboration across teams, and a deep understanding of DevOps, security, and software development workflows.

What You’ll Do

  • Develop best practices and tooling for implementing a DevSecOps approach that helps secure BeyondTrust’s CI/CD while enabling our Engineering teams to adopt these approaches seamlessly.
  • Collaborate with cross-functional teams, including application security engineers, Engineering leadership, software engineers, SREs, and product managers, to drive secure development initiatives.
  • Secure our codebases and pipelines from misuse, bad coding practices, vulnerable dependencies, and exposed secrets.

What You’ll Bring

  • Develop and implement tooling for Static Application Security Testing (SAST) along with improving analytics in Github Security Centre.
  • Implement a robust end-to-end process in partnership with Application Security teams for Code Scanning, Secret Scanning, and Dependency Reviews.
  • Establish and enforce policies for secure code development and vulnerability management.
  • Automate remediation workflows to streamline vulnerability fixes and improve code quality.

CI/CD Tooling and Pipeline Security

  • Design and enhance secure CI/CD pipelines to ensure secure, automated, and reliable software delivery.
  • Implement guardrails and security checks (e.g., static/dynamic analysis, software composition analysis) into CI/CD pipelines.
  • Standardize and optimize tools like Jenkins, GitHub Actions, Azure DevOps, or other CI/CD platforms.

Security by Design

  • Champion secure coding practices and lead efforts to embed security in all stages of the SDLC.
  • Collaborate with development teams to identify and mitigate risks early in the development lifecycle.
  • Provide technical leadership for implementing industry best practices in application security and cloud-native environments.

Automation and Infrastructure Security

  • Develop and manage infrastructure-as-code (IaC) security processes.
  • Automate security tasks, including testing, monitoring, and alerting for potential threats.
  • Drive continuous improvement through automated patch management and dependency updates.

Compliance and Governance

  • Ensure CI/CD and GitHub workflows comply with regulatory requirements (e.g., SOC 2, GDPR).
  • Develop and maintain metrics and reporting to demonstrate the Engineering teams' security program effectiveness.

Leadership and Collaboration

  • Serve as a subject-matter expert and mentor for engineers on DevOps and DevSecOps principles and tooling.
  • Lead incident response and forensic investigations related to DevSecOps environments.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, or a related field; advanced degree preferred.
  • 10+ years of experience in Operations, DevOps, DevSecOps, or related engineering roles.
  • Expertise in building out application security pipelines and CI/CD platforms using tools such as GitHub Actions, Jenkins, and/or Azure DevOps.
  • Proficiency in programming/scripting languages like Python, Go, or Typescript.
  • Hands-on experience with IaC tools (Terraform, OpenTofu, CloudFormation) and cloud platforms (AWS, Azure).
  • Strong understanding of application security, container security (Docker, Kubernetes), and cloud security (AWS or Azure Services) .
  • Knowledge of modern software delivery paradigms, including microservices and serverless architectures.
  • Familiarity with security frameworks and standards (OWASP, NIST, CIS).
  • Exceptional problem-solving skills, communication, and ability to work in a fast-paced environment.

Nice To Have

  • Certifications such as AWS Certified Security, Certified DevSecOps Professional, or CISSP.
  • Experience with SAST/DAST tools like SonarQube or Burp Suite.
  • Experience hardening SCM codebases using tools such as Legitify, Scorecard or Allstar.
  • Experience rolling out GenAI tools for Software Engineers with a Security-First approach.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the worldwide leader in intelligent identity and access security, enabling organizations to protect identities, stop threats, and deliver dynamic access. We are leading the charge in innovating identity-first security and are trusted by 20,000 customers, including 75 of the Fortune 100, plus a global ecosystem of partners.

Learn more at www.beyondtrust.com. 

#LI-BS1

Top Skills

AWS
Azure
Azure Devops
Burp Suite
Ci/Cd
CloudFormation
Docker
Github Actions
Go
Jenkins
Kubernetes
Opentofu
Python
Sonarqube
Static Application Security Testing (Sast)
Terraform
Typescript

Similar Jobs

Yesterday
Easy Apply
Remote
Hybrid
Canada
Easy Apply
Senior level
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
The Senior Security Engineer will manage Samsara’s security systems, support engineering teams, document processes, mentor junior engineers, and enhance the security posture of the company.
Top Skills: Aws LambdaCrowdstrikePythonSplunkTerraformTinesWizZscaler
2 Days Ago
Remote
Hybrid
Toronto, ON, CAN
Senior level
Senior level
Gaming • Information Technology • Mobile • Software
As an Application Security Architect, you will ensure security in product development by conducting assessments, shaping standards, and mentoring teams. You'll create threat models and design secure architectures while ensuring compliance with security protocols.
Top Skills: Ci/Cd PipelinesCloud InfrastructureContainerized Environments
2 Days Ago
Remote
Hybrid
9 Locations
Senior level
Senior level
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
As an EUC NALA Lead, manage IT infrastructure supporting end users, lead a team, implement new technologies, and ensure compliance and user experience.
Top Skills: AndroidApplication PackagingBigfixEncryptioniOSmacOSMdmVirtual Desktop InfrastructureWindows

What you need to know about the Montreal Tech Scene

With roots dating back to 1642, Montreal is often recognized for its French-inspired architecture and cobblestone streets lined with traditional shops and cafés. But what truly sets the city apart is how it blends its rich tradition with a modern edge, reflected in its evolving skyline and fast-growing tech industry. According to economic promotion agency Montréal International, the city ranks among the top in North America to invest in artificial intelligence, making it le spot idéal for job seekers who want the best of both worlds.

Key Facts About Montreal Tech

  • Number of Tech Workers: 255,000+ (2024, Tourisme Montréal)
  • Major Tech Employers: SAP, Google, Microsoft, Cisco
  • Key Industries: Artificial intelligence, machine learning, cybersecurity, cloud computing, web development
  • Funding Landscape: $1.47 billion in venture capital funding in 2024 (BetaKit)
  • Notable Investors: CIBC Innovation Banking, BDC Capital, Investissement Québec, Fonds de solidarité FTQ
  • Research Centers and Universities: McGill University, Université de Montréal, Concordia University, Mila Quebec, ÉTS Montréal

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account