1

Cloud Devsecops Engineer Jobs in Alberta (NOW HIRING)

... to-end solution structure, DevSecOps tooling and processes using Octopus Deploy and cloud ... Mentor junior engineers on proper standards and techniques to improve their accuracy and efficiency ...

Build scalable cloud-native solutions using modern web, mobile, API, and integration technologies ... Security, compliance, DevSecOps, and SRE best practices. Strongly Preferred: * Experience building ...

AWS Security Specialist / Senior Cloud Security Engineer About the Client Our client is a globally ... DevSecOps implementation experience, familiar with security tool integration in CI/CD pipelines ...

AWS Security Specialist / Senior Cloud Security Engineer About the Client Our client is a globally ... DevSecOps implementation experience, familiar with security tool integration in CI/CD pipelines ...

... or technical cloud certifications such as Azure Fundamentals, Azure Security Engineer, AWS ... Good understanding of IT technologies and practices (DevSecOps, CI/CD) Providing you with the ...

Cloud Devsecops Engineer information

What is a Cloud DevSecOps Engineer?

A Cloud DevSecOps Engineer is a professional who integrates security practices into the DevOps process within cloud environments. They are responsible for automating security measures, ensuring compliance, and identifying vulnerabilities during the development, deployment, and operation of cloud-based applications. Their work bridges the gap between development, operations, and security teams, helping organizations deliver secure, scalable, and resilient applications in the cloud. Typical tasks include implementing security tools, monitoring cloud infrastructure, and responding to security incidents. The role requires a strong understanding of cloud platforms, security frameworks, and automation tools.

What does a Cloud DevSecOps Engineer do?

A Cloud DevSecOps Engineer works closely with development and operations teams to embed security practices at every stage of the software delivery process. This often involves participating in code reviews, automating security scans within CI/CD pipelines, and advising on secure cloud architecture. They serve as a bridge between security and engineering, ensuring that security controls are integrated early and continuously. This collaborative approach fosters a culture of shared responsibility, helping teams deliver secure, high-quality applications more efficiently.

What are the key skills and qualifications needed to thrive as a Cloud DevSecOps Engineer?

To thrive as a Cloud DevSecOps Engineer, you need a solid background in cloud platforms (such as AWS, Azure, or Google Cloud), infrastructure as code, automation, and security best practices, often backed by a relevant degree and certifications like AWS Certified Security or CompTIA Security+. Familiarity with CI/CD tools (Jenkins, GitLab), containerization (Docker, Kubernetes), and security scanning tools (like Snyk or Aqua) is typically required. Strong analytical thinking, problem-solving, and the ability to collaborate across development, operations, and security teams are crucial soft skills. These abilities ensure the secure, efficient, and scalable delivery of cloud-native applications by integrating security into every step of the development lifecycle.

What is the difference between Cloud Devsecops Engineer vs Cloud Security Engineer?

AspectCloud Devsecops EngineerCloud Security Engineer
Primary FocusIntegrating security into DevOps processes, automating security in CI/CD pipelinesImplementing and managing security measures specifically for cloud environments
Skills & CertificationsCloud platforms, DevOps tools, security automation, certifications like AWS DevOps Engineer, CISSPCloud security frameworks, encryption, compliance, certifications like CCSK, CISSP
Work EnvironmentCollaborates with development and operations teams, focuses on automation and continuous integrationWorks with security teams, cloud administrators, focuses on threat mitigation and compliance
Industry UsageCommon in organizations adopting DevOps with cloud infrastructureCommon in organizations prioritizing cloud security and compliance

While both roles focus on cloud security, the Cloud Devsecops Engineer emphasizes integrating security into development pipelines and automation, whereas the Cloud Security Engineer concentrates on implementing security measures and compliance within cloud environments.

What cities in Alberta are hiring for Cloud Devsecops Engineer jobs?

Cities in Alberta with the most Cloud Devsecops Engineer job openings:

Senior Cloud Security Engineer, Information Security

Calgary, AB • On-site

Peoples Group
Investment Clubs and Venture Capital Companies • 1 - 10 employees

Full-time

PTO

Re-posted 20 days ago


Job description

We are hiring for this position out of our Toronto, Vancouver and Calgary offices. Successful candidates who apply outside of these areas will be expected to relocate and reside in a location that is within a commutable distance. 

About the role:

We’re hiring a Senior DevSecOps Engineer with 8–10+ years of experience, deep multi-cloud expertise (AWS + Azure), strong Terraform and the ability to drive technical strategy across a regulated financial institution. This is a senior individual contributor role. You’ll set technical direction for DevSecOps, partner with the AVP of Corporate Information Security on strategy, mentor and grow the team, and personally own the hardest pieces of work. You’ll be a primary point of contact for engineering leadership, audit, and external regulators when DevSecOps topics come up.

About the day-to-day:

Technical leadership and strategy (~30%)

  • Build and evolve the DevSecOps technical strategy across CI/CD, IaC, secure cloud architecture, detection, and compliance automation.
  • Partner with the AVP of Corporate Information Security and the Team Lead, DevSecOps, on the security roadmap; translate risk decisions into engineering work.
  • Collaborate on architecture decisions and ADRs for the DevSecOps platform. Champion paved roads and golden paths over one-off solutions.
  • Lead vendor evaluations and POCs for security tooling. Make the build-vs-buy argument with the data to back it up.
  • Develop and maintain a Security Centre of Excellence for all new products and substantial changes, ensuring security requirements are met before they reach production.
  • Represent DevSecOps to engineering leadership, audit (internal and external), and regulators on technical questions.

Hands-on engineering (~40%)

  • Personally architect and build the hardest pieces: the IaC pipeline that gates all production change, the cross-cloud detection fabric, the SBOM/supply-chain integrity program, the secrets management migration.
  • Drive the AWS-to-Azure migration of applications as a senior security engineering owner: design target-state controls in Azure, run gap analysis against AWS, validate equivalence before workload cutover.
  • Architect and review Terraform at scale: module strategy, state isolation, workspace patterns, drift detection, breaking-change management.
  • Implement and operate policy-as-code across the SDLC: PR-time, pipeline-time, deploy-time, and runtime enforcement.
  • Lead implementation of supply-chain security: signed builds (Sigstore/cosign), SBOM generation and storage, SLSA-aligned provenance, dependency pinning, runner isolation.
  • Integrate, monitor, and tune SAST/DAST platforms across CI/CD pipelines.
  • Build out Zero Trust patterns: workload identity federation, conditional access, just-in-time access and microsegmentation.
  • Publish and disseminate CI/CD best practices, patterns, and solutions across product engineering teams.

Compliance, audit, and risk (~20%)

  • Own the threat-modeling program: set the methodology (STRIDE, LINDDUN, attack-tree, MITRE ATT&CK-mapped), train others on it, ensure outputs become real backlog items.
  • Be an engineering owner of control evidence for SOC 2, PCI-DSS and applicable Canadian regulatory expectations.
  • Automate audit evidence collection wherever feasible: replace screenshot-based evidence with API-pulled, signed, dated artifacts.
  • Contribute to the cybersecurity risk register and risk treatment plans; partner with GRC and Operational Risk Management.
  • Make the case to regulators and auditors that controls are designed effectively and operating effectively.
  • Stay current on emerging threats and regulatory changes in cloud security, AI, and automation; apply innovative solutions to enhance the security framework.

People and team (~10%)

  • Mentor Intermediate and Junior DevSecOps engineers: set development goals, do code reviews that teach, sponsor stretch projects.
  • Build the team's documentation and onboarding so it scales with hires.
  • Contribute to a healthy on-call culture: sustainable rotations, blameless retros, runbook quality.

Nice to have / differentiators:

  • Canadian regulated financial services experience (banking, trust company, credit union, fintech sponsor bank).
  • Active certifications: CISSP, CCSP, OSCP/CPTS, AWS Security Specialty, Azure SC-100, AZ-500, AZ-400, CKS, HashiCorp Terraform Associate/Pro.
  • Prior Security Centre of Excellence experience: stood one up, or served as the lead engineer inside one.
  • Supply-chain security: Sigstore, in-toto, SLSA, SBOM (CycloneDX/SPDX), Dependency Track.
  • Offensive security background: OSCP, real red-team/purple-team engagements, CTF placement.
  • AI/LLM security experience: secure agent design, prompt-injection defenses, model supply-chain integrity.

About us:  

Peoples Group is a trusted financial services company for the innovators at the forefront of Canada’s economic future. With offices in Vancouver, Calgary and Toronto, we are driving change by working alongside challenger banks, fintechs, brokers, and merchants to foster a dynamic and competitive financial ecosystem. 

Our culture is built on four core behaviors: Grit to GrowConnect to CollaboratePutting Clients First, and Owning the Outcome. We believe people do not simply choose a company to work for—they choose a company that makes a positive impact in the lives of Canadians. Above all, we value people, build meaningful relationships, focus on individual strengths, and approach our work with passion. 

About the work environment: 

Peoples Group offers a flexible and hybrid work environment. In this role you will work a combination of in-office and remotely from home. Typically, you'll be working regular business hours, Monday to Friday between 8:00am and 4:30pm with flexibility around start/end times. 

The role requires the candidate to participate in on-call, acting as an escalation path in the event of a severe incident.

We offer: 

  • A hybrid work environment, enabling you to balance your personal and professional life seamlessly. 
  • Competitive salaries, profit sharing, RRSP matching and benefits from day one. 
  • Generous paid time off to help achieve a healthy work-life balance. 
  • A strengths-based approach, ensuring we work together more effectively. 
  • A commitment to your well-being in five key areas: Financial, Physical, Social, Career, and Community. 

Hiring process:  

If your application is selected, you will be invited for a first interview with one of our Talent Acquisition Business Partners. Depending on the role, interviews may be conducted virtually or in-person. The hiring team will communicate any in-person requirements throughout the process.

Compensation:

The expected salary for this role is approximately $125,000.00 - $145,000.00 annually. Actual compensation may vary based on experience, skills, and qualifications. 

NOTE: This job posting is for an existing vacancy. Peoples Group is an Equal Employment Opportunity employer. Please accept our utmost appreciation for your interest; however, only those applicants under consideration will be contacted.  

We value and celebrate individuality while fostering an inclusive workplace for everyone. If there's any way we can support or accommodate you during the selection process, please don't hesitate to let us know.