About the role: We're hiring a Senior DevSecOps Engineer with 8-10+ years of experience, deep multi-cloud expertise (AWS + Azure), strong Terraform and the ability to drive technical strategy across ...
About the role: We're hiring a Senior DevSecOps Engineer with 8-10+ years of experience, deep multi-cloud expertise (AWS + Azure), strong Terraform and the ability to drive technical strategy across ...
Application Security Engineer (AppSec) - Public Sector
Sherwood Park, AB ยท Remote
CA$30/hr
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Quick apply
Application Security Engineer (AppSec) - Public Sector
Sherwood Park, AB ยท Remote
CA$30/hr
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Application Security Engineer (AppSec) - Public Sector
Spruce Grove, AB ยท Remote
CA$30/hr
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Quick apply
Application Security Engineer (AppSec) - Public Sector
Spruce Grove, AB ยท Remote
CA$30/hr
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Application Security Engineer (AppSec) - Public Sector
Edmonton, AB ยท Remote
CA$30/hr
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Quick apply
Application Security Engineer (AppSec) - Public Sector
Edmonton, AB ยท Remote
CA$30/hr
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Application Security Engineer (AppSec) - Public Sector
Saint Albert, AB ยท Remote
CA$30/hr
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Quick apply
Application Security Engineer (AppSec) - Public Sector
Saint Albert, AB ยท Remote
CA$30/hr
Edmonton, Alberta About the Role We are seeking an Application Security Engineer to secure enterprise applications through secure development, DevSecOps, and application security testing practices.
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Quick apply
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Quick apply
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Quick apply
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Application Security Engineer (AppSec) - BFSI - 0604 AS #5
Spruce Grove, AB ยท On-site
CA$30/hr
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Quick apply
Application Security Engineer (AppSec) - BFSI - 0604 AS #5
Spruce Grove, AB ยท On-site
CA$30/hr
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Quick apply
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Quick apply
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Implement secure SDLC and DevSecOps practices. * Assist development teams with remediation activities. * Develop application security standards and controls. Required Qualifications * 5+ years of ...
Devsecops information
See Alberta salary details
$92K - $98.5K
2% of jobs
$98.5K - $105K
2% of jobs
$105K - $111.5K
4% of jobs
$111.5K - $118K
13% of jobs
$120.2K is the 25th percentile. Wages below this are outliers.
$118K - $124.5K
12% of jobs
$124.5K - $131K
12% of jobs
The median wage is $133.1K / yr.
$131K - $137.5K
18% of jobs
$142.8K is the 75th percentile. Wages above this are outliers.
$137.5K - $144K
16% of jobs
$144K - $150.5K
9% of jobs
$150.5K - $157K
5% of jobs
$157K - $163.5K
7% of jobs
$92K
$133K
$163.5K
How much do devsecops jobs pay per year?
What is a DevSecOps job?
A DevSecOps job focuses on integrating security into the software development and operations process. Professionals in this role work to automate security measures, ensure compliance, and identify vulnerabilities throughout the development lifecycle. They collaborate with development, operations, and security teams to embed security best practices into CI/CD pipelines. The goal is to create secure software efficiently without slowing down development and deployment.
What are the key skills and qualifications needed to thrive in the Devsecops position, and why are they important?
To thrive as a DevSecOps professional, you need expertise in secure software development, CI/CD pipelines, cloud infrastructure, automation, and strong knowledge of cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools such as Jenkins, Docker, Kubernetes, Terraform, and security certifications like CISSP or AWS Certified Security are typically required. Strong problem-solving abilities, effective communication, and a collaborative mindset are valuable soft skills. These are essential to ensuring security is integrated throughout the development lifecycle while enabling efficient deployment and cross-team collaboration.
What are some common challenges DevSecOps professionals face on the job?
DevSecOps professionals often navigate the challenge of balancing rapid development cycles with the need for robust security, which requires both technical adaptability and continuous vigilance. They may encounter resistance to adopting new security practices within development teams, making communication and advocacy skills crucial. Additionally, staying updated with evolving security threats and ensuring compliance with industry standards can be demanding. These challenges offer opportunities to make a significant impact on organizational security and to develop expertise in both security and automation, leading to diverse career advancement possibilities.

Full-time
PTO
Posted 12 days ago
Job description
We areย hiring forย this position out of ourย Toronto,ย Vancouverย and Calgaryย offices.ย Successful candidates who apply outside of these areas will be expected toย relocateย andย resideย in a location that is within a commutable distance.ย
About the role:
Weโre hiring a Senior DevSecOps Engineer with 8โ10+ years of experience, deep multi-cloud expertise (AWS + Azure), strong Terraform and the ability to drive technical strategy across a regulated financial institution. This is a senior individual contributor role. Youโll set technical direction for DevSecOps, partner with the AVP of Corporate Information Security on strategy, mentor and grow the team, and personally own the hardest pieces of work. Youโll be a primary point of contact for engineering leadership, audit, and external regulators when DevSecOps topics come up.
About the day-to-day:
Technical leadership and strategy (~30%)
- Build and evolve the DevSecOps technical strategy across CI/CD, IaC, secure cloud architecture, detection, and compliance automation.
- Partner with the AVP of Corporate Information Security and the Team Lead, DevSecOps, on the security roadmap; translate risk decisions into engineering work.
- Collaborate on architecture decisions and ADRs for the DevSecOps platform. Champion paved roads and golden paths over one-off solutions.
- Lead vendor evaluations and POCs for security tooling. Make the build-vs-buy argument with the data to back it up.
- Develop and maintain a Security Centre of Excellence for all new products and substantial changes, ensuring security requirements are met before they reach production.
- Represent DevSecOps to engineering leadership, audit (internal and external), and regulators on technical questions.
Hands-on engineering (~40%)
- Personally architect and build the hardest pieces: the IaC pipeline that gates all production change, the cross-cloud detection fabric, the SBOM/supply-chain integrity program, the secrets management migration.
- Drive the AWS-to-Azure migration of applications as a senior security engineering owner: design target-state controls in Azure, run gap analysis against AWS, validate equivalence before workload cutover.
- Architect and review Terraform at scale: module strategy, state isolation, workspace patterns, drift detection, breaking-change management.
- Implement and operate policy-as-code across the SDLC: PR-time, pipeline-time, deploy-time, and runtime enforcement.
- Lead implementation of supply-chain security: signed builds (Sigstore/cosign), SBOM generation and storage, SLSA-aligned provenance, dependency pinning, runner isolation.
- Integrate, monitor, and tune SAST/DAST platforms across CI/CD pipelines.
- Build out Zero Trust patterns: workload identity federation, conditional access, just-in-time access and microsegmentation.
- Publish and disseminate CI/CD best practices, patterns, and solutions across product engineering teams.
Compliance, audit, and risk (~20%)
- Own the threat-modeling program: set the methodology (STRIDE, LINDDUN, attack-tree, MITRE ATT&CK-mapped), train others on it, ensure outputs become real backlog items.
- Be an engineering owner of control evidence for SOC 2, PCI-DSS and applicable Canadian regulatory expectations.
- Automate audit evidence collection wherever feasible: replace screenshot-based evidence with API-pulled, signed, dated artifacts.
- Contribute to the cybersecurity risk register and risk treatment plans; partner with GRC and Operational Risk Management.
- Make the case to regulators and auditors that controls are designed effectively and operating effectively.
- Stay current on emerging threats and regulatory changes in cloud security, AI, and automation; apply innovative solutions to enhance the security framework.
People and team (~10%)
- Mentor Intermediate and Junior DevSecOps engineers: set development goals, do code reviews that teach, sponsor stretch projects.
- Build the team's documentation and onboarding so it scales with hires.
- Contribute to a healthy on-call culture: sustainable rotations, blameless retros, runbook quality.
Nice to have / differentiators:
- Canadian regulated financial services experience (banking, trust company, credit union, fintech sponsor bank).
- Active certifications: CISSP, CCSP, OSCP/CPTS, AWS Security Specialty, Azure SC-100, AZ-500, AZ-400, CKS, HashiCorp Terraform Associate/Pro.
- Prior Security Centre of Excellence experience: stood one up, or served as the lead engineer inside one.
- Supply-chain security: Sigstore, in-toto, SLSA, SBOM (CycloneDX/SPDX), Dependency Track.
- Offensive security background: OSCP, real red-team/purple-team engagements, CTF placement.
- AI/LLM security experience: secure agent design, prompt-injection defenses, model supply-chain integrity.
About us:ย ย
Peoples Group is a trusted financial services company for the innovators at the forefront of Canadaโs economic future. With offices in Vancouver,ย Calgaryย and Toronto, we are driving change by working alongside challenger banks, fintechs, brokers, and merchants to foster a dynamic and competitive financial ecosystem.ย
Our culture is built on four coreย behaviors:ย Grit to Grow,ย Connect to Collaborate,ย Putting Clients First, andย Owning the Outcome. We believe people do not simply choose a company to work forโthey choose a company that makes a positive impact in the lives of Canadians.ย Above all, weย value people, build meaningful relationships, focus on individual strengths, and approach our work with passion.ย
About the work environment:ย
Peoples Group offers a flexible and hybrid work environment. In this role you will work a combination of in-office and remotely from home. Typically,ย you'llย be working regular business hours, Monday to Friday between 8:00am and 4:30pm with flexibility around start/end times.ย
The role requires the candidate to participate in on-call, acting as an escalation path in the event of a severe incident.
We offer:ย
- A hybrid work environment, enabling you to balance your personal and professional life seamlessly.ย
- Competitive salaries, profit sharing, RRSP matching and benefits from day one.ย
- Generous paid time off to help achieve a healthy work-life balance.ย
- Aย strengths-based approach,ย ensuringย we work together more effectively.ย
- A commitment to your well-being in five key areas: Financial, Physical, Social, Career, and Community.ย
Hiring process:ย ย
If your application is selected, you will be invited for a first interview with one of our Talent Acquisition Business Partners. Depending on the role, interviews may be conducted virtually orย in-person. The hiring team will communicate any in-person requirements throughout the process.
Compensation:
The expected salary for this role isย approximatelyย $125,000.00ย - $145,000.00ย annually. Actual compensation may vary based on experience, skills, and qualifications.ย
NOTE: Thisย job posting is for an existing vacancy. Peoples Group is an Equal Employment Opportunity employer. Please accept our utmost appreciation for your interest; however, only those applicants under consideration will be contacted.ย ย
We value and celebrate individuality while fostering an inclusive workplace for everyone. Ifย there'sย any way we can support or accommodate you during the selection process, pleaseย don'tย hesitate to let us know.ย
About People's Group
Sourced by ZipRecruiter
Industry
Investment clubs and venture capital companies
Company size
1 - 10 Employees
Headquarters location
Alameda, CA, US
Year founded
2021