DevSecOps and secure delivery * Embed security testing into CI/CD - static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing ...
DevSecOps and secure delivery * Embed security testing into CI/CD - static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing ...
Design secure, resilient and scalable services using DevSecOps, automation, service-level objectives, observability and effective incident response practices * Develop high-level and low-level ...
Design secure, resilient and scalable services using DevSecOps, automation, service-level objectives, observability and effective incident response practices * Develop high-level and low-level ...
Manager, Platform Technology
Mississauga, ON · On-site
CA$99K - CA$138K/yr
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Quick apply
Manager, Platform Technology
Mississauga, ON · On-site
CA$99K - CA$138K/yr
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
You are adept at modern software development methodologies and are well-versed in DevOps/DevSecOps and Agile methodologies. * You understand the need for and can push Quality Left. You have a keen ...
You are adept at modern software development methodologies and are well-versed in DevOps/DevSecOps and Agile methodologies. * You understand the need for and can push Quality Left. You have a keen ...
Lead Software Engineer, AI & Emerging Tech
CA$163K - CA$255K/yr
Ensure adherence to governance, DevSecOps protocols. Qualifications * Bachelor's degree in computer science, engineering, or a related field; advanced degrees or certifications are an asset. * 6+ ...
Lead Software Engineer, AI & Emerging Tech
CA$163K - CA$255K/yr
Ensure adherence to governance, DevSecOps protocols. Qualifications * Bachelor's degree in computer science, engineering, or a related field; advanced degrees or certifications are an asset. * 6+ ...
Hands-on experience with system administration and DevSecOps support of Linux, Windows, SQL Server, PostgreSQL, and other vendor software. * Software and system architecture and technical ...
Hands-on experience with system administration and DevSecOps support of Linux, Windows, SQL Server, PostgreSQL, and other vendor software. * Software and system architecture and technical ...
Brings specialized subject matter expertise in DevSecOps and secure SDLC controls, including CI/CD pipeline governance, build and release integrity, segregation of duties, change and release ...
Brings specialized subject matter expertise in DevSecOps and secure SDLC controls, including CI/CD pipeline governance, build and release integrity, segregation of duties, change and release ...
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Manager, Platform Technology
Pickering, ON · On-site
CA$99K - CA$138K/yr
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Quick apply
Manager, Platform Technology
Pickering, ON · On-site
CA$99K - CA$138K/yr
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Enforce DevSecOps and zerotrust patterns: OAuth2/OIDC, mTLS, secrets (Vault/KMS), SAST/DAST, threat modeling; ensure privacy, data residency, and compliant deployments (NIST, SOX/ITGC) across AWS ...
Enforce DevSecOps and zerotrust patterns: OAuth2/OIDC, mTLS, secrets (Vault/KMS), SAST/DAST, threat modeling; ensure privacy, data residency, and compliant deployments (NIST, SOX/ITGC) across AWS ...
Manager, Platform Technology
Mississauga, ON · On-site
CA$99K - CA$138K/yr
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Quick apply
Manager, Platform Technology
Mississauga, ON · On-site
CA$99K - CA$138K/yr
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
You'll partner with Engineering, Security, DevSecOps, and Compliance teams to build a compliant cloud environment from the ground up. Your leadership will ensure that security controls aren't just ...
You'll partner with Engineering, Security, DevSecOps, and Compliance teams to build a compliant cloud environment from the ground up. Your leadership will ensure that security controls aren't just ...
Software operations (DevSecOps, Reliability Engineering, observability, support/maintenance, etc.). * Experience with multiple tech stacks and the verification of its functions including QNX, and ...
Software operations (DevSecOps, Reliability Engineering, observability, support/maintenance, etc.). * Experience with multiple tech stacks and the verification of its functions including QNX, and ...
Agile & DevSecOps Enablement - Support Agile ways of working and DevSecOps pipelines to enhance development and deployment processes. * Stakeholder Engagement - Build strong relationships with ...
Agile & DevSecOps Enablement - Support Agile ways of working and DevSecOps pipelines to enhance development and deployment processes. * Stakeholder Engagement - Build strong relationships with ...
Agile Development, DevOps, System Hardening, DevSecOps, Cybersecurity. * Excellent verbal and written communication skills across internal and external organizations. * Ability to prioritize and ...
Agile Development, DevOps, System Hardening, DevSecOps, Cybersecurity. * Excellent verbal and written communication skills across internal and external organizations. * Ability to prioritize and ...
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Agile & DevSecOps Enablement - Support Agile ways of working and DevSecOps pipelines to enhance development and deployment processes. * Stakeholder Engagement - Build strong relationships with ...
Agile & DevSecOps Enablement - Support Agile ways of working and DevSecOps pipelines to enhance development and deployment processes. * Stakeholder Engagement - Build strong relationships with ...
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Drive best practices using Agile and DevSecOps approaches to enable faster, more reliable delivery cycles. * Identify opportunities to improve delivery velocity, reduce technical debt, and optimize ...
Staff Software Developer
Toronto, ON · On-site
Set up end-to-end solution structure, DevSecOps tooling and processes using Octopus Deploy and cloud technologies while taking leadership roles in large projects * Leverage AI coding assistants and ...
Staff Software Developer
Toronto, ON · On-site
Set up end-to-end solution structure, DevSecOps tooling and processes using Octopus Deploy and cloud technologies while taking leadership roles in large projects * Leverage AI coding assistants and ...
You are adept at modern software development methodologies and are well-versed in DevOps/DevSecOps and Agile methodologies. * You understand the need for and can push Quality Left. You have a keen ...
You are adept at modern software development methodologies and are well-versed in DevOps/DevSecOps and Agile methodologies. * You understand the need for and can push Quality Left. You have a keen ...
Devsecops information
See Ontario salary details
$92K - $98.5K
2% of jobs
$98.5K - $105K
2% of jobs
$105K - $111.5K
4% of jobs
$111.5K - $118K
13% of jobs
$120.2K is the 25th percentile. Wages below this are outliers.
$118K - $124.5K
12% of jobs
$124.5K - $131K
12% of jobs
The median wage is $133.1K / yr.
$131K - $137.5K
18% of jobs
$142.8K is the 75th percentile. Wages above this are outliers.
$137.5K - $144K
16% of jobs
$144K - $150.5K
9% of jobs
$150.5K - $157K
5% of jobs
$157K - $163.5K
7% of jobs
$92K
$133K
$163.5K
How much do devsecops jobs pay per year?
What is a DevSecOps?
A DevSecOps job focuses on integrating security into the software development and operations process. Professionals in this role work to automate security measures, ensure compliance, and identify vulnerabilities throughout the development lifecycle. They collaborate with development, operations, and security teams to embed security best practices into CI/CD pipelines. The goal is to create secure software efficiently without slowing down development and deployment.
What are the key skills and qualifications needed to thrive in the DevSecOps position?
To thrive as a DevSecOps professional, you need expertise in secure software development, CI/CD pipelines, cloud infrastructure, automation, and strong knowledge of cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools such as Jenkins, Docker, Kubernetes, Terraform, and security certifications like CISSP or AWS Certified Security are typically required. Strong problem-solving abilities, effective communication, and a collaborative mindset are valuable soft skills. These are essential to ensuring security is integrated throughout the development lifecycle while enabling efficient deployment and cross-team collaboration.
What are some common challenges DevSecOps professionals face on the job?
DevSecOps professionals often navigate the challenge of balancing rapid development cycles with the need for robust security, which requires both technical adaptability and continuous vigilance. They may encounter resistance to adopting new security practices within development teams, making communication and advocacy skills crucial. Additionally, staying updated with evolving security threats and ensuring compliance with industry standards can be demanding. These challenges offer opportunities to make a significant impact on organizational security and to develop expertise in both security and automation, leading to diverse career advancement possibilities.
Is DevSecOps a good career?
What are the most commonly searched types of Devsecops jobs in Ontario?
The most popular types of Devsecops jobs in Ontario are:
What are popular job titles related to Devsecops jobs in Ontario?
For Devsecops jobs in Ontario, the most frequently searched job titles are:
What job categories do people searching Devsecops jobs in Ontario look for?
The top searched job categories for Devsecops jobs in Ontario are:

Job description
As a Staff Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices.
Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team.
You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software.
What you'll doCloud and infrastructure security- Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries.
- Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management.
- Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.
- Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations.
- Strengthen tenant isolation, authorization enforcement, and fine-grained data access controls at the schema, table, row, and column level.
- Help protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, S3, analytics services, and internal tools, including logging and auditability for sensitive-data access.
- Review AI and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions; ensure agents operate strictly within the calling user's permissions; and define secure patterns for approved services such as Amazon Bedrock.
- Identify and help remediate application vulnerabilities, and build tooling and reusable libraries that make the secure path the easy one for engineers.
- Embed security testing into CI/CD - static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing - without creating unnecessary friction for developers.
- Define practical vulnerability-severity, remediation, exception, and escalation standards, and partner with developers to separate real risk from noise and fix root causes.
- Improve software supply-chain security, including build permissions, artifact integrity, dependency governance, and GitHub administration.
- Improve security visibility across cloud infrastructure, applications, identities, endpoints, and SaaS systems, and build alerts and detection logic that are worth acting on.
- Lead investigations and coordinate containment, remediation, and root-cause analysis, supported by clear runbooks, ownership, and escalation paths.
- Run tabletop exercises, and track and communicate security metrics and material risks to technical and business stakeholders.
- Strengthen SSO, MFA, privileged access, and onboarding, offboarding, and access-review processes across AWS, GitHub, Microsoft 365, Entra ID, production systems, and internal SaaS - automating provisioning, entitlement reviews, and evidence collection where practical.
- Translate security and compliance requirements into concrete technical controls, and support customer security reviews, audits, and programs such as SOC 2 and ISO 27001.
- Evaluate third-party tools and integrations for security, privacy, and access-control risk, and help select, consolidate, and rationalize Forma's security tooling for both coverage and cost.
- Maintain clear technical standards and provide practical guidance, training, and mentorship that raises security capability across Engineering.
- Eight or more years of experience in security engineering, cloud security, application security, DevSecOps, or infrastructure engineering.
- Strong hands-on experience securing AWS environments, including IAM, networking, encryption, logging, and secrets management.
- Experience with Terraform, Kubernetes, containers, and security controls in CI/CD pipelines.
- Strong understanding of application and API security, authentication, authorization, and multi-tenant SaaS risks.
- Experience with vulnerability management, threat modelling, incident response, and security automation.
- Ability to write scripts using Python, Bash, PowerShell, or a similar language.
- Strong communication, troubleshooting, and cross-functional collaboration skills.
Strongly preferred
- Experience supporting SOC 2, ISO 27001, privacy programs, or enterprise customer security reviews.
- Experience securing analytics platforms, data pipelines, or systems handling sensitive customer data, including row-level, column-level, or attribute-based access controls.
- Experience with AWS security services, EKS, Datadog, Wiz, Snyk, CrowdStrike, or similar tools.
- Experience securing AI applications, large language models, agents, or Amazon Bedrock workloads.
- Experience in a B2B SaaS or high-growth technology company.
- Relevant security or cloud certifications.
- Build an understanding of Forma's application architecture, AWS environments, deployment processes, data flows, identity systems, and security obligations.
- Meet key partners across Engineering, DevOps, IT, Product, Legal, and Privacy, and agree on how security reviews and escalations will operate.
- Review existing controls, open findings, incidents, access patterns, monitoring, and compliance commitments.
- Identify immediate risks, quick wins, and areas needing deeper assessment.
- Deliver a prioritized security roadmap based on risk, business impact, and engineering effort.
- Begin addressing the highest-priority gaps in cloud access, secrets management, CI/CD security, vulnerability management, and monitoring.
- Introduce or improve a consistent process for threat modelling and security architecture reviews, and define vulnerability-severity, ownership, remediation, and exception standards.
- Assess the current security tool stack for coverage, overlap, and cost, with consolidation recommendations.
- Improve incident-response runbooks, alert ownership, and escalation paths for critical systems, and recommend measurable security objectives and reporting metrics.
The expectation here is momentum, not completion - these should be underway and demonstrably working, not finished.
- A first set of automated security guardrails in place across AWS, Terraform, Kubernetes, GitHub, or CI/CD, with remaining coverage planned and underway.
- Repeatable processes running for vulnerability management, access reviews, security assessments, and incident follow-up, even if still being refined.
- Security reviews completed for the highest-priority product, data, or AI initiatives, with required controls agreed and in progress.
- Improved visibility into high-risk identities, infrastructure changes, and sensitive-data access.
- Progress, key risks, and the next phase of the security roadmap presented to leadership.
Additional Info:
- This position is for an existing vacancy