Talent.com
DevSecOps Specialist
DevSecOps SpecialistConstruction Virtuelle et Technologie BI • Québec, QC, Canada
No longer accepting applications
DevSecOps Specialist

DevSecOps Specialist

Construction Virtuelle et Technologie BI • Québec, QC, Canada
30+ days ago
Job type
  • Full-time
Job description

Job Description

Job Description

At Newforma, you’ll help shape the future of project information management for architects, engineers, and contractors worldwide. Join a team that’s trusted by over 1,500 firms to simplify how they work. Together, we’re creating tools that connect people to the information they need, faster and smarter. Let’s build something great.

We're seeking a DevSecOps Specialist to join our Platform Engineering team and play a pivotal role in establishing and evolving our security-first culture. As Newforma undergoes a strategic migration from Azure to AWS, you'll be instrumental in building secure, automated infrastructure and embedding security practices throughout our software development lifecycle. This is an opportunity to shape the DevSecOps foundation for a platform trusted by hundreds of thousands of users managing sensitive project data across the construction industry.

In this role, your responsibilities will include:

Security Leadership & Culture

  • Champion DevSecOps principles across engineering teams, fostering a culture where security is everyone's responsibility.
  • Establish and evangelize security best practices, secure coding standards, and threat modeling approaches.
  • Mentor and guide development teams on security automation, vulnerability management, and secure architecture patterns.
  • Lead by example, demonstrating how to balance security requirements with development velocity and business needs.
  • Conduct security training sessions and create documentation to elevate the organization's security awareness.
  • Partner with engineering leadership to define and track security metrics and KPIs.

AWS Security & Infrastructure

  • Support team to design and implement secure cloud infrastructure on AWS, following the AWS Well-Architected Framework security pillar.
  • Architect and maintain Identity and Access Management (IAM) policies, roles, and service control policies across AWS accounts.
  • Support team to implement security controls using AWS services including GuardDuty, Security Hub, Config, CloudTrail, and WAF.
  • Design and enforce network security using VPCs, security groups, NACLs, and AWS PrivateLink.
  • Establish secrets management strategies using AWS Secrets Manager and Parameter Store.
  • Lead the security aspects of the Azure-to-AWS migration, ensuring secure architecture patterns and data protection.
  • Implement infrastructure-as-code security scanning and policy enforcement using tools like Checkov, tfsec, or AWS CDK.

CI/CD Security & Automation

  • Build and maintain secure CI/CD pipelines integrating security scanning at every stage of the development lifecycle.
  • Implement automated security testing including SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), and SCA (Software Composition Analysis).
  • Integrate container security scanning and image vulnerability assessment into build pipelines.
  • Automate compliance checks and security policy enforcement in deployment workflows.
  • Design and implement automated remediation workflows for common security findings.
  • Establish secure artifact management and software supply chain security practices.

Vulnerability & Compliance Management

  • Implement and maintain vulnerability scanning and management programs for applications, containers, and infrastructure.
  • Establish processes for triaging, tracking, and remediating security vulnerabilities.
  • Ensure compliance with industry standards and regulations relevant to the AECO industry.
  • Conduct regular security assessments, penetration testing coordination, and security audits.
  • Develop and maintain incident response playbooks and participate in security incident response.
  • Create and maintain security baselines and hardening standards for systems and applications.

Monitoring & Incident Response

  • Design and implement security monitoring, logging, and alerting solutions using CloudWatch, CloudTrail, and SIEM tools.
  • Establish threat detection and response capabilities for cloud infrastructure and applications.
  • Build automated alerting and response mechanisms for security events.
  • Conduct security investigations and root cause analysis for security incidents.
  • Implement and maintain disaster recovery and business continuity plans from a security perspective.

Collaboration & Integration

  • Work on security initiatives in collaboration with other members of the platform engineering team.
  • Work closely with development teams to integrate security into all aspects of the SDLC.
  • Collaborate with the Lead Software Architect to ensure security considerations in architectural decisions.
  • Partner with compliance and legal teams on security requirements and audit preparation.
  • Engage with third-party security vendors and manage security tooling evaluation and implementation.
  • Participate in agile ceremonies including daily stand-ups, sprint planning, and retrospectives.

Requirements for the position include:

  • 7+ years of experience in DevOps, Security Engineering, or related roles with at least 3 years focused on DevSecOps practices.
  • Strong hands-on experience with AWS security services and best practices, including IAM, Security Hub, GuardDuty, Config, KMS, and CloudTrail.
  • Proven track record of implementing security automation and integrating security into CI/CD pipelines.
  • Deep understanding of infrastructure-as-code security (Pulumi, Terraform, AWS CDK, CloudFormation).
  • Experience with container security, including Docker, Kubernetes/EKS security, and container image scanning.
  • Proficiency with security scanning tools such as SonarQube, Snyk, Aqua Security, Prisma Cloud, or similar.
  • Strong knowledge of application security principles, OWASP Top 10, and secure coding practices.
  • Experience with scripting and automation using Python, Bash, or PowerShell.
  • Understanding of network security, encryption, certificate management, and secrets management.
  • Familiarity with compliance frameworks (SOC 2, ISO 27001, GDPR) and security audit processes.
  • Excellent communication skills with ability to explain complex security concepts to diverse audiences.
  • Experience mentoring and influencing engineering teams on security best practices.
  • Bachelor's degree in Computer Science, Information Security, or related field.

Nice to have qualifications for this position include:

  • AWS Security certifications (AWS Certified Security - Specialty, AWS Solutions Architect, or similar).
  • Additional security certifications such as CISSP, CEH, GIAC, or OSCP.
  • Experience migrating security controls and practices from Azure to AWS.
  • Hands-on experience with Azure security services (Azure Security Center, Defender, Sentinel).
  • Knowledge of .NET/C# application security and secure development practices.
  • Experience with React or frontend security considerations.
  • Familiarity with Kubernetes security tools and practices (admission controllers, policy engines, runtime security).
  • Experience with DevSecOps in SaaS/multi-tenant environments.
  • Knowledge of security considerations for document management and file storage systems.
  • Experience with API security, OAuth 2.0, SAML, and identity federation.
  • Familiarity with supply chain security and SBOM (Software Bill of Materials) practices.
  • Experience with security aspects of AI/ML systems and data protection
  • Bilingual in French and English.

Why Work at Newforma?

  • Purpose-driven work: Help professionals in the AECO industry solve real-world challenges.
  • Global impact: Our tools are used on over 16 million projects worldwide.
  • Collaborative culture: Work alongside talented teammates who value your input.
  • Room to grow: We support your career development through learning opportunities and mentorship.
  • Innovation at its core: Be part of a company that’s always evolving to meet industry needs.

Create a job alert for this search

DevSecOps Specialist • Québec, QC, Canada

Similar jobs
Operations Specialist - lévis

Operations Specialist - lévis

MatchaCFO • lévis, qc, ca
Full-time
MatchaCFO is a fractional, AI-enabled COO, CFO, accounting, and data services firm based in Silicon Valley.Seed through Series C—with full-stack financial operations, including FP&A, accounting, an...Show more
Last updated: 17 days ago • Promoted
Cloud Consultant - lévis

Cloud Consultant - lévis

HCLTech • lévis, qc, ca
Full-time
Own production support for all Dayforce ↔ Indeavor integrations including:.Monitor scheduled Logic Apps and Durable Functions.Perform root cause analysis for failed jobs using Application Insights ...Show more
Last updated: 17 days ago • Promoted
Azure DevOps Engineer - lévis

Azure DevOps Engineer - lévis

LTIMindtree • lévis, qc, ca
Full-time
LTIMindtree is an equal opportunity employer that is committed to diversity in the workplace.Our employment decisions are made without regard to race, color, creed, religion, sex (including pregnan...Show more
Last updated: 30+ days ago • Promoted
Dev/DevOps C# – Orchestrade

Dev/DevOps C# – Orchestrade

Evolvic Inc. • Quebec, Capitale-Nationale, CA
Full-time
This position is part of a strategic initiative to strengthen and optimize the Orchestrade Core environment — a key platform supporting multiple financial business lines including Front Office, Mid...Show more
Last updated: 30+ days ago • Promoted
Transformation-DevOps Engineer (GitLab Actions & CI/CD Pipeline)

Transformation-DevOps Engineer (GitLab Actions & CI/CD Pipeline)

E-Solutions • Quebec, Capitale-Nationale, CA
Full-time
Our parent company Iver has 1, employees today and is growing and now we are looking for new employees who want to join our journey.As part of Accelerate at Iver, you are at the absolute forefront ...Show more
Last updated: 3 days ago • Promoted
Expert in Infrastructure Management with Linux and DevOps Focus

Expert in Infrastructure Management with Linux and DevOps Focus

Services SFT • Quebec, Capitale-Nationale, CA
Full-time
Drive operational efficiency as a Senior Operations Consultant.Utilize your advanced Linux skills and automated solutions to optimize performance and security across client infrastructures.This piv...Show more
Last updated: 2 days ago • Promoted
Senior DevOps Specialist

Senior DevOps Specialist

360.Agency Inc. • Courbe Québec, QC, CA
Full-time
Ready to make a lasting impact with a dynamic and innovative company? Join the.We’re experts in creating web and marketing solutions tailored for the automotive sector.Yo u will support our organiz...Show more
Last updated: 30+ days ago • Promoted
DevSecOps Analyst

DevSecOps Analyst

Alithya Group • Quebec, Capitale-Nationale, CA
Full-time
En tant qu’analyste DevSecOps, vous serez responsable de soutenir la conception, l’évolution et la qualité de nos solutions technologiques.Vous vous appliquerez à comprendre les besoins des utilisa...Show more
Last updated: 20 days ago • Promoted
Cloud Support Engineer

Cloud Support Engineer

Quantum World Technologies Inc. • saint-augustin-de-desmaures, QC, ca
Full-time
Role - Azure Operations EngineerDuration: Long-Term Contract Location: Canada, remoteNo.JD:As an Azure Operations Engineer with Terraform, you will be responsible for ...Show more
Last updated: 4 days ago • Promoted
Senior DevOps Engineer – Real-Time Streaming & CI/CD

Senior DevOps Engineer – Real-Time Streaming & CI/CD

E-Solutions • Quebec, Capitale-Nationale, CA
Full-time
A leading cloud technology firm is seeking a Senior DevOps Engineer for its Canadian operations.In this fully remote role, you will design and manage scalable cloud-native infrastructure, focusing ...Show more
Last updated: 3 days ago • Promoted
Développeur DevOps / DevOps Developer

Développeur DevOps / DevOps Developer

GoTo • Quebec, Capitale-Nationale, CA
Full-time
Job Description**Participer aux activités de support et d’astreinte (on-call), en maintenant de hauts standards de qualité et de fiabilité afin de garantir la performance de la plateforme et de lim...Show more
Last updated: 17 hours ago • Promoted • New!
Spécialiste DevOps - Développeur applicatif / DevOps Specialist - Application Developer

Spécialiste DevOps - Développeur applicatif / DevOps Specialist - Application Developer

PayFacto • Quebec, Capitale-Nationale, CA
Full-time
Employer Industry: Cloud Services and Application Development.Why consider this job opportunity.Medical and dental coverage starting from Day 1.RRSP matching contributions from the employer.Vacatio...Show more
Last updated: 30+ days ago • Promoted
Cloud DevOps & App Developer — Remote, AWS & CI/CD

Cloud DevOps & App Developer — Remote, AWS & CI/CD

PayFacto • Quebec, Capitale-Nationale, CA
Remote
Full-time
A leading cloud services company located in Quebec is seeking an experienced professional to design and deploy cloud-native applications.The ideal candidate will have over 5 years of experience man...Show more
Last updated: 30+ days ago • Promoted
Azure DevOps Engineer

Azure DevOps Engineer

LTIMindtree • saint-augustin-de-desmaures, QC, ca
Full-time
LTIMindtree is an equal opportunity employer that is committed to diversity in the workplace.Our employment decisions are made without regard to race, color, creed, religion, sex (including pregnan...Show more
Last updated: 30+ days ago • Promoted
DevOps Senior — CI/CD, Cloud & Horaires flexibles

DevOps Senior — CI/CD, Cloud & Horaires flexibles

Base Camp Connect • Lévis, Chaudière-Appalaches, CA
Full-time
Une entreprise technologique innovante située à Lévis, Canada, recherche un(e) développeur(euse) DevOps senior.Le candidat travaillera à automatiser le déploiement d'applications, mettra en place d...Show more
Last updated: 14 days ago • Promoted
Spécialiste DevOps CI/CD & Cloud — Télétravail

Spécialiste DevOps CI/CD & Cloud — Télétravail

Tehora • Quebec, Capitale-Nationale, CA
Remote
Full-time
Une firme de technologie multidisciplinaire recherche un(e) spécialiste DevOps pour renforcer son équipe.Le candidat devra avoir dix ans d'expérience, dont cinq en DevOps et contribuer à l'automati...Show more
Last updated: 30+ days ago • Promoted
Spécialiste DevOps

Spécialiste DevOps

Vitr.ai • Quebec, Capitale-Nationale, CA
Full-time
Spécialiste Infrastructure Cloud (DevOps).On aide concrètement le personnel médical à mieux orienter les patients en mettant l’IA que nous bâtissons au service de la décision clinique.On est en ple...Show more
Last updated: 30+ days ago • Promoted
Architecte Cloud & IA DevOps – AWS/GCP

Architecte Cloud & IA DevOps – AWS/GCP

Vitr.ai • Quebec, Capitale-Nationale, CA
Full-time
Une entreprise de technologie au Québec recherche un Spécialiste Infrastructure Cloud (DevOps) pour concevoir et sécuriser l'infrastructure de ses modèles d'Intelligence Artificielle.Les responsabi...Show more
Last updated: 30+ days ago • Promoted