Talent.com
DevSecOps Specialist
DevSecOps SpecialistConstruction Virtuelle et Technologie BI • Québec, QC, Canada
No longer accepting applications
DevSecOps Specialist

DevSecOps Specialist

Construction Virtuelle et Technologie BI • Québec, QC, Canada
30+ days ago
Job type
  • Full-time
Job description

Job Description

Job Description

At Newforma, you’ll help shape the future of project information management for architects, engineers, and contractors worldwide. Join a team that’s trusted by over 1,500 firms to simplify how they work. Together, we’re creating tools that connect people to the information they need, faster and smarter. Let’s build something great.

We're seeking a DevSecOps Specialist to join our Platform Engineering team and play a pivotal role in establishing and evolving our security-first culture. As Newforma undergoes a strategic migration from Azure to AWS, you'll be instrumental in building secure, automated infrastructure and embedding security practices throughout our software development lifecycle. This is an opportunity to shape the DevSecOps foundation for a platform trusted by hundreds of thousands of users managing sensitive project data across the construction industry.

In this role, your responsibilities will include:

Security Leadership & Culture

  • Champion DevSecOps principles across engineering teams, fostering a culture where security is everyone's responsibility.
  • Establish and evangelize security best practices, secure coding standards, and threat modeling approaches.
  • Mentor and guide development teams on security automation, vulnerability management, and secure architecture patterns.
  • Lead by example, demonstrating how to balance security requirements with development velocity and business needs.
  • Conduct security training sessions and create documentation to elevate the organization's security awareness.
  • Partner with engineering leadership to define and track security metrics and KPIs.

AWS Security & Infrastructure

  • Support team to design and implement secure cloud infrastructure on AWS, following the AWS Well-Architected Framework security pillar.
  • Architect and maintain Identity and Access Management (IAM) policies, roles, and service control policies across AWS accounts.
  • Support team to implement security controls using AWS services including GuardDuty, Security Hub, Config, CloudTrail, and WAF.
  • Design and enforce network security using VPCs, security groups, NACLs, and AWS PrivateLink.
  • Establish secrets management strategies using AWS Secrets Manager and Parameter Store.
  • Lead the security aspects of the Azure-to-AWS migration, ensuring secure architecture patterns and data protection.
  • Implement infrastructure-as-code security scanning and policy enforcement using tools like Checkov, tfsec, or AWS CDK.

CI/CD Security & Automation

  • Build and maintain secure CI/CD pipelines integrating security scanning at every stage of the development lifecycle.
  • Implement automated security testing including SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), and SCA (Software Composition Analysis).
  • Integrate container security scanning and image vulnerability assessment into build pipelines.
  • Automate compliance checks and security policy enforcement in deployment workflows.
  • Design and implement automated remediation workflows for common security findings.
  • Establish secure artifact management and software supply chain security practices.

Vulnerability & Compliance Management

  • Implement and maintain vulnerability scanning and management programs for applications, containers, and infrastructure.
  • Establish processes for triaging, tracking, and remediating security vulnerabilities.
  • Ensure compliance with industry standards and regulations relevant to the AECO industry.
  • Conduct regular security assessments, penetration testing coordination, and security audits.
  • Develop and maintain incident response playbooks and participate in security incident response.
  • Create and maintain security baselines and hardening standards for systems and applications.

Monitoring & Incident Response

  • Design and implement security monitoring, logging, and alerting solutions using CloudWatch, CloudTrail, and SIEM tools.
  • Establish threat detection and response capabilities for cloud infrastructure and applications.
  • Build automated alerting and response mechanisms for security events.
  • Conduct security investigations and root cause analysis for security incidents.
  • Implement and maintain disaster recovery and business continuity plans from a security perspective.

Collaboration & Integration

  • Work on security initiatives in collaboration with other members of the platform engineering team.
  • Work closely with development teams to integrate security into all aspects of the SDLC.
  • Collaborate with the Lead Software Architect to ensure security considerations in architectural decisions.
  • Partner with compliance and legal teams on security requirements and audit preparation.
  • Engage with third-party security vendors and manage security tooling evaluation and implementation.
  • Participate in agile ceremonies including daily stand-ups, sprint planning, and retrospectives.

Requirements for the position include:

  • 7+ years of experience in DevOps, Security Engineering, or related roles with at least 3 years focused on DevSecOps practices.
  • Strong hands-on experience with AWS security services and best practices, including IAM, Security Hub, GuardDuty, Config, KMS, and CloudTrail.
  • Proven track record of implementing security automation and integrating security into CI/CD pipelines.
  • Deep understanding of infrastructure-as-code security (Pulumi, Terraform, AWS CDK, CloudFormation).
  • Experience with container security, including Docker, Kubernetes/EKS security, and container image scanning.
  • Proficiency with security scanning tools such as SonarQube, Snyk, Aqua Security, Prisma Cloud, or similar.
  • Strong knowledge of application security principles, OWASP Top 10, and secure coding practices.
  • Experience with scripting and automation using Python, Bash, or PowerShell.
  • Understanding of network security, encryption, certificate management, and secrets management.
  • Familiarity with compliance frameworks (SOC 2, ISO 27001, GDPR) and security audit processes.
  • Excellent communication skills with ability to explain complex security concepts to diverse audiences.
  • Experience mentoring and influencing engineering teams on security best practices.
  • Bachelor's degree in Computer Science, Information Security, or related field.

Nice to have qualifications for this position include:

  • AWS Security certifications (AWS Certified Security - Specialty, AWS Solutions Architect, or similar).
  • Additional security certifications such as CISSP, CEH, GIAC, or OSCP.
  • Experience migrating security controls and practices from Azure to AWS.
  • Hands-on experience with Azure security services (Azure Security Center, Defender, Sentinel).
  • Knowledge of .NET/C# application security and secure development practices.
  • Experience with React or frontend security considerations.
  • Familiarity with Kubernetes security tools and practices (admission controllers, policy engines, runtime security).
  • Experience with DevSecOps in SaaS/multi-tenant environments.
  • Knowledge of security considerations for document management and file storage systems.
  • Experience with API security, OAuth 2.0, SAML, and identity federation.
  • Familiarity with supply chain security and SBOM (Software Bill of Materials) practices.
  • Experience with security aspects of AI/ML systems and data protection
  • Bilingual in French and English.

Why Work at Newforma?

  • Purpose-driven work: Help professionals in the AECO industry solve real-world challenges.
  • Global impact: Our tools are used on over 16 million projects worldwide.
  • Collaborative culture: Work alongside talented teammates who value your input.
  • Room to grow: We support your career development through learning opportunities and mentorship.
  • Innovation at its core: Be part of a company that’s always evolving to meet industry needs.

Create a job alert for this search

DevSecOps Specialist • Québec, QC, Canada

Similar jobs
Spécialiste DevOps - Développeur applicatif / DevOps Specialist - Application Developer

Spécialiste DevOps - Développeur applicatif / DevOps Specialist - Application Developer

PayFacto • Quebec
Full-time
Employer Industry: Cloud Services and Application Development.Why consider this job opportunity.Medical and dental coverage starting from Day 1.RRSP matching contributions from the employer.Vacatio...Show more
Last updated: 25 days ago • Promoted
Dev/Devops C – Orchestrade

Dev/Devops C – Orchestrade

360.Agency Inc. • Lévis, Canada
Full-time
Overview of the Role:- This role consists of a combination of Support and DevOps for a range of applications that sit within the firm’s Plant Management (PLM) Department – which is part of the Reli...Show more
Last updated: 3 days ago • Promoted
Systems Monitoring & Infrastructure Specialist - lévis

Systems Monitoring & Infrastructure Specialist - lévis

Dexcent • lévis, qc, ca
Full-time
Systems Monitoring & Infrastructure Specialist.Operational Technology (OT) environment.This is a contract opportunity and the individual can be fully remote.Dexcent) is an engineering consulting fi...Show more
Last updated: 17 days ago • Promoted
DevOps

DevOps

Kickflip • Quebec
Full-time
Rejoins notre équipe en pleine croissance, où ton implication aura un grand impact.Kickflip permet aux commerces en ligne d'offrir des expériences de personnalisation de produits grâce à une platef...Show more
Last updated: 30+ days ago • Promoted
Information Technology Private Tutoring Jobs Beauport

Information Technology Private Tutoring Jobs Beauport

Superprof • Beauport, Canada
Full-time +1
Superprof is Canada's #1 tutoring platform, and we're actively recruiting passionate tutors! Whether you're a student, a professional, or simply someone who loves teaching, join the largest communi...Show more
Last updated: 30+ days ago • Promoted
Dev/DevOps C# – Orchestrade

Dev/DevOps C# – Orchestrade

Evolvic Inc. • Quebec
Full-time
This position is part of a strategic initiative to strengthen and optimize the Orchestrade Core environment — a key platform supporting multiple financial business lines including Front Office, Mid...Show more
Last updated: 30+ days ago • Promoted
Devsecops Specialist

Devsecops Specialist

Newforma • L'Ancienne-Lorette, Canada
Full-time
At Newforma, you’ll help shape the future of project information management for architects, engineers, and contractors worldwide.Join a team that’s trusted by over 1,500 firms to simplify how they ...Show more
Last updated: 5 days ago • Promoted
Dev/Devops C – Orchestrade

Dev/Devops C – Orchestrade

Evolvic Inc. • Québec, Canada
Full-time
This position is part of a strategic initiative to strengthen and optimize the Orchestrade Core environment — a key platform supporting multiple financial business lines including Front Office, Mid...Show more
Last updated: 30+ days ago • Promoted
Information Technology Private Tutoring Jobs Charlesbourg

Information Technology Private Tutoring Jobs Charlesbourg

Superprof • Charlesbourg, Canada
Full-time +1
Superprof is Canada's #1 tutoring platform, and we're actively recruiting passionate tutors! Whether you're a student, a professional, or simply someone who loves teaching, join the largest communi...Show more
Last updated: 30+ days ago • Promoted
DevSecOps Specialist

DevSecOps Specialist

Newforma • Quebec
Full-time
At Newforma, you’ll help shape the future of project information management for architects, engineers, and contractors worldwide.Join a team that’s trusted by over 1,500 firms to simplify how they ...Show more
Last updated: 12 days ago • Promoted
Senior/Lead DevOps Engineer

Senior/Lead DevOps Engineer

PhenoTips • lévis, QC, ca
Full-time +1
At PhenoTips, we are transforming genetic medicine by helping healthcare providers seamlessly integrate genomic insights into patient care.Backed by top Canadian investors and leading healthcare sy...Show more
Last updated: 12 hours ago • Promoted • New!
Dev Ops Senior

Dev Ops Senior

Bearsight Inc • saint-augustin-de-desmaures, qc, ca
Full-time
Remote (Open to candidates across Canada).Competitive – Based on experience.We are seeking a highly experienced.AI & Software Engineering team.This role is ideal for a cloud-native infrastructure e...Show more
Last updated: 23 hours ago • Promoted
Senior DevOps Specialist

Senior DevOps Specialist

360.Agency Inc. • Quebec
Full-time
Ready to make a lasting impact with a dynamic and innovative company? Join the.We’re experts in creating web and marketing solutions tailored for the automotive sector.Yo u will support our organiz...Show more
Last updated: 6 days ago • Promoted
DevOps Engineer

DevOps Engineer

Promote Project • Quebec
Full-time
Company Description At Higher Logic, engagement happens here.As the industry-leading, human-focused engagement platform we deliver powerful online communities and communication tools to organizatio...Show more
Last updated: 30+ days ago • Promoted
Central Support Specialist - Scanning & Reality Capture

Central Support Specialist - Scanning & Reality Capture

Leica Geosystems part of Hexagon • saint-augustin-de-desmaures, QC, ca
Full-time
Central Customer Support Specialist - Reality CaptureRemote, CanadaWhen an entire city needs to be rendered into a 3D model in-flight, utilities buried deep under soil need to be uncovered, highly ...Show more
Last updated: 6 days ago • Promoted
Genesys Cloud WFM Implementation Consultant

Genesys Cloud WFM Implementation Consultant

Full Potential Solutions • saint-augustin-de-desmaures, QC, ca
Full-time
We are currently looking to identify a qualified resource for a Genesys Cloud WFM Implementation Consultant role and would appreciate your assistance in sourcing candidates who meet the attached re...Show more
Last updated: 16 hours ago • Promoted • New!
Azure DevOps Engineer

Azure DevOps Engineer

LTIMindtree • lévis, QC, ca
Full-time
LTIMindtree is an equal opportunity employer that is committed to diversity in the workplace.Our employment decisions are made without regard to race, color, creed, religion, sex (including pregnan...Show more
Last updated: 30+ days ago • Promoted
Développeur DevSecOps

Développeur DevSecOps

CGI • Québec, Qc
Full-time
CGI est à la recherche d'un Développeur DevSecOps afin de soutenir un client majeur dans la conception, le déploiement et la sécurisation d'applications cloud‑ candidat idéal possède une expérience...Show more
Last updated: 12 hours ago • Promoted • New!