DevSecOps Engineer

Maxima AI

Toronto

On-site

CAD 110,000 - 150,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Maxima is seeking a DevSecOps/ Security Engineer to implement and manage security across the SDLC, with a strong focus on CI/CD hardening and cloud security in GCP. You will enforce SAST/DAST, secret scanning, and secure deployment practices while aligning with governance standards. Collaboration with engineering and compliance teams is essential.

The role requires 4+ years in DevSecOps, a CS/engineering degree, and excellent communication skills in a fast-growing startup environment.

Qualifications

  • Bachelor's degree in engineering or CS; preferred but not mandatory.
  • 4+ years in DevSecOps, security engineering, or CI/CD security.
  • Experience securing Google Cloud Platform (GCP).
  • Hardening CI/CD systems such as GitHub Actions and related tooling.
  • Security practices for applications (SAST, DAST, secret scanning).
  • Proficient in Golang, Python, or Typescript for automation.
  • Familiar with SOC 2, PCI DSS, ISO 42001 and audit evidence.
  • Thrives in fast-paced startup environments.
  • Strong verbal and written communication skills.

Responsibilities

  • Implement and manage DevSecOps across the SDLC with shift-left security.
  • Hardening CI/CD pipelines (GitHub Actions) and cloud deployments.
  • Enforce security checks, including SAST, DAST, and secret scanning.
  • Secure cloud infrastructure (GCP) with least-privilege IAM and secrets.
  • Manage encryption with Cloud KMS and secret handling best practices.
  • Oversee container and artifact hardening and signing (Cosign).
  • Ensure secure coding practices and input validation; integrate Descope auth.
  • Monitor pipelines and production for security events and audits.

Skills

CI/CD security
GCP security
Kubernetes
GitHub Actions
SAST
DAST
Secret scanning
Cosign
Golang
Python
Typescript

Education

Bachelor’s degree in engineering or CS

Tools

GitHub Actions
Blacksmith
Descope
Trufflehog
GitGuardian
Cosign
Cloud KMS
Secret Manager
Datadog
GCP

Job description

About Us

At Maxima, we're eliminating the pain of enterprise accounting through powerful integrations, intuitive design, and AI-driven automation. By consolidating processes into a single, easy-to-use platform and automating repetitive tasks, we free accounting teams to focus on strategic, high-impact work—achieving more with fewer resources.

Our team is led by top engineers and finance professionals from companies like Robinhood, Bolt, EY, Facebook, Twitter, Netflix, Amazon, Google, Airbnb, Rubrik, and more. Together, we're using our extensive industry experience to transform the way businesses manage their finances.

Maxima is backed by leading Silicon Valley investors. We raised the largest seed round in our category, with support from top-tier VCs such as Kleiner Perkins and Audacious Ventures. This funding has allowed us to launch a fully operational product and onboard several major customers.

Your Role at Maxima
  • Implement and manage DevSecOps practices across the entire Software Development Lifecycle (SDLC), ensuring a "shift-left" approach to security.
  • Comfortable with Kubernetes and other container orchestration platforms
  • Design and harden CI/CD pipelines (e.g., GitHub Actions) by implementing minimal permissions and leveraging OIDC with Workload Identity Federation for cloud deployments.
  • Integrate and enforce security checks, including SAST, dependency scanning, and secret scanning (e.g., using tools like Trufflehog or GitGuardian), to fail builds on high-severity issues.
  • Secure cloud infrastructure (GCP) by implementing the principle of least privilege for IAM, configuring VPC firewalls to restrict traffic, and using Google Secret Manager.
  • Manage encryption and key rotation using Cloud KMS, ensuring all secrets are handled securely and not stored in code or plaintext.
  • Oversee container and artifact hardening, including using multi-stage builds, scanning images for vulnerabilities, and signing artifacts (e.g., Cosign) for supply chain integrity.
  • Ensure application code follows secure coding best practices, including input validation, output encoding to prevent XSS, and secure authentication/session management via Descope integration.
  • Monitor CI/CD pipelines and production environments (using GCP and Datadog) for anomalies, security-relevant events, and audit logs to meet compliance requirements.
  • Maintain documentation and controls necessary to align with compliance frameworks, including SOC 2, SOC 1, and ISO 42001 for AI governance.
  • Assist in developer infrastructure work, including deployment automation and internal tooling, in a full-stack environment.
Your Qualifications
  • 4+ years of experience in DevSecOps, Security Engineering, or a related role focused on CI/CD pipeline security.
  • Bachelor’s degree in any engineering discipline; Computer Science is preferred but not mandatory.
  • Proven experience securing cloud environments, preferably Google Cloud Platform (GCP), with familiarity in IAM, Secret Manager, VPC controls, and Cloud KMS.
  • Strong practical experience with hardening continuous integration/continuous deployment (CI/CD) systems (e.g., GitHub Actions, Blacksmith, or similar).
  • Proficiency in security practices for application development (SAST, DAST, secret scanning) and a deep understanding of common security anti-patterns (e.g., hard-coded secrets, insufficient input validation).
  • Proficient in languages like Golang, Typescripts, Python, or similar programming languages used for automation and development.
  • Familiarity with compliance standards like SOC 2, PCI DSS, or ISO 42001 and experience generating evidence for auditors.
  • Can handle the high intensity and fast pace of a startup environment.
  • Strong verbal and written communication skills.

Maxima is an equal opportunity employer. We do not discriminate based on race, color, ethnicity, ancestry, national origin, religion, sex, gender, gender identity, gender expression, sexual orientation, age, disability, veteran status, genetic information, marital status or any legally protected status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Deployment Engineer - Toronto
Deployment Engineer - Toronto

Urban Ridge Supplies • Toronto

On-site
CAD 90,000 - 120,000
Senior/Staff Software Engineer - Toronto
Senior/Staff Software Engineer - Toronto

Maxima • Toronto

On-site
CAD 120,000 - 180,000
The benefits. Competitive salary, 401k
Unlimited PTO
Lunch in the office
+1
Deployment Engineer
Deployment Engineer

Maxima • Toronto

On-site
CAD 90,000 - 130,000
Competitive salary
401(k) for US employees
Unlimited PTO
+2
Forward Deployment Strategist - Toronto
Forward Deployment Strategist - Toronto

Maxima AI • Toronto

On-site
CAD 120,000 - 180,000
Competitive salary
Equity
Benefits (401k, unlimited PTO)
Forward Deployment Strategist - Toronto
Forward Deployment Strategist - Toronto

Maxima • Toronto

On-site
CAD 95,000 - 140,000
Competitive salary
Equity
401k
+1
Software Engineer - Toronto
Software Engineer - Toronto

Maxima AI • Toronto

On-site
CAD 85,000 - 120,000
401k
Unlimited PTO
Senior DevOps Engineer
Senior DevOps Engineer

DataStealth Inc. • Mississauga

On-site
CAD 90,000 - 130,000
Hybrid work model
Senior Software Engineer (Security)
Senior Software Engineer (Security)

Super • Toronto

On-site
CAD 90,000 - 120,000
Competitive salary
Learning & development allowance
Generous equity options
+2
Senior Software Engineer (DevOps) - BC, Canada Onsite (Vancouver, Canada)
Senior Software Engineer (DevOps) - BC, Canada Onsite (Vancouver, Canada)

S27a • Vancouver

On-site
CAD 110,000 - 125,000
Internet allowance
Laptop
Annual Bonus
+2
DevOps Engineer
DevOps Engineer

LuxeTech Inc. • Canada

On-site
CAD 100,000 - 120,000