Enable job alerts via email!

DevSecOps & Secure-SDLC Engineer

Marsh McLennan

Vancouver

Hybrid

CAD 111,000 - 186,000

Full time

4 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a leading company as a DevSecOps & Secure-SDLC Engineer, where you'll enhance application security and integrate security tools into agile development. This hybrid role requires collaboration in the office and offers professional growth opportunities.

Benefits

health and welfare benefits
tuition assistance
retirement programs
employee assistance programs

Qualifications

  • 5+ years DevSecOps and Secure-SDLC experience.
  • CISSP, CSSLP, or similar certification required.

Responsibilities

  • Lead initiatives to enhance Secure-SDLC.
  • Integrate security tools into DevSecOps processes.

Skills

DevSecOps
Secure-SDLC
cloud security
automation
programming languages

Education

Post-secondary education

Tools

SAST
DAST
SCA

Job description

Join to apply for the DevSecOps & Secure-SDLC Engineer role at Marsh McLennan

3 weeks ago Be among the first 25 applicants

Join to apply for the DevSecOps & Secure-SDLC Engineer role at Marsh McLennan

Marsh McLennan is seeking candidates for the following position. This role will be based in Canada. This is a hybrid role that has a requirement of working at least three days a week in the office.

Join our dynamic team as a DevSecOps & Secure-SDLC Engineer, where you will play a pivotal role in leading initiatives that enhance our Secure Software Development Lifecycle (Secure-SDLC) in alignment with our Application Development Security Policy. In this position, you will be responsible for selecting and standardizing application security tools through comprehensive vendor assessments and proof of concepts. You will integrate Secure-SDLC requirements into our DevSecOps processes, ensuring that our application security standards are robust and tailored for agile development methods across both traditional and cloud architectures, including container workloads.

We will count on you to :

  • Advise the application security leadership on best practices and standards around application security tools with main focus on shift-left, create predictable CI / CD pipeline processes, and enable application teams to develop new capabilities securely, and free from security defects, by design
  • Assess security tools and related processes currently used within the various Software Development Life Cycle processes to identify improvements opportunities, and rationalize the tools set
  • Select new application security tools including vendor / tool assessments and conduct full POC to prove that the security solutions / products are fit-for-purpose and fit-for-use
  • Draft documentations for the Secure-SDLC and DevSecOps to illustrate the frameworks and its process guidelines to internal customers ensuring the style is palatable and easy to navigate
  • Assess impact of new publications from the security industry (e.g. NIST 800-XXX, ISO 2700X : 2022, etc) on the company’s AppSec programs
  • Research new trends and advise the application security leaderships on impact of the new trends as they relate to currently used tools, tool chain roadmap, efficiency and effectiveness of current processes, etc.
  • Promote secure coding standard and all related processes
  • Promote the priorities set forth by Global Information Security function, and the roadmap set forth by the Global Application Security
  • Automate and integrate security scan and analysis tools into the DevSecOps pipeline

What you need to have :

  • 5 years+ DevSecOps and Secure-SDLC work experience
  • CISSP, CSSLP, cloud security, DevSecOps automation, or similar is required
  • Post-secondary education or equivalent experience as a DevSecOps Engineer
  • Develop / enhance and implement the Secure-SDLC framework
  • Design, implement, and rollout DevSecOps automations and tool chain
  • Implement sensors to collect data on key metrics for statistics and reporting
  • Serve as the subject matter expert in Secure-SDLC and DevSecOps
  • Advise on the processes and standards that are designed to implement a company’s Application Development Security Policy
  • Experience in designing Secure-SDLC processes and relevant tooling to support the processes
  • Experience in software / application analysis tools like SAST, DAST, SCA, threat modeling, supply-chain etc.
  • Technical hands-on experience in automating and integrating security scan and analysis tools into the DevSecOps pipeline.
  • Experience in one or more programming languages
  • Familiarity with security frameworks (OWASP Top 10, SANS Top 25, CWE)

What makes you stand out :

  • Identify application security requirements and brainstorm solutions factoring in industry best practices
  • Assess the tooling and remediation of threats and vulnerabilities within our software / applications, and the hosting environment

Why join our team :

  • We help you be your best through professional development opportunities, interesting work, and supportive leaders.
  • We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients, and communities.
  • Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.

Marsh McLennan (NYSE : MMC) is a global leader in risk, strategy and people, advising clients in 130 countries across four businesses : Marsh, Guy Carpenter, Mercer and Oliver Wyman. With annual revenue of $24 billion and more than 90,000 colleagues, Marsh McLennan helps build the confidence to thrive through the power of perspective. For more information, visit marshmclennan.com, or follow on LinkedIn and X.

Marsh McLennan is committed to embracing a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age background, disability, ethnic origin, family duties, gender orientation or expression, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex / gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law. In accordance with the Accessibility for Ontarians with Disabilities Act, 2005, Marsh McLennan will provide a reasonable accommodation to employees and prospective employees to the point of undue hardship upon request and as required in respect of the individual’s particular restrictions and limitations. If you require a specific accommodation because of a disability or medical need, please contact reasonableaccommodations@mmc.com.

Marsh McLennan is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh McLennan colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person.

The applicable base salary range for this role is $111,700 to $185,200.

The base pay offered will be determined on factors such as experience, skills, training, location, certifications, education, and any applicable minimum wage requirements. Decisions will be determined on a case-by-case basis. In addition to the base salary, this position may be eligible for performance-based incentives.

We are excited to offer a competitive total rewards package which includes health and welfare benefits, tuition assistance, retirement programs as well as employee assistance programs.

R_300178

Seniority level

Seniority level

Not Applicable

Employment type

Employment type

Full-time

Job function

Job function

Engineering and Information Technology

Insurance and Business Consulting and Services

Referrals increase your chances of interviewing at Marsh McLennan by 2x

Get notified about new Civil Engineer jobs in Vancouver, British Columbia, Canada .

Software Development Engineer - 2025 (Canada)

Full Stack Developer (Future Opportunity)

Burnaby, British Columbia, Canada 1 month ago

Fullstack Front-End Engineer, AI at OpusClip

Burnaby, British Columbia, Canada $160,000.00-$200,000.00 1 month ago

Burnaby, British Columbia, Canada 15 hours ago

Intermediate Full Stack Software Developer

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

J-18808-Ljbffr

Create a job alert for this search
We Care About Your Privacy

We and our 1 partners store and access personal data, like browsing data or unique identifiers, on your device. Selecting I Accept enables tracking technologies to support the purposes shown under we and our partners process data to provide. Selecting Reject All or withdrawing your consent will disable them. If trackers are disabled, some content and ads you see may not be as relevant to you. You can resurface this menu to change your choices or withdraw consent at any time by clicking the Show Purposes link on the bottom of the webpage [or the floating icon on the bottom-left of the webpage, if applicable]. Your choices will have effect within our Website. For more details, refer to our Privacy Policy.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.