DevSecOps Developer
TechnologieDescription
English version follows
DevSecOps Developer
About Us
Toboggan Labs is a boutique consultancy building at the intersection of AI and healthcare. We solve challenging human problems by applying cutting-edge technology and domain understanding.
About the role
We're seeking a DevSecOps Developer to join our team and integrate security into development pipelines, cloud infrastructure, and engineering practices across client environments.
In this role, you will design and implement security controls directly into CI/CD pipelines, automate vulnerability scanning, harden cloud infrastructure, and collaborate with development and operations teams to embed security early in the development lifecycle. You will work alongside senior security practitioners and client teams to build environments that are secure, reliable, and compliant.
Note that while we specialize in healthcare and regulated industries, not all our projects are in these fields, so you may work across different domains from time to time.
Your daily responsibilities
- CI/CD pipeline security — Integrate static analysis (SAST), software composition analysis (SCA), and container image scanning tools into deployment pipelines; automate security checks in GitHub Actions, ArgoCD, or equivalents.
- Cloud infrastructure security — Implement and maintain security controls across AWS or Azure environments using infrastructure-as-code tools (Terraform, CloudFormation, or equivalents), including IAM policy management, network hardening, and vulnerability management.
- Identity and access management — Design and administer secure IAM architectures, including SSO, MFA, SCIM provisioning, and access governance, working with identity providers such as Okta and Azure AD.
- Security automation and compliance — Develop automations for configuration drift detection, remediation, and compliance monitoring; contribute to SOC 2, HIPAA, and ISO 27001 programs.
- On certain engagements, technical leadership — Lead specific security aspects or take ownership of client deliverables with increasing autonomy.
- Team support — Document security architectures and procedures, contribute to internal tools and standards, participate in knowledge-sharing activities, and interviews.
About you
We are looking for individuals with strong software development and security backgrounds, eager to develop their skills in a consultative context covering cloud security, DevSecOps integration, and compliance. Most of our clients use AWS, modern CI/CD tools, and common identity providers. You should be comfortable working at the intersection of development, operations, and security.
When we talk about DevSecOps, we're looking for someone who can read a CI/CD pipeline and spot a security flaw, write the automation to fix it, and clearly explain the risk to a development team — someone who understands both code and infrastructure, and considers security a shared responsibility.
We encourage you to apply if you
- Have 5+ years of experience in software development, DevOps, or application security;
- Have hands-on experience with AWS or Azure infrastructures and infrastructure-as-code tools (Terraform, CloudFormation, or equivalents);
- Have solid experience with CI/CD pipelines (GitHub Actions, ArgoCD, Jenkins, or equivalents) and integrating security tools into deployment processes;
- Have deployed and administered Okta or similar identity providers (Azure AD, Google Workspace), including SSO, MFA, SCIM provisioning, and access governance;
- Are familiar with cloud infrastructure security best practices, including network security, IAM, encryption, and vulnerability management;
- Are familiar with compliance frameworks such as SOC 2, HIPAA, ISO 27001, or equivalents;
- Have excellent communication skills and can explain security and infrastructure concepts to diverse audiences;
- Are adaptable, self-motivated, and comfortable in dynamic client environments.
Bonus qualifications
- Experience in client-facing roles (consulting, implementation engineering, advisory services);
- Experience in healthcare or other highly regulated industries;
- Experience with container security, Kubernetes, or cloud-native security tools (Falco, OPA, Trivy, or equivalents);
- Experience in security automation using scripts (Python, Bash) or workflow tools (Okta Workflows, Tray.io, Workato);
- Experience with MDM/workstation management and device security policies;
- Relevant certifications (AWS Security Specialty, CKS, CISSP, or equivalents).
All our job postings describe a bit of a unicorn. If you're more of a "narwhal," apply anyway! It's not necessary to meet all the requirements or bonus criteria. Experience and skills are important, but growth potential and attitude are just as important. We're generally flexible about where you can level up to a more appropriate offer when it's opened.
What we offer
We are a remote-first company with an office in Montreal. We prioritize hiring in Quebec but are open to applications across Canada within EST ±2 time zones.
Toboggan Labs values the diversity of the people we hire and serve. For us, diversity means creating a workplace where each person's differences are recognized, appreciated, respected, and taken into account to develop and leverage each person's talents and strengths.
In addition:
- Home office and technology budget;
- Annual professional development budget;
- REER with employer contribution after 1 year;
- Starting on day one:
- + 100% employer-paid health and dental insurance, including an annual amount for complementary care (acupuncture, osteopathy, massage therapy, naturopathy, psychology, etc.);
- + Life and short- and long-term disability insurance;
- + Parental leave supplement (8 weeks), available to employees with more than one year of tenure, regardless of the path to parenthood.
- DevSecOps Developer
About Us
Toboggan Labs is a boutique consultancy building at the intersection of AI and healthcare. We solve challenging human problems by applying cutting-edge technology and domain understanding.
About the role
We're seeking a DevSecOps Developer to join our team and integrate security into development pipelines, cloud infrastructure, and engineering practices across client environments.
In this role, you will design and implement security controls directly into CI/CD pipelines, automate vulnerability scanning, harden cloud infrastructure, and collaborate with development and operations teams to embed security early in the development lifecycle. You will work alongside senior security practitioners and client teams to build environments that are secure, reliable, and compliant.
Note that while we specialize in healthcare and regulated industries, not all our projects are in these fields, so you may work across different domains from time to time.
Cette offre a été agrégée depuis indeed. Groupe Sentinella n'est pas l'employeur; postuler vous redirige vers le site original. Le texte intégral appartient à l'auteur de l'offre.
Envie qu'on travaille pour vous ?
Inscrivez-vous au banc de talents Sentinella. On vous contacte dès qu'un mandat correspond à votre profil — y compris des postes comme celui-ci.
Rejoindre le banc de talents