← Back to jobs

Devops engineer

Venuiti
Waterloo , ON · Canada
Posted 19 hours ago Full time $ 100,000 to $ 125,000 YEAR annually

Job description

*Cybersecurity Engineer* *Canadian Citizenship is required for security clearance* *Permanent, Full-time* *100% in-person in Waterloo, ON* We are seeking a pragmatic Software Security Engineer to join our team. In this role, you will be responsible for securing our software products from the inside out - ensuring that the applications, architectures, and automated pipelines powering our business are resilient against modern, complex cyber threats. We view software security as a core business enabler, not a compliance exercise or a "gatekeeping" function. You will not simply run automated scanners and assign tickets. Instead, you will work side-by-side with our software engineering teams to analyze attack paths, perform threat modeling early in design phases, prioritize real business risk over raw scanner severity ratings, and build practical security into our modern CI/CD pipelines. *Key Responsibilities* * Architectural Threat Modeling & Design: Partner with software engineers to perform threat modeling on new features, services, and cloud architectures before code is written. * Contextual Risk Management & Prioritization: Evaluate vulnerability findings across code, containers, cloud infrastructure, and APIs, cutting through scanner severity and noise to determine real exploitability, reachability, and business impact. * Engineering Collaboration & Influence: Serve as a trusted security advisor to engineers: understand the design, demonstrate impact, and work through practical alternatives, compensating controls, or documented risk acceptance with an accountable owner. * Pragmatic DevSecOps & Pipeline Integration: Design, deploy, and maintain security guardrails (SAST, SCA, Secrets Detection, IaC scanning) within modern CI/CD pipelines. * Attack Surface Analysis: Determine our actual attack surface across cloud and on-prem environments, from both an external/unauthenticated and an internal/identity-based perspective, including assets we don?t know we own. * Incident Response: Support investigation and containment of compromised systems and credentials, including secrets exposure, and help drive decisions on scope, blast radius, and remediation. *Qualifications* * 5+ Years in Product Security / Application Security (AppSec): Proven hands-on experience securing modern web applications, microservices, and APIs in production software environments. * Offensive Mindset & Exploitability Analysis: Deep understanding of how adversaries exploit software features. * Software Engineering & Cloud Literacy: Ability to read code, review pull requests, understand modern application architectures (React, Java/Python/Go, microservices), and navigate multi-cloud (AWS and others) and on-prem environments. * Identity & Network Architectural Knowledge: Deep understanding of identity protocols (OIDC, OAuth, SAML, MFA), network boundaries, API gateways, load balancers, and Zero Trust concepts. * Hands-on DevSecOps Experience: Experience integrating automated security tools into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins) with a focus on developer experience. * Strong Business Acumen & Communication: Ability to articulate technical risk in clear business terms to engineering leads, product managers, and executive leadership. * Knowledge of Container & Kubernetes Security. * Incident Response Experience: Hands-on experience investigating and containing security incidents, including compromised credentials and secrets exposure, beyond following a written IR procedure. *Nice-to-Have Qualifications* * Experience with External Attack Surface Management (EASM) and asset discovery tools. * Active experience in Red Teaming or Ethical Hacking. * Industry certifications such as GWAPT, OSCP, CISSP, or CCSP (practical experience is valued above certifications). *Why Join Us?* Venuiti believes in universal acceptance for everyone everywhere. We promote diversity of thought, culture, and background, which connects the entire Venuiti fa