More jobs:
Senior Specialist - IT Security (Dev Sec Ops
Job in
Vancouver, BC, Canada
Listed on 2026-08-11
Listing for:
Marsh
Full Time
position Listed on 2026-08-11
Job specializations:
-
IT/Tech
Cybersecurity, IT Consultant, Cloud Computing: Infrastructure & Operations, Systems Engineer
Job Description & How to Apply Below
Dev Sec Ops & Secure-SDLC Engineer
Lead initiatives related to Dev Sec Ops and Secure-SDLC.
Enhance the company’s Secure Software development Liability (Secure-Business) (Secure-Business) which in turn will reflect the company’s Application Development Security Policy,
Select and standardize application security tools. This includes vendor/tool assessments and full POC,
Integrate Secure-SDLC requirements and other security policy/requirements into the Dev Sec Ops processes,
Define and enhance application security requirements and standards which must be designed for agile development methods leveraging traditional application architectures as well as cloud architectures and container workloads.
What can you expect?- Lead initiatives related to Dev Sec Ops and Secure-SDLC.
- Enhance the company’s Secure Software development Lifecycle (Secure-SDLC) which in turn will reflect the company’s Application Development Security Policy,
- Select and standardize application security tools. This includes vendor/tool assessments and full POC,
- Integrate Secure-SDLC requirements and other security policy/requirements into the Dev Sec Ops processes,
- Define and enhance application security requirements and standards which must be designed for agile development methods leveraging traditional application architectures as well as cloud architectures and container workloads.
- Advise the application security leadership on best practices and standards around application security tools with main focus on shift-left, create predictable CI/CD pipeline processes, and enable application teams to develop new capabilities securely, and free from security defects, by design
- Assess security tools and related processes currently used within the various Software Development Life Cycle processes to identify improvements opportunities, and rationalize the tools set
- Select new application security tools including vendor/tool assessments and conduct full POC to prove that the security solutions/products are fit-for-purpose and fit-for-use
- Draft documentations for the Secure-SDLC and Dev Sec Ops to illustrate the frameworks and its process guidelines to internal customers ensuring the style is palatable and easy to navigate
- Assess impact of new publications from the security industry (e.g. NIST 800-XXX, ISO 2700X:2022, etc) on the company’s App Sec programs
- Research new trends and advise the application security leaderships on impact of the new trends as they relate to currently used tools, tool chain roadmap, efficiency and effectiveness of current processes, etc.
- Promote secure coding standard and all related processes
- Promote the priorities set forth by Global Information Security function, and the roadmap set forth by the Global Application Security
- Automate and integrate security scan and analysis tools into the Dev Sec Ops pipeline
- 5 years+ Dev Sec Ops and Secure-SDLC work experience
- CISSP, CSSLP, cloud security, Dev Sec Ops automation, or similar is required
- Post‑secondary education or equivalent experience as a Dev Sec Ops Engineer
- Develop/enhance and implement the Secure‑SDLC framework
- Design, implement, and rollout Dev Sec Ops automations and tool chain
- Implement sensors to collect data on key metrics for statistics and reporting
- Serve as the subject matter expert in Secure‑SDLC and Dev Sec Ops
- Advise on the processes and standards that are designed to implement a company’s Application Development Security Policy
- Experience in designing Secure‑SDLC processes and relevant tooling to support the processes
- Experience in software/application analysis tools like SAST, DAST, SCA, threat modeling, supply‑chain etc.
- Technical hands‑on experience in automating and integrating security scan and analysis tools into the Dev Sec Ops pipeline.
- Experience in one or more programming languages
- Familiarity with security frameworks (OWASP Top 10, SANS Top 25, CWE)
- Identify application security requirements and brainstorm solutions factoring in industry best practices
- Assess the tooling and remediation of threats and vulnerabilities within our software/applications, and the hosting environment
Ma…
Position Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×