Senior DevSecOps & AI Security Engineer
Toronto, Canada (Onsite)
Contract
F2F Interview
Role Overview
We are looking for an experienced Senior DevSecOps & AI Security Engineer to strengthen enterprise security across applications, cloud-native platforms, DevSecOps pipelines, and AI/LLM-based solutions. The ideal candidate will have deep expertise in application security, offensive security testing, vulnerability management, secure code reviews, cloud security, and emerging AI security practices.
This role will partner with engineering, architecture, product, and leadership teams to embed security throughout the Software Development Lifecycle (SDLC) and MLOps lifecycle while enabling secure innovation.
Primary Skills
Application Security (SAST, DAST, Secure Code Review)
Penetration Testing (Web, API, Mobile)
AI/LLM Security (Prompt Injection, Jailbreak Testing, Model Security)
DevSecOps & CI/CD Security
Vulnerability Management & Remediation
Security Automation using Python
Secondary Skills
Azure Cloud Security
Container & Kubernetes Security
SCA & Open-Source Security
GitHub Security Controls
Threat Modeling & Risk Assessment
Security Governance & Developer Enablement
Key Responsibilities
Security Assessment & Testing
Perform penetration testing across web, API, mobile, cloud-native, and AI-powered applications.
Conduct secure code reviews and identify security weaknesses in enterprise applications.
Validate findings from SAST, DAST, SCA, and container security platforms.
Execute vulnerability analysis, root cause investigation, and remediation validation.
AI Security Engineering
Assess AI and LLM-based applications for security vulnerabilities and misuse scenarios.
Conduct prompt injection, prompt manipulation, and jailbreak testing.
Evaluate AI deployment architectures and recommend security controls.
Support secure AI adoption initiatives across enterprise platforms.
DevSecOps & Security Automation
Integrate security controls into CI/CD pipelines and deployment workflows.
Implement shift-left security practices across engineering teams.
Automate security validation and reporting using Python and modern security tooling.
Optimize vulnerability assessment workflows and remediation tracking.
Enhance security monitoring and policy enforcement across development environments.
Cloud & Container Security
Perform Azure cloud security assessments.
Review Kubernetes and containerized workloads for security risks.
Analyze container images and deployment configurations.
Recommend cloud-native security best practices and remediation actions.
Vulnerability Management & Governance
Review and validate vulnerabilities identified by enterprise security tools.
Prioritize findings based on exploitability, business risk, and operational impact.
Perform root cause analysis and drive remediation efforts with engineering teams.
Track security findings through closure and verify remediation effectiveness.
Support security governance, compliance requirements, and audit activities.
Stakeholder Engagement
Work closely with development, DevOps, architecture, and product teams.
Provide guidance on secure coding, vulnerability remediation, and security best practices.
Mentor engineering teams on security-first development approaches.
Present security findings and recommendations to business and technical stakeholders.
Required Qualifications
Bachelor’s or master’s degree in computer science, Information Security, Cyber Security, or related discipline.
6+ years of experience in Application Security, DevSecOps, Offensive Security, or Security Engineering.
Strong understanding of SDLC, SSDLC, DevSecOps, and MLOps practices.
Hands-on experience with penetration testing, secure code reviews, and vulnerability management.
Experience securing cloud-native and AI-enabled applications.
Strong scripting and automation experience using Python.
Preferred Certifications (Any 2 to 3 Certifications Mandatory)
Certified Information Systems Security Professional (CISSP)
Certified Secure Software Lifecycle Professional (CSSLP)
Microsoft Azure Security Engineer (AZ-500)
Certified DevSecOps Professional
Cloud Security Certifications (Azure/AWS)