Security Engineer
About the role
Job Title: Security Engineer (DevSecOps / Cloud)
Location: Remote
Duration: 6-Month Contract (Full-Time – 37.5 hours/week, Exclusive)
Clearance: Secret or Top-Secret (Mandatory)
Role Overview
We are seeking a skilled Security Engineer to support a Government of Canada (GOC) client in delivering secure cloud-based applications. This role focuses on embedding security into the software development lifecycle, with a strong emphasis on CI/CD security, automated controls, and compliance with federal security standards.
The ideal candidate will have hands-on experience with Security Assessment & Authorization (SA&A) processes within the GOC environment and a strong background in DevSecOps practices.
Key Responsibilities
- Design and implement secure CI/CD pipelines with integrated security controls
- Deploy and manage automated security scanning tools (SAST, DAST, SCA, container security, etc.)
- Lead and support Security Assessment & Authorization (SA&A) activities for cloud-based applications
- Ensure compliance with Government of Canada security frameworks, policies, and standards
- Identify, assess, and remediate application and infrastructure vulnerabilities
- Apply modern security engineering practices across the SDLC
- Collaborate with development and DevOps teams to embed DevSecOps best practices
- Support threat modeling, risk assessments, and security reviews for new and existing systems
Mandatory Requirements
- Bachelor ’ s degree or College Diploma in a relevant discipline
- Minimum 5+ years of experience in a software development / engineering environment
- Strong hands-on experience with CI/CD pipelines and DevSecOps practices
- Proven experience completing Security Assessment & Authorization (SA&A) for at least two (2) cloud-based applications within the last 5 years ( GOC experience required )
- Minimum 2+ years of recent experience implementing automated security scanning and controls within CI/CD pipelines
- Experience applying modern application security principles to applications released within the past 3 years
- Active Secret or Top-Secret Clearance (Mandatory)
Additional Requirements
- Prior experience working within Government of Canada (GOC) environments
- Strong knowledge of cloud security, risk management, and compliance frameworks
- Ability to commit to a full-time (37.5 hours/week), exclusive contract
- Strong communication and stakeholder collaboration skills
Nice to Have
- Certifications such as CISSP, CISM, CEH, AWS/Azure Security
- Experience with Infrastructure as Code (IaC) and secure configuration management
- Familiarity with containerization and Kubernetes security
- Experience with security tools like SonarQube, Snyk, Checkmarx, Prisma Cloud , etc.
This engagement is managed end-to-end by Querentia. Our recruiters give you honest feedback at every stage, prepare you for the interview, and support a smooth onboarding once you land the offer.
