Cybersecurity
Senior DevSecOps & AI Security Engineer
Toronto, ONContract · On-site 1 day ago
About the role
Senior DevSecOps & AI Security Engineer
Role Overview
We are seeking an experienced Senior DevSecOps & AI Security Engineer to strengthen security across applications, cloud-native platforms, DevSecOps pipelines, and AI/LLM-based solutions . The role focuses on application security, offensive security testing, vulnerability management, secure code reviews, cloud security, and emerging AI security practices.
Primary Skills
- Application Security - SAST, DAST, Secure Code Review
- Penetration Testing - Web, API, Mobile
- AI/LLM Security - Prompt Injection, Jailbreak & Model Security
- DevSecOps & CI/CD Security
- Vulnerability Management & Remediation
- Security Automation using Python
Secondary Skills
- Azure Cloud Security
- Container & Kubernetes Security
- SCA & Open-Source Security
- GitHub Security Controls
- Threat Modeling & Risk Assessment
- Security Governance & Developer Enablement
Key Responsibilities
Security Assessment & Testing
- Perform penetration testing across web, API, mobile, cloud-native, and AI-powered applications .
- Conduct secure code reviews and identify application security weaknesses.
- Validate findings from SAST, DAST, SCA, and container security tools .
- Perform vulnerability analysis, root-cause investigation, and remediation validation.
AI Security
- Assess AI/LLM applications for security vulnerabilities and misuse scenarios.
- Conduct prompt injection, manipulation, and jailbreak testing.
- Evaluate AI deployment architectures and recommend appropriate security controls.
- Support secure AI adoption across enterprise platforms.
DevSecOps & Automation
- Integrate security controls into CI/CD pipelines and deployment workflows.
- Implement shift-left security practices.
- Automate security validation and reporting using Python .
- Optimize vulnerability assessment and remediation workflows.
- Enhance security monitoring and policy enforcement across development environments.
Cloud & Container Security
- Perform Azure cloud security assessments .
- Review Kubernetes and containerized workloads for security risks.
- Analyze container images and deployment configurations.
- Recommend cloud-native security practices and remediation actions.
Vulnerability Management & Governance
- Review and validate vulnerabilities identified by enterprise security tools.
- Prioritize findings based on exploitability, business risk, and operational impact .
- Drive remediation with engineering teams and verify effectiveness.
- Support security governance, compliance, and audit activities.
Stakeholder Engagement
- Collaborate with development, DevOps, architecture, and product teams .
- Provide guidance on secure coding and vulnerability remediation.
- Mentor engineering teams on security-first development.
- Present security findings and recommendations to technical and business stakeholders.
Required Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or related field .
- 6+ years of experience in Application Security, DevSecOps, Offensive Security, or Security Engineering.
- Strong understanding of SDLC, SSDLC, DevSecOps, and MLOps .
- Hands-on experience with penetration testing, secure code reviews, and vulnerability management.
- Experience securing cloud-native and AI-enabled applications .
- Strong Python scripting and security automation experience.
Certifications
Any 2-3 certifications mandatory:
- CISSP
- CSSLP
- Microsoft Azure Security Engineer ( AZ-500 )
- Certified DevSecOps Professional
- Cloud Security Certifications - Azure/AWS
This engagement is managed end-to-end by Querentia. Our recruiters give you honest feedback at every stage, prepare you for the interview, and support a smooth onboarding once you land the offer.
Skills
SecurityAI / ML
