- Company Name
- Air Canada
- Job Title
- Specialist, DevOps
- Job Description
-
**Job title**
Specialist, DevOps
**Role Summary**
Lead the design, implementation, and maintenance of secure DevSecOps practices across cloud environments. Drive automation of security controls, CI/CD pipelines, and infrastructure-as-code while ensuring compliance with industry standards and internal security policies. Mentor teammates and collaborate with cross‑functional stakeholders to embed security into every phase of the software lifecycle.
**Expectations**
- 5+ years of IT experience, with deep expertise in cloud security and DevSecOps.
- Proven track record of building secure, automated pipelines and hardened container images.
- Strong analytical, strategic thinking, and communication skills to influence and guide teams.
- Ability to operate in a fast‑paced, collaborative environment and mentor junior engineers.
**Key Responsibilities**
- Champion the DevSecOps vision, integrating security into CI/CD and cloud infrastructure.
- Architect, deploy, and manage secure AWS environments, applying governance services (CloudTrail, Config, IAM).
- Automate security controls: IAM policies, encryption, secrets rotation, and vulnerability patching.
- Conduct risk assessments, security reviews, and incident response, leading root‑cause analysis.
- Build and maintain hardened base images (Docker, AMI) following CIS, NIST, and company benchmarks.
- Implement automated scanning, SBOM management, and secure deployment gates across pipelines.
- Integrate SAST, DAST, SCA, and container scanners into build processes; monitor and remediate findings.
- Support threat modeling, compliance automation, and continuous improvement of security metrics.
- Educate developers and engineering teams on secure practices and promote a security‑first culture.
**Required Skills**
- Cloud platforms: AWS, Azure, or Google Cloud (core services, networking, governance).
- Security frameworks: HIPAA, PCI DSS, GDPR, PIPEDA, SOC 2.
- DevSecOps expertise: CI/CD (GitHub Actions, Bitbucket Pipelines, etc.), IaC (Terraform, Ansible).
- Containerization: Docker, Podman, image scanning, SBOM, SLSA.
- Scripting/automation: Bash, Python, Go.
- Secure SDLC knowledge and experience with OWASP ZAP, Snyk, SonarQube, Checkmarx, Fortify.
- Package management: pip, npm, apt, yum with secure dependency handling.
- Strong communication, influence, and mentorship capabilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, or equivalent technical experience.
- Relevant certifications preferred: AWS Certified Security – Specialty, Certified DevSecOps Professional, or equivalent.