02 Aug
|
Pengcorp
|
Calgary
Role: Development Security Specialist (DevSecOps) -Industrial Oil & Gas Applications
Reports To: Manager, Application & Software Development
Department: Digitization
Position Type: Full Term
Location: Calgary, Alberta (Hybrid)
About the Company
Pengcorp is a consortium of highly dedicated and talented engineers providing specialized services to industrial enterprises throughout North and South America. Our expertise has been embedded in mid- to large-scale projects across Western Canada and around the world. We are recognized for delivering innovative solutions that optimize industrial processes while meeting the needs of all stakeholders.
Our services span multiple industrial technology disciplines, including Electrical & Instrumentation, Industrial Ethernet, Cybersecurity, Automation Integration, Data Visualization & Analytics, and Field Maintenance Support. As we continue to grow, we are seeking experienced professionals who are passionate about advancing secure and reliable industrial operations.
What You Will Do
We are seeking a highly skilled DevSecOps Engineer to support the secure design, development, deployment, and operation of industrial software applications used within the Oil & Gas sector. This role combines software engineering, cybersecurity, DevOps, and industrial control system (ICS) security to ensure that mission-critical applications are protected against cyber threats while maintaining operational reliability, safety, and regulatory compliance.
The ideal candidate will have experience implementing secure software development practices, cloud and on-premises infrastructure security, industrial cybersecurity standards, and automated security controls throughout the software development lifecycle (SDLC).
Key Responsibilities
DevSecOps & Application Security
- Integrate security controls into all phases of the Software Development Lifecycle (SDLC).
- Design, implement, and maintain secure CI/CD pipelines.
- Automate security testing, code scanning, vulnerability management, and compliance checks.
- Conduct secure code reviews and identify security vulnerabilities in application code.
- Implement Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Infrastructure as Code (IaC) scanning.
- Develop secure deployment standards for cloud, on-premise, and hybrid environments.
- Manage secrets, encryption keys, certificates, and privileged access controls.
- Ensure secure integration between industrial applications, enterprise systems, and operational technology (OT) environments.
Penetration Testing
Conduct and coordinate:
- Web application and API security testing to identify and remediate vulnerabilities.
- Cloud, container, and Kubernetes security assessments to evaluate risks and security controls.
- Annual third-party penetration testing, including remediation tracking and validation of findings.
Tools:
o Burp Suite Pro
o OWASP ZAP
o Nmap
o Metasploit
o Postman Security Tests
o Kali Linux
Industrial Cybersecurity Responsibilities
- Design and maintain cybersecurity controls protecting Oil & Gas operational applications.
- Implement security architectures aligned with:
IEC 62443
NIST Cybersecurity Framework (CSF)
NIST SP 800-82
ISA/IEC Industrial Automation Security Standards
ISO 27001
- Support cybersecurity risk assessments for industrial applications and supporting infrastructure.
- Develop secure interfaces between SCADA systems, historians, PLCs, RTUs, IIoT devices, and enterprise applications.
- Identify and mitigate cybersecurity threats affecting industrial operations.
- Implement segmentation strategies between IT and OT environments.
- Assist in the deployment and maintenance of Zero Trust security principles across industrial systems.
- Conduct threat modeling for critical operational applications.
Vulnerability Management & Security Monitoring
- Perform regular vulnerability assessments and remediation tracking.
- Analyze application and infrastructure security findings.
- Coordinate security patch management activities.
- Monitor security events using SIEM and security monitoring platforms.
- Investigate cybersecurity incidents affecting development environments and industrial applications.
- Participate in incident response exercises and post-incident reviews.
- Develop automated security alerting and compliance reporting.
- Cloud & Infrastructure Security
- Secure AWS, Azure, or private cloud infrastructures hosting industrial applications.
- Implement infrastructure hardening standards.
- Manage container security for Docker and Kubernetes environments.
- Establish secure network architectures including firewalls, VPNs, reverse proxies, and micro-segmentation.
- Secure APIs and application integrations.
Governance, Risk & Compliance
- Support audits and compliance activities.
- Maintain cybersecurity policies, standards, and procedures.
- Document security architectures, risk assessments, and remediation plans.
- Ensure compliance with customer, industry, and regulatory cybersecurity requirements.
- Track cybersecurity KPIs and risk metrics.
Required Qualifications
Education
Bachelor's Degree in:
- Computer Science
- Software Engineering
- Cybersecurity
- Computer Engineering
- Related Technical Field
Experience
- 5+ years of software development, DevOps, cybersecurity, or DevSecOps experience.
- 3+ years securing industrial, operational technology (OT), or critical infrastructure systems.
- Experience supporting Oil & Gas, Energy, Utilities, Manufacturing, or Industrial Automation environments.
Technical Skills
CI/CD Platforms:
- Azure DevOps
- GitHub Actions
- Jenkins
- GitLab CI/CD
Programming & Scripting:
- Python
- PowerShell
- Bash
- C#
- JavaScript
Cloud Platforms:
- Microsoft Azure
- AWS
- Google Cloud Platform (GCP)
- Security Tools:
- Microsoft Defender Suite
- Microsoft Sentinel
- Splunk
- Qradar
- Securonix
- CrowdStrike
- Qualys
- Tenable
- SonarQube
- Checkmarx
- Veracode
- Snyk
Containers & Infrastructure:
- Docker
- Kubernetes
- Terraform
- Ansible
OT Technologies:
- SCADA Systems
- PLCs
- Historians
- OPC UA
- Modbus
- DNP3
- Industrial Networks
Preferred Certifications
- CISSP (Certified Information Systems Security Skilled)
- GICSP (Global Industrial Cyber Security Professional)
- CSSLP (Certified Secure Software Lifecycle Professional)
- CISM (Certified Information Security Manager)
- Certified Kubernetes Security Specialist (CKS)
- Microsoft Cybersecurity Architect Expert
- AWS Certified DevOps Engineer-Professional
- AWS Certified Security - Specialty
- Azure Security Engineer Associate
- GIAC Industrial Cyber Security Certifications
- ISA/IEC 62443 Cybersecurity Certificate
Key Competencies
- Secure Software Development
- Industrial Cybersecurity
- DevSecOps Automation
- Risk Management
- Threat Modeling
- Incident Response
- Vulnerability Management
- Cloud Security
- OT/IT Convergence Security
- Analytical Problem Solving
- Communication and Collaboration
Success Measures
The successful candidate will:
- Reduce application security vulnerabilities and remediation times.
- Improve security automation coverage across CI/CD pipelines.
- Maintain compliance with industrial cybersecurity standards.
- Successfully secure critical Oil & Gas operational applications.
- Minimize cybersecurity risk to production and operational environments.
- Enhance resilience against cyber threats targeting industrial operations.
Typical Applications Protected
- Production Management Systems
- Pipeline Monitoring Applications
- Asset Integrity Platforms
- Predictive Maintenance Systems
- SCADA and HMI Interfaces
- Digital Oilfield Applications
- Field Data Collection Systems
- Emissions Monitoring Applications
- Industrial IoT Platforms
- Operational Analytics and Reporting Systems
This role is critical to ensuring that industrial software applications remain secure, reliable, and resilient while supporting safe and efficient Oil & Gas operations.
Why Join Us?
- Work on mission-critical OT and cybersecurity projects supporting industrial operations across North and South America.
- Join a team of highly skilled engineers delivering innovative solutions to complex industrial challenges.
- Competitive compensation and comprehensive benefits package.
- Hybrid work environment with flexibility and autonomy.
- Opportunities for career growth, technical leadership, and professional development.
- Exposure to leading OT networking, cybersecurity, and industrial automation technologies.
📌 Development Security Specialist (Industrial Oil & Gas Applications) - calgary
🏢 Pengcorp
📍 Calgary