24 Aug
|
Pengcorp
|
Alberta
Role: Development Security Specialist (DevSecOps)
Reports To: Manager, Application & Software Development
Position Type: Full Term
Position Overview
We are seeking a Senior Application Security & DevSecOps Engineer to establish, operationalize, and continuously improve our Secure Software Development Lifecycle (SSDLC) across enterprise, mobile, cloud, and OT-integrated applications.
This role will serve as the bridge between Software Development, DevOps, Infrastructure, and Operational Technology (OT) teams, ensuring that security is embedded into products, platforms, deployment pipelines, and operational processes from design through production.
The successful candidate will own application security strategy, security automation, vulnerability management, threat modeling, secure architecture reviews, and security governance while enabling quick and reliable product delivery.
Key Responsibilities
Application Security
Lead the integration of security requirements and controls throughout all phases of the Secure Software Development Lifecycle (SSDLC).
Conduct application security assessments, architecture reviews, and threat modeling for new applications, APIs, mobile solutions, and major product enhancements.
Perform secure code reviews and identify security vulnerabilities, insecure coding practices, and design weaknesses.
Establish and maintain secure coding standards, application security guidelines, and remediation best practices.
Lead security design reviews for enterprise, cloud-native, mobile, and OT-integrated applications.
Collaborate with development teams to embed security-by-design principles into software architecture and development practices.
Manage application vulnerability assessment and remediation processes, including risk prioritization and validation of corrective actions.
Coordinate internal and external penetration testing activities and support remediation planning.
Ensure secure integration between enterprise applications, mobile platforms, cloud services, and Operational Technology (OT) environments.
Support customer security assessments, audits, and compliance initiatives related to application security.
DevSecOps
Design, implement, and continuously improve security controls within CI/CD pipelines in collaboration with DevOps teams.
Automate security testing, code scanning, vulnerability detection, and compliance validation throughout the software delivery process.
Implement and maintain:
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
Infrastructure as Code (IaC) scanning
Secret scanning
Container security scanning
Develop and enforce secure deployment standards for cloud, on-premises, and hybrid environments.
Implement security quality gates and release criteria within deployment pipelines.
Manage and govern secrets, encryption keys, certificates, privileged access controls, and secure credential management practices.
Partner with DevOps teams to strengthen cloud security posture, container security, infrastructure security, and platform hardening.
Develop security dashboards, metrics, and reporting to measure security coverage, vulnerability trends, and risk reduction.
Continuously evaluate and improve DevSecOps tooling, automation, and security processes across the organization.
Provide security guidance during platform modernization, cloud migrations, and implementation of emerging technologies.
Penetration Testing
Conduct and coordinate:
Web application and API security testing to identify and remediate vulnerabilities.
Cloud, container, and Kubernetes security assessments to evaluate risks and security controls.
Annual third-party penetration testing, including remediation tracking and validation of findings.
Industrial Cybersecurity Responsibilities
Design and maintain cybersecurity controls protecting Oil & Gas operational applications.
Implement security architectures aligned with:
IEC 62443
NIST Cybersecurity Framework (CSF)
NIST SP 800-82
ISA/IEC Industrial Automation Security Standards
ISO 27001
Support cybersecurity risk assessments for industrial applications and supporting infrastructure.
Develop secure interfaces between SCADA systems, historians, PLCs, RTUs, IIoT devices, and enterprise applications.
Identify and mitigate cybersecurity threats affecting industrial operations.
Implement segmentation strategies between IT and OT environments.
Assist in the deployment and maintenance of Zero Trust security principles across industrial systems.
Conduct threat modeling for critical operational applications.
Vulnerability Management & Security Monitoring
Perform regular vulnerability assessments and remediation tracking.
Analyze application and infrastructure security findings.
Coordinate security patch management activities.
Monitor security events using SIEM and security monitoring platforms.
Investigate cybersecurity incidents affecting development environments and industrial applications.
Participate in incident response exercises and post-incident reviews.
Develop automated security alerting and compliance reporting.
Secure AWS, Azure, or private cloud infrastructures hosting industrial applications.
Manage container security for Docker and Kubernetes environments.
Establish secure network architectures including firewalls, VPNs, reverse proxies, and micro-segmentation.
Secure APIs and application integrations.
Support audits and compliance activities.
Maintain cybersecurity policies, standards, and procedures.
Document security architectures, risk assessments,
and remediation plans.
Ensure compliance with customer, industry, and regulatory cybersecurity requirements.
Track cybersecurity KPIs and risk metrics.
Required Qualifications
Education
Bachelor's Degree in:
Computer Science
Software Engineering
Cybersecurity
Related Technical Field
Experience
5+ years of software development, DevOps, cybersecurity, or DevSecOps experience.
3+ years securing industrial, operational technology (OT), or critical infrastructure systems.
Experience supporting Oil & Gas, Energy, Utilities, Manufacturing, or Industrial Automation environments.
Experience securing cloud-based applications.
Experience with Azure DevOps, GitHub, or GitLab pipelines.
Strong understanding of:
OWASP Top 10
API Security
Identity and Access Management
Secure SDLC
Threat Modeling
CI/CD Security
Technical Skills
CI/CD Platforms:
GitHub Actions
Jenkins
Programming & Scripting:
Python
PowerShell
Bash
C#
AWS
Security Tools:
CrowdStrike
Qualys
Tenable
SonarQube
Checkmarx
Veracode
Containers & Infrastructure:
Docker
Terraform
Ansible
OT Technologies:
SCADA Systems
PLCs
Historians
OPC UA
Modbus
DNP3
Preferred Certifications
CCSK (Certificate of Cloud Security Knowledge)
CISSP (Certified Information Systems Security Professional)
GICSP (Global Industrial Cyber Security Professional)
CSSLP (Certified Secure Software Lifecycle Professional)CISM (Certified Information Security Manager)
Certified Kubernetes Security Specialist (CKS)
Microsoft Cybersecurity Architect Expert
AZ-500 or similar
Azure Security Engineer Associate
GIAC Industrial Cyber Security Certifications
ISA/IEC 62443 Cybersecurity Certificate
Secure Software Development
DevSecOps Automation
Threat Modeling
Vulnerability Management
OT/IT Convergence Security
Analytical Problem Solving
Communication and Collaboration
Success Measures
The successful candidate will:
Reduce application security vulnerabilities and remediation times.
Improve security automation coverage across CI/CD pipelines.
Maintain compliance with industrial cybersecurity standards.
Successfully secure critical Oil & Gas operational applications.
Minimize cybersecurity risk to production and operational environments.
Enhance resilience against cyber threats targeting industrial operations.
Typical Applications Protected
Production Management Systems
Pipeline Monitoring Applications
Asset Integrity Platforms
Predictive Maintenance Systems
SCADA and HMI Interfaces
Digital Oilfield Applications
Field Data Collection Systems
Emissions Monitoring Applications
Operational Analytics and Reporting Systems
This role is critical to ensuring that industrial software applications remain secure, reliable, and resilient while supporting safe and efficient Oil & Gas operations.
#J-18808-Ljbffr
📌 Development Security Specialist (Industrial Oil & Gas Applications) (Alberta)
🏢 Pengcorp
📍 Alberta