11 Sep
|
AceStack
|
Montreal
Job Title: Senior Dev
SecOps Architect Job Type: Full-Time Location: Montreal, QC (Remote) Job Overview We are looking for a Senior Dev
SecOps Architect with 10+ years of experience to lead the architecture, governance, and technical evolution of enterprise Dev
SecOps platforms and secure software delivery pipelines.
You will design, build, and demonstrate hands-on proofs-of-concept (PoCs) while embedding security controls across multi-stage CI/CD workflows, containerized environments, and cloud infrastructure.
Key Responsibilities Enterprise Architecture & Delivery: Lead the strategy, governance, and rollout of enterprise Dev
SecOps practices; build hands-on PoCs to validate solutions before organization-wide adoption. CI/CD & Pipeline Governance: Establish standards for branching strategies, pull requests, reusable multi-stage YAML pipelines, approval gates, and embedded security checks.
Supply Chain & Vulnerability Security: Integrate SAST, SCA, secret scanning, IaC analysis, container scanning, software bill of materials (SBOM) generation, artifact signing, and policy enforcement into delivery workflows.
Kubernetes & Cloud Security: Partner with Cloud Architecture teams to implement secure deployment patterns, admission controls, Helm, Git
Ops workflows, workload identities,
and pipeline integrations (specifically GKE).
Container & Artifact Governance: Oversee container image registries, image signing, immutability, vulnerability management, and secure artifact management via Sonatype Nexus.
Automation & Applied AI: Build reusable pipeline templates, scripts, and secrets-management workflows; evaluate AI-assisted tools to streamline pipeline triage, testing, and operational support.
Compliance & Technical Leadership: Support architecture reviews, risk assessments, and audit evidence gathering while mentoring application teams, DSO Champions, and platform engineers.
Key Requirements Experience: 10+ years of total experience in software engineering, Dev
SecOps, and enterprise architecture roles.
Security & Supply Chain: Deep experience with SAST/SCA tooling, Sonatype Nexus, container image security, SBOMs, and supply chain security frameworks.
Containerization & Orchestration: Proven expertise in Kubernetes, GKE, Helm, and Git
Ops delivery models.
Automation: Proficiency in multi-stage YAML pipelines, scripting, platform engineering, and enterprise secrets management.
Leadership: Robust track record in technical governance, audit compliance, risk mitigation, and team mentorship.
📌 Senior DevSecOps Architect (Montreal)
🏢 AceStack
📍 Montreal