29 Sep
|
Querentia
|
Toronto
Senior DevSecOps & AI Security Engineer Role Overview
We are seeking an experienced Senior DevSecOps & AI Security Engineer to strengthen security across applications, cloud-native platforms, DevSecOps pipelines, and AI/LLM-based solutions. The role focuses on application security, offensive security testing, vulnerability management, secure code reviews, cloud security, and emerging AI security practices. Primary Skills
Application Security SAST, DAST, Secure Code Review
Penetration Testing Web, API, Mobile
AI/LLM Security Prompt Injection, Jailbreak & Model Security
DevSecOps & CI/CD Security
Vulnerability Management & Remediation
Security Automation using Python Secondary Skills
Azure Cloud Security
Container & Kubernetes Security
SCA & Open-Source Security
GitHub Security Controls
Threat Modeling & Risk Assessment
Security Governance & Developer Enablement Key Responsibilities Security Assessment & Testing
Perform penetration testing across web, API, mobile, cloud-native, and AI-powered applications.
Conduct secure code reviews and identify application security weaknesses.
Validate findings from SAST, DAST, SCA, and container security tools.
Perform vulnerability analysis, root-cause investigation, and remediation validation. AI Security
Assess AI/LLM applications for security vulnerabilities and misuse scenarios.
Conduct prompt injection, manipulation, and jailbreak testing.
Evaluate AI deployment architectures and recommend appropriate security controls.
Support secure AI adoption across enterprise platforms. DevSecOps & Automation
Integrate security controls into CI/CD pipelines and deployment workflows.
Implement shift-left security practices.
Automate security validation and reporting using Python.
Optimize vulnerability assessment and remediation workflows.
Enhance security monitoring and policy enforcement across development environments. Cloud & Container Security
Perform Azure cloud security assessments.
Review Kubernetes and containerized workloads for security risks.
Analyze container images and deployment configurations.
Recommend cloud-native security practices and remediation actions. Vulnerability Management & Governance
Review and validate vulnerabilities identified by enterprise security tools.
Prioritize findings based on exploitability, business risk, and operational impact.
Drive remediation with engineering teams and verify effectiveness.
Support security governance, compliance, and audit activities. Stakeholder Engagement
Collaborate with development, DevOps, architecture, and product teams.
Provide guidance on secure coding and vulnerability remediation.
Mentor engineering teams on security-first development.
Present security findings and recommendations to technical and business stakeholders. Required Qualifications
Bachelor's or Master's degree in Computer Science, Information Security, Cybersecurity, or related field.
6+ years of experience in Application Security, DevSecOps, Offensive Security, or Security Engineering.
Strong understanding of SDLC, SSDLC, DevSecOps, and MLOps.
Hands-on experience with penetration testing, secure code reviews, and vulnerability management.
Experience securing cloud-native and AI-enabled applications.
Robust Python scripting and security automation experience. Certifications
Any 2 3 certifications mandatory:
CISSP
CSSLP
Microsoft Azure Security Engineer (AZ-500)
Certified DevSecOps Professional
Cloud Security Certifications Azure/AWS
📌 Senior DevSecOps & AI Security Engineer (Toronto)
🏢 Querentia
📍 Toronto