Full Job Description
We are seeking an Information Technology Security Engineer to support security engineering activities for cloud-based applications within a Government of Canada environment. The successful candidate will implement secure development practices, support CI/CD security automation, and guide teams through GC Security Assessment and Authorization (SA&A) processes.
In this role, you will:
• Implement security controls, automated scanning, and secure coding practices within CI/CD pipelines.
• Support security engineering for cloud-based applications throughout development and release cycles.
• Lead or support Government of Canada Security Assessment and Authorization (SA&A) activities.
• Apply modern security principles to custom software applications.
• Collaborate with development teams to ensure compliance with GC security standards and cloud best practices.
• Identify vulnerabilities, recommend remediation, and support continuous security improvement.
• Bachelor's degree or College Diploma.
• 5+ years experience in a software development environment working with:
• CI/CD pipelines
• Security engineering practices
• Experience navigating the Government of Canada SA&A process for at least two (2) cloud-based applications developed within the past 5 years.
• 2+ years (within last 5 years) implementing automated security scanning and controls in CI/CD pipelines.
• Experience applying modern security principles to custom software applications released within the past three (3) years
Nice to have
• Experience with AWS, Azure, or hybrid cloud environments.
• Knowledge of GC security policies, ITSG-33, and cloud security frameworks.
• Security certifications (CISSP, CCSP, CEH, etc.).