
Cloud Security Developer
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in Canada.
• Develop and uphold robust security measures to safeguard our cloud infrastructure and applications.
• Identify, address, and verify security vulnerabilities within the cloud infrastructure.
• Perform security-centric architecture and design evaluations, delivering prompt and actionable recommendations.
• Partner with security leadership, compliance personnel, and engineering teams to implement security initiatives.
• Design, deploy, and oversee security tools such as WAF, IDS/IPS, workload protection, GCP Security Command Center, Azure Security Center, and others.
• Suggest and assist in enhancing security and compliance protocols for nesto's CI/CD pipelines and deployment workflows.
• Automate infrastructure setup and deployment processes utilizing Infrastructure as Code (IaC) tools like Terraform or Pulumi.
• Create and manage scalable procedures for cloud access provisioning while adhering to the principle of least privilege.
• Engage in and support detection and incident response efforts by enhancing observability and alerts, while assisting the incident response team.
• Independently organize and prioritize tasks effectively.
• Facilitate first-party security audits and complete security questionnaires.
• Execute and supervise security evaluations and threat modeling activities.
• Apply security controls within Kubernetes environments.
• Develop DevSecOps tools and integrations.
• Over 5 years of experience in an infrastructure- and/or security-oriented role.
• At least 5 years of development experience (preferably in GoLang, TypeScript/JavaScript).
• Familiarity with common web application vulnerabilities and the OWASP Top 10 framework.
• Competence in analyzing and acting on outputs from DAST and SAST tools (e.g., Tenable, Snyk).
• Strong grasp of DevSecOps principles and experience with CI/CD pipelines (GitHub Actions, Argo CD, Azure DevOps) for automated security testing.
• Proven experience in deploying and customizing security tools to mitigate threats and minimize risk, including vulnerability scanners, static analyzers, web application firewalls (WAF), intrusion detection/prevention systems (IDS/IPS), and endpoint security monitoring.
• Extensive knowledge of cloud and network security, with a deep understanding of Kubernetes.
• Experience with GCP, particularly with services such as Security Command Center, GKE, Cloud IDS, Cloud Armor, and Secrets Manager.
• Experience with Azure, especially with services like Security Center, Azure PaaS App Services, VMs, Azure SQL, Front Door, and Key Vault.
• Proficiency in writing infrastructure-as-code using tools such as Terraform, Pulumi, and Helm.
• Knowledge of common security frameworks and benchmarks such as CIS, NIST, and MITRE ATT&CK.
• Understanding of identity and access management (IAM) principles and cloud-native IAM solutions.
• Eagerness for continuous learning and knowledge sharing.
• Bilingual in English and French.
• Employee mortgage program offering exclusive preferred rates.
• Comprehensive health benefits, including best-in-class extended health, dental, and vision coverage with 100% prescription drug reimbursement.
• Access to a group retirement savings plan (RRSP/DPSP) with competitive employer matching contributions.
• Telemedicine and family support programs, including supplemental benefits for maternity and parental leave.
• Flexible work environment: fully remote or in one of our offices (Montréal, Quebec City, Toronto, etc.).
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.