AI Security & DevOps Engineer in Canada Creek, Nova Scotia at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a AI Security & DevOps Engineer based in Canada.
This role is responsible for defining how AI systems move securely from prototype to production across a broad portfolio of client engagements. You will combine application security, DevOps, cloud infrastructure, identity, and AI-specific security expertise to establish practical production standards. The position has significant ownership over threat modeling, secure engineering practices, CI/CD controls, and agent security. You will also work directly with enterprise security teams to translate requirements into technical solutions and approval-ready evidence. With clients often operating in regulated environments and Microsoft-focused technology stacks, the role requires strong judgment around risk, scale, and production readiness. You will help shape engineering standards while remaining deeply hands-on with the systems and platforms being secured.
- Own and continuously improve the security standard for moving AI systems from development through production.
- Define and operate security gates across the delivery lifecycle, including threat modeling, architecture reviews, design reviews, and production readiness decisions.
- Harden applications and AI systems across authentication, identity, secrets management, data protection, egress controls, and access management.
- Establish controls for AI-specific risks such as prompt injection, excessive agency, tool and connector permissions, untrusted inputs, insecure agent loops, and MCP authentication.
- Own security-critical platform capabilities including CI/CD, automated security scanning, infrastructure-as-code, environment management, access controls, logging, and telemetry.
- Audit repositories and internal systems, identify vulnerabilities and weaknesses, and implement appropriate remediation.
- Lead security discussions with enterprise clients, engaging security teams early and translating requirements into practical technical controls.
- Develop threat models, security documentation, evidence packages, and other materials required to support enterprise security reviews and production approvals.
- Establish preferred technology and vendor patterns for authentication, secrets, telemetry, and security scanning to create consistency across engagements.
- Incorporate security requirements into project scoping, timelines, and production roadmaps, accounting for validation and approval processes.
- Raise security standards across engineering through technical reviews, pairing, mentoring, and clear written guidance.
Requirements:
- Deep hands-on experience in application and product security, including threat modeling, vulnerability identification, remediation, and secure design.
- Strong DevOps and platform engineering expertise covering CI/CD, infrastructure-as-code, cloud environments, secrets management, and observability.
- Strong experience with Azure, with additional familiarity with AWS and/or GCP.
- Advanced knowledge of identity and authentication technologies, including OAuth/OIDC, SSO, SCIM, RBAC, conditional access, and Microsoft Entra.
- Demonstrated expertise in LLM and AI agent security, including prompt injection, excessive agency, tool and connector permissions, insecure output handling, retrieval abuse, and AI supply chain risks.
- Practical experience implementing secure SDLC practices, including SAST, DAST, SCA, dependency management, software supply chain controls, and automated security reviews.
- Strong judgment and the ability to right-size security controls according to the maturity, risk, and business impact of a system.
- Proven ability to work directly with enterprise security teams and communicate technical risks in terms that executives and decision-makers can understand.
- An AI-native mindset, with hands-on experience using modern AI tools and building or working with AI and agent-based systems.
- Strong ownership, initiative, and written communication skills, with the ability to create effective technical standards, security evidence, and decision-making documents.
- Ability to operate independently across multiple projects and priorities while collaborating effectively with engineering and client teams.
- Experience in regulated industries such as financial services, healthcare, or other highly scrutinized environments is a plus.
- Consulting, agency, or forward-deployed experience working directly with client security organizations is advantageous.
- Familiarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, or ISO 42001 is a plus.
- Experience with SOC 2 or ISO 27001, AI red teaming, adversarial testing, or abuse-case analysis is desirable.
Benefits:
- CAD $180,000–$230,000 compensation range for Canada, with actual compensation calibrated according to location, qualifications, experience, and seniority.
- Fully remote position for candidates based in Canada.
- Occasional client travel.
- Flexible working arrangements across North American and international teams, with most collaboration overlapping North American time zones.
- Medical, dental, and vision coverage.
- Flexible paid time off.
- Health FSA/HSA.
- Life insurance.
- Opportunity to work across diverse AI security, cloud, DevOps, and enterprise technology environments.
- Significant technical ownership and influence over security standards, production readiness, and engineering practices.
- Exposure to complex AI systems and emerging security challenges involving agents, tools, connectors, and AI infrastructure.