Maxima

enterprise accounting

DevSecOpsEngineer

Toronto, Ontario, Canada FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“DevSecOps Engineer at Maxima. Skills: DevSecOps, CI/CD pipeline security, cloud security, container orchestration, secure coding practices. Implement and manage DevSecOps practices across the entire Software Development Lifecycle (SDLC). Design and harden CI/CD pipelines”

What You'll Achieve.

ensuring a "shift-left" approach to security; fail builds on high-severity issues; ensuring all secrets are handled securely and not stored in code or plaintext; for supply chain integrity; to meet compliance requirements

Industry & Context.

enterprise accounting
Eligibility Requirements

high intensity and fast pace of a startup environment

What They're Looking For.

Must Have

4+ years of experience in DevSecOps, Security Engineering, or a related role focused on CI/CD pipeline security, Proven experience securing cloud environments, preferably Google Cloud Platform (GCP), with familiarity in IAM, Secret Manager, VPC controls, and Cloud KMS, practical experience with hardening continuous integration/continuous deployment (CI/CD) systems (e.g., GitHub Actions, Blacksmith, or similar), Proficiency in security practices for application development (SAST, DAST, secret scanning) and a deep understanding of common security anti-patterns (e.g., hard-coded secrets, insufficient input validation), Proficient in languages like Golang, Typescripts, Python, or similar programming languages used for automation and development, Familiarity with compliance standards like SOC 2, PCI DSS, or ISO 42001 and experience generating evidence for auditors, Can handle the high intensity and fast pace of a startup environment

Nice to Have

Computer Science is preferred but not mandatory

What You'll Do.

Implement and manage DevSecOps practices across the entire Software Development Lifecycle (SDLC)

Design and harden CI/CD pipelines

Integrate and enforce security checks

Secure cloud infrastructure (GCP)

Manage encryption and key rotation

Oversee container and artifact hardening

Ensure application code follows secure coding best practices

Monitor CI/CD pipelines and production environments for anomalies

security-relevant events

Maintain documentation and controls necessary to align with compliance frameworks

Assist in developer infrastructure work

including deployment automation and internal tooling

How You'll Work.

Communication Scope

verbal and written communication skills

Full Job Description

ABOUT US At Maxima, we're eliminating the pain of enterprise accounting through powerful integrations, intuitive design, and AI-driven automation. By consolidating processes into a single, easy-to-use platform and automating repetitive tasks, we free accounting teams to focus on strategic, high-impact work—achieving more with fewer resources. Our team is led by top engineers and finance professionals from companies like Robinhood, Bolt, EY, Facebook, Twitter, Netflix, Amazon, Google, Airbnb, Rubrik, and more. Together, we're using our extensive industry experience to transform the way businesses manage their finances. Maxima is backed by leading Silicon Valley investors. We raised the largest seed round in our category, with support from top-tier VCs such as Kleiner Perkins and Audacious Ventures. This funding has allowed us to launch a fully operational product and onboard several major customers. YOUR ROLE AT MAXIMA - Implement and manage DevSecOps practices across the entire Software Development Lifecycle (SDLC), ensuring a "shift-left" approach to security. - Comfortable with Kubernetes and other container orchestration platforms - Design and harden CI/CD pipelines (e.g., GitHub Actions) by implementing minimal permissions and leveraging OIDC with Workload Identity Federation for cloud deployments. - Integrate and enforce security checks, including SAST, dependency scanning, and secret scanning (e.g., using tools like Trufflehog or GitGuardian), to fail builds on high-severity issues. - Secure cloud infrastructure (GCP) by implementing the principle of least privilege for IAM, configuring VPC firewalls to restrict traffic, and using Google Secret Manager. - Manage encryption and key rotation using Cloud KMS, ensuring all secrets are handled securely and not stored in code or plaintext. - Oversee container and artifact hardening, including using multi-stage builds, scanning images for vulnerabilities, and signing artifacts (e.g., Cosign) for supply chain integrit

Free ATS check

Applying for this DevSecOps Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Maxima?

Real rants from real employees. Read before you apply.

Read Company Rants →