bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesMaximaDevSecOps Engineer

DevSecOps Engineer

Maxima · Toronto · Active · Ashby

Job facts

FieldValue
CompanyMaxima
TitleDevSecOps Engineer
Normalized title-
Department / teamEngineering & Product / Engineering & Product
LocationToronto, ON, Canada
Work model-
Employment typeFull Time
Salary-
Statusactive
ATS providerAshby
Posted / first seen / 2026-05-29
Changed / last seen2026-05-29 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Maxima.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Ashby.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Toronto.Open
Department jobsActive postings in Engineering & Product.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyMaxima
Source11869f36-ba5d-4a91-b101-c8ac876c5aff
ATS providerAshby

Description

About Us At Maxima, we're eliminating the pain of enterprise accounting through powerful integrations, intuitive design, and AI-driven automation. By consolidating processes into a single, easy-to-use platform and automating repetitive tasks, we free accounting teams to focus on strategic, high-impact work—achieving more with fewer resources. Our team is led by top engineers and finance professionals from companies like Robinhood, Bolt, EY, Facebook, Twitter, Netflix, Amazon, Google, Airbnb, Rubrik, and more. Together, we're using our extensive industry experience to transform the way businesses manage their finances. Maxima is backed by leading Silicon Valley investors. We raised the largest seed round in our category, with support from top-tier VCs such as Kleiner Perkins and Audacious Ventures. This funding has allowed us to launch a fully operational product and onboard several major customers. Your Role at Maxima Implement and manage DevSecOps practices across the entire Software Development Lifecycle (SDLC), ensuring a "shift-left" approach to security. Comfortable with Kubernetes and other container orchestration platforms Design and harden CI/CD pipelines (e.g., GitHub Actions) by implementing minimal permissions and leveraging OIDC with Workload Identity Federation for cloud deployments. Integrate and enforce security checks, including SAST, dependency scanning, and secret scanning (e.g., using tools like Trufflehog or GitGuardian), to fail builds on high-severity issues. Secure cloud infrastructure (GCP) by implementing the principle of least privilege for IAM, configuring VPC firewalls to restrict traffic, and using Google Secret Manager. Manage encryption and key rotation using Cloud KMS, ensuring all secrets are handled securely and not stored in code or plaintext. Oversee container and artifact hardening, including using multi-stage builds, scanning images for vulnerabilities, and signing artifacts (e.g., Cosign) for supply chain integrity. Ensure application code follows secure coding best practices, including input validation, output encoding to prevent XSS, and secure authentication/session management via Descope integration. Monitor CI/CD pipelines and production environments (using GCP and Datadog) for anomalies, security-relevant events, and audit logs to meet compliance requirements. Maintain documentation and controls necessary to align with compliance frameworks, including SOC 2, SOC 1, and ISO 42001 for AI governance. Assist in developer infrastructure work, including deployment automation and internal tooling, in a full-stack environment. Your Qualifications 4+ years of experience in DevSecOps, Security Engineering, or a related role focused on CI/CD pipeline security. Bachelor’s degree in any engineering discipline; Computer Science is preferred but not mandatory. Proven experience securing cloud environments, preferably Google Cloud Platform (GCP), with familiarity in IAM, Secret Manager, VPC controls, and Cloud KMS. Strong practical experience with hardening continuous integration/continuous deployment (CI/CD) systems (e.g., GitHub Actions, Blacksmith, or similar). Proficiency in security practices for application development (SAST, DAST, secret scanning) and a deep understanding of common security anti-patterns (e.g., hard-coded secrets, insufficient input validation). Proficient in languages like Golang, Typescripts, Python, or similar programming languages used for automation and development. Familiarity with compliance standards like SOC 2, PCI DSS, or ISO 42001 and experience generating evidence for auditors. Can handle the high intensity and fast pace of a startup environment. Strong verbal and written communication skills. Maxima is an equal opportunity employer. We do not discriminate based on race, color, ethnicity, ancestry, national origin, religion, sex, gender, gender identity, gender expression, sexual orientation, age, disability, veteran status, genetic information, marital status or any legally protected status.

Full job record

Job ID5e42407abc4e5c537d12bb08a15a7ae652216de9
Org ID387adba7-877f-4cf1-a09b-997ce2e11227
Source ID11869f36-ba5d-4a91-b101-c8ac876c5aff
Board ID11869f36-ba5d-4a91-b101-c8ac876c5aff
Providerashby
Provider Job Keyd5de5a9a-61dd-44ef-8943-870464245fde
TitleDevSecOps Engineer
Normalized Title
Statusactive
Activeyes
Location TextToronto
DepartmentEngineering & Product
TeamEngineering & Product
Employment Typefull_time
Workplace Type
Remote Policy
CountryCanada
RegionON
CityToronto
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.ashbyhq.com/Maxima/d5de5a9a-61dd-44ef-8943-870464245fde
Apply URLhttps://jobs.ashbyhq.com/Maxima/d5de5a9a-61dd-44ef-8943-870464245fde/application
First Seen At2026-05-29 05:06:51Z
Last Seen At2026-06-06 19:18:51Z
Last Checked At2026-06-06 19:18:51Z
Last Changed At2026-05-29 05:06:51Z
Inactive At
Source Posted At
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=ashby/board=Maxima/date=2026-06-06/2026-06-06T19-18-48-635Z-30682c88250aa7597b48fbaaeffdc0661fb66dba52a003546422a0fdfac866d2.json
Event Fields
{
  "content_hash": "de8a854502c55a6aa99e397652b377dd55fe9d8d759bcd4a92d8c60de2e617aa",
  "source_hash": "5903e5518273cc6283dcfa68e5b4be42c9f6ac8a40a0f2cfc8e3497930ea7549",
  "last_changed_at": "2026-05-29T05:06:51.723Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Toronto",
    "city": "Toronto",
    "region": "ON",
    "country": "Canada",
    "is_remote": false,
    "confidence": 0.75
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T19:18:51.718Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Toronto",
      "city": "Toronto",
      "region": "ON",
      "country": "Canada",
      "is_remote": false,
      "confidence": 0.75
    },
    "countries": [
      "Canada"
    ]
  },
  "remote_policy": null,
  "salary_period": null,
  "workplace_type": null,
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "id": "d5de5a9a-61dd-44ef-8943-870464245fde",
  "team": "Engineering & Product",
  "title": "DevSecOps Engineer",
  "jobUrl": "https://jobs.ashbyhq.com/Maxima/d5de5a9a-61dd-44ef-8943-870464245fde",
  "address": null,
  "applyUrl": "https://jobs.ashbyhq.com/Maxima/d5de5a9a-61dd-44ef-8943-870464245fde/application",
  "isListed": true,
  "isRemote": false,
  "location": "Toronto",
  "updatedAt": null,
  "apiVersion": "ashby-non-user-graphql-v1",
  "department": "Engineering & Product",
  "publishedAt": null,
  "workplaceType": null,
  "employmentType": "FullTime",
  "secondaryLocations": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/5e42407abc4e5c537d12bb08a15a7ae652216de9?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/387adba7-877f-4cf1-a09b-997ce2e11227JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/11869f36-ba5d-4a91-b101-c8ac876c5affJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/5e42407abc4e5c537d12bb08a15a7ae652216de9/eventsJSON