DevSecOps Engineer
We are looking for a DevSecOps Engineer to lead and strengthen an experienced compliance and security assurance program in Ottawa, Ontario. This Long-term Contract role is centred on expanding an established SOC 2 Type 2 framework beyond core security controls to include confidentiality and availability requirements, while maintaining a strong audit posture. The successful candidate will work closely with stakeholders to build practical controls, maintain continuous evidence collection, and support a resilient, well-governed cloud security environment.<br><br>Responsibilities:<br>• Lead the ongoing management and enhancement of the SOC 2 Type 2 program, with emphasis on broadening coverage to include Confidentiality and Availability Trust Services Criteria.<br>• Develop, implement, and refine controls related to data classification, secure handling of sensitive information, encryption standards, and role-based access practices.<br>• Establish and maintain operational controls that support service availability, including backup validation, disaster recovery readiness, capacity planning, and uptime oversight.<br>• Configure and maintain compliance evidence workflows within Vanta to ensure documentation remains current, accurate, and ready for audit review at all times.<br>• Act as the primary point of contact for external auditors, coordinate audit activities, and address control or evidence questions to minimize audit findings.<br>• Partner with technical and business teams to align cloud security practices, configuration management, and cyber security controls with compliance objectives.<br>• Assess firewall and network security environments, including technologies such as Check Point and Cisco ASA, to support secure infrastructure operations.<br>• Investigate security and operational issues, troubleshoot control gaps, and recommend corrective actions that improve compliance effectiveness and system resilience.
• 5+ years of experience in DevSecOps, cyber security, IT security, or a closely related discipline.<br>• Demonstrated experience managing or contributing significantly to SOC 2 Type 2 compliance programs, including audit preparation and evidence management.<br>• Strong understanding of security controls related to confidentiality, availability, access management, encryption, backup, and disaster recovery.<br>• Hands-on experience with cloud technologies, configuration management practices, and security-focused operational processes.<br>• Practical knowledge of firewall and network security platforms, including Check Point, Cisco ASA, and broader Cisco technologies.<br>• Ability to troubleshoot technical and compliance issues, identify root causes, and implement sustainable solutions.<br>• Familiarity with tools used for continuous compliance tracking and control monitoring, including platforms such as Vanta.<br>• Strong communication and stakeholder management skills, with the ability to work effectively with auditors, engineering teams, and business partners.
<p>Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.</p>
<p>Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. <a href="https://www.roberthalf.com/ca/en/mobile-app" target="_blank">Download the Robert Half app</a> and get 1-tap apply, notifications of AI-matched jobs, and much more.</p>
<p>This job posting is for a current vacancy with our client.</p>
<p>Our specialized recruiting professionals apply their expertise and utilize our proprietary AI to find you great job matches faster.</p>
<p>Questions? Call your local office at 1.888.490.4429. All applicants applying for Canadian job openings must be authorized to work in Canada.</p>
<p>Only job postings for jobs located in Quebec appear in French.</p>
<p>© 2025 Robert Half. By clicking “Apply,” you’re agreeing to Robert Half’s <a href="https://www.roberthalf.com/ca/en/terms">Terms of Use</a> and <a href="https://www.roberthalf.com/ca/en/privacy">Privacy Notice</a>.</p>
- Kanata, ON
- onsite
- Temporary
-
49.4 - 57.2 CAD / Hourly
- We are looking for a DevSecOps Engineer to lead and strengthen an experienced compliance and security assurance program in Ottawa, Ontario. This Long-term Contract role is centred on expanding an established SOC 2 Type 2 framework beyond core security controls to include confidentiality and availability requirements, while maintaining a strong audit posture. The successful candidate will work closely with stakeholders to build practical controls, maintain continuous evidence collection, and support a resilient, well-governed cloud security environment.<br><br>Responsibilities:<br>• Lead the ongoing management and enhancement of the SOC 2 Type 2 program, with emphasis on broadening coverage to include Confidentiality and Availability Trust Services Criteria.<br>• Develop, implement, and refine controls related to data classification, secure handling of sensitive information, encryption standards, and role-based access practices.<br>• Establish and maintain operational controls that support service availability, including backup validation, disaster recovery readiness, capacity planning, and uptime oversight.<br>• Configure and maintain compliance evidence workflows within Vanta to ensure documentation remains current, accurate, and ready for audit review at all times.<br>• Act as the primary point of contact for external auditors, coordinate audit activities, and address control or evidence questions to minimize audit findings.<br>• Partner with technical and business teams to align cloud security practices, configuration management, and cyber security controls with compliance objectives.<br>• Assess firewall and network security environments, including technologies such as Check Point and Cisco ASA, to support secure infrastructure operations.<br>• Investigate security and operational issues, troubleshoot control gaps, and recommend corrective actions that improve compliance effectiveness and system resilience.
- 2026-08-05T00:00:00Z