
Cloud Security Developer
Nesto Cloud7 months ago
Remote, CanadaSenior
Responsibilities
- Implement and maintain security controls for cloud infrastructure and applications.
- Discover, remediate, and validate security issues across cloud infrastructure.
- Conduct security-focused architectural and design reviews and provide actionable recommendations.
- Build, deploy, and manage WAF, IDS/IPS, workload protection, GCP Command Center, and Azure Security Center tools.
- Improve security and compliance for CI/CD pipelines and deployment processes.
- Automate infrastructure provisioning and deployment using Infrastructure as Code tools.
- Design and operate scalable cloud access provisioning processes based on least privilege.
- Support incident detection and response by improving observability and alerting.
- Support audits, first-party security questionnaires, security assessments, and threat modeling exercises.
- Implement security controls within Kubernetes and build DevSecOps tools and integrations.
Requirements
- At least 5 years of experience working on infrastructure and/or security teams.
- At least 5 years of development experience, ideally with GoLang and TypeScript/JavaScript.
- Knowledge of common web application vulnerabilities and the OWASP Top 10.
- Ability to analyze and act on DAST and SAST results from tools such as Tenable and Snyk.
- DevSecOps experience and familiarity with GitHub Actions, Argo CD, and Azure DevOps for automated security testing.
- Experience deploying and customizing vulnerability scanners, static analyzers, WAFs, IDS/IPS, and endpoint security monitoring tools.
- Strong understanding of cloud and network security, Kubernetes, and cloud-native IAM.
- Experience with GCP services including Security Command Center, GKE, Cloud IDS, Cloud Armor, and Secrets Manager.
- Experience with Azure services including Security Center, Azure PaaS App Services, VMs, Azure SQL, Front Door, and Key Vault.
- Experience writing Infrastructure as Code with Terraform, Pulumi, and Helm.
- Knowledge of CIS, NIST, and MITRE ATT&CK security frameworks and benchmarks.
- Experience monitoring and managing security posture through security tooling outputs.
- Bilingual English and French communication skills.
Benefits
- Fully paid premium benefits including comprehensive insurance, telemedicine, and mental health services for employees and their families.
- Four weeks of vacation.
- Access to required tools and resources.
- Hybrid work model.
- Collaborative environment with learning and career growth opportunities.