DevSecOps Engineer

Posted 23 Days Ago
Be an Early Applicant
Toronto, ON, CAN
In-Office
Mid level
Artificial Intelligence • Fintech
The first agentic AI platform for enterprise accounting
The Role
Implement and manage DevSecOps practices in SDLC, focusing on security integration, CI/CD pipeline hardening, cloud infrastructure security, and compliance documentation.
Summary Generated by Built In
About Us

At Maxima, we're eliminating the pain of enterprise accounting through powerful integrations, intuitive design, and AI-driven automation. By consolidating processes into a single, easy-to-use platform and automating repetitive tasks, we free accounting teams to focus on strategic, high-impact work—achieving more with fewer resources.

Our team is led by top engineers and finance professionals from companies like Robinhood, Bolt, EY, Facebook, Twitter, Netflix, Amazon, Google, Airbnb, Rubrik, and more. Together, we're using our extensive industry experience to transform the way businesses manage their finances.

Maxima is backed by leading Silicon Valley investors. We raised the largest seed round in our category, with support from top-tier VCs such as Kleiner Perkins and Audacious Ventures. This funding has allowed us to launch a fully operational product and onboard several major customers.

Your Role at Maxima
  • Implement and manage DevSecOps practices across the entire Software Development Lifecycle (SDLC), ensuring a "shift-left" approach to security.

  • Comfortable with Kubernetes and other container orchestration platforms

  • Design and harden CI/CD pipelines (e.g., GitHub Actions) by implementing minimal permissions and leveraging OIDC with Workload Identity Federation for cloud deployments.

  • Integrate and enforce security checks, including SAST, dependency scanning, and secret scanning (e.g., using tools like Trufflehog or GitGuardian), to fail builds on high-severity issues.

  • Secure cloud infrastructure (GCP) by implementing the principle of least privilege for IAM, configuring VPC firewalls to restrict traffic, and using Google Secret Manager.

  • Manage encryption and key rotation using Cloud KMS, ensuring all secrets are handled securely and not stored in code or plaintext.

  • Oversee container and artifact hardening, including using multi-stage builds, scanning images for vulnerabilities, and signing artifacts (e.g., Cosign) for supply chain integrity.

  • Ensure application code follows secure coding best practices, including input validation, output encoding to prevent XSS, and secure authentication/session management via Descope integration.

  • Monitor CI/CD pipelines and production environments (using GCP and Datadog) for anomalies, security-relevant events, and audit logs to meet compliance requirements.

  • Maintain documentation and controls necessary to align with compliance frameworks, including SOC 2, SOC 1, and ISO 42001 for AI governance.

  • Assist in developer infrastructure work, including deployment automation and internal tooling, in a full-stack environment.

Your Qualifications
  • 4+ years of experience in DevSecOps, Security Engineering, or a related role focused on CI/CD pipeline security.

  • Bachelor’s degree in any engineering discipline; Computer Science is preferred but not mandatory.

  • Proven experience securing cloud environments, preferably Google Cloud Platform (GCP), with familiarity in IAM, Secret Manager, VPC controls, and Cloud KMS.

  • Strong practical experience with hardening continuous integration/continuous deployment (CI/CD) systems (e.g., GitHub Actions, Blacksmith, or similar).

  • Proficiency in security practices for application development (SAST, DAST, secret scanning) and a deep understanding of common security anti-patterns (e.g., hard-coded secrets, insufficient input validation).

  • Proficient in languages like Golang, Typescripts, Python, or similar programming languages used for automation and development.

  • Familiarity with compliance standards like SOC 2, PCI DSS, or ISO 42001 and experience generating evidence for auditors.

  • Can handle the high intensity and fast pace of a startup environment.

  • Strong verbal and written communication skills.

Maxima is an equal opportunity employer. We do not discriminate based on race, color, ethnicity, ancestry, national origin, religion, sex, gender, gender identity, gender expression, sexual orientation, age, disability, veteran status, genetic information, marital status or any legally protected status.

Skills Required

  • 4+ years of experience in DevSecOps, Security Engineering, or related role
  • Bachelor's degree in engineering discipline; Computer Science preferred
  • Proven experience securing cloud environments, preferably GCP
  • Experience with CI/CD systems (e.g., GitHub Actions)
  • Familiarity with security practices for application development
  • Proficient in languages like Golang, Typescript, Python
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Mateo, California
55 Employees
Year Founded: 2024

What We Do

Maxima is the first agentic AI platform for enterprise accounting to deliver SOX-compliant, real-time close. From journal entries and reconciliations to variance analysis, Maxima automates the most manual and error-prone tasks across record-to-report operations. Our team brings together top fintech engineers from Robinhood, Bolt, X.ai, and Facebook with former accountants and auditors from EY, BlackLine, and FloQast to solve a decades-old problem with agent prepared, human reviewed accounting.

Similar Jobs

Rain Logo Rain

Devsecops Engineer

Aerospace • Artificial Intelligence • Robotics • Software
Remote or Hybrid
8 Locations
50 Employees

Autodesk Logo Autodesk

Devsecops Engineer

Big Data • Cloud • Digital Media • Machine Learning • Mobile • Software • Industrial
In-Office
Toronto, ON, CAN
13285 Employees
88K-129K Annually

WorkWhile Logo WorkWhile

Senior Software Engineer

Artificial Intelligence • HR Tech • Information Technology • Machine Learning • Software • App development • Industrial
Hybrid
4 Locations
100 Employees
150K-200K Annually

Capco Logo Capco

Database Administrator

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Hybrid
Toronto, ON, CAN
6000 Employees
113K-145K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account