Title: SecDevOps Specialist
Requisition ID: 255763
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.
We are looking for an experienced SecDevOps Specialist to join our Authentication Services team to help build the next generation of Authentication Services for the Bank. This is an exciting opportunity to start with us on a challenging journey building, managing, maintaining and supporting a critical new Digital Identity platform for Scotiabank.
You will participate in the operational implementation, risk management, vulnerability remediation and software currency management for one of the largest, cutting-edge Digital Identity and Access Management (IAM) services in Canada. You will be part of a larger highly skilled professional organization, that will deliver high demand services like biometric (fingerprint/face-id) authentication, push notifications, password-less authentication, behaviour authentication … among others.
If you are a savvy infrastructure and vulnerability management focused individual with a keen interest in authentication and security services in a fast-moving environment, this is the position for you. As a value-added member of a talented group of specialists, you will not only get the opportunity to grow and learn from experts in security and IAM domains but also to mentor peers to enhance your leadership skills – together ultimately shaping the future of our Bank.
Is this role right for you? In this role, you will:
Technical Leadership & Infrastructure Delivery
- Support enterprise-wide IAM services including authentication, provisioning, federation, and directory platforms
- Lead the automation of secure infrastructure scripting solutions using Ansible, Bash, and CI/CD pipelines.
- Enhance core CIAM infrastructure components, including middleware configuration management (e.g, Tomcat), logging/monitoring (e.g., Splunk, Dynatrace), and deployment tooling (Ansible, Terraform).
- Participate and contribute to platform upgrades, software currency initiatives, and environment lifecycle management.
- Actively contribute to production support for infrastructure services (L2+), ensuring high reliability and rapid response to incidents.
- Prioritize and drive operational standards and best practices for secure configuration, code quality, and operational readiness.
IT Risk Management & Vulnerability Management
- Lead end-to-end internal vulnerability management process: Identify, Analyze, Prioritize, Track, Monitor & Review, Remediate, Report, Communicate
- Partner with security, compliance, and audit teams to address IT risk findings and ensure closure of issues within SLA.
- Integrate risk reduction practices into day-to-day workstreams and automation pipelines.
- Lead efforts to track, report, and communicate risk status, exceptions, and metrics to stakeholders and leadership.
- Promote secure-by-design principles and ensure compliance with Scotiabank's regulatory and IT standards.
- Analyze SAST/DAST/TRA/PENTEST vulnerabilities and work collaboratively with Engineering and Operations teams to devise effective and timely remediation plans.
Planning, Communication & Technical Navigation
- Break down complex technical/audit requirements into executable tasks with clearly defined deliverables, owners, and timelines.
- Support project tracking, reporting on progress, risks, and key results to technical and business stakeholders.
- Act as a liaison between operations and other cross-functional teams (e.g., development, product, architecture, compliance, etc.) to drive delivery alignment.
- Assist in defining and refining KPIs that measure infrastructure and security engineering performance.
Do you have the skills that will enable you to succeed in this role? We'd love to work with you if you have:
- 5+ years of experience in application configuration & deployments, supporting large, complex, highly available enterprise systems.
- 3+ years of hands-on experience in utilizing DevOps pipeline to build, scan, test and deploy code to various production and pre-production environments.
- 3+ years of experience working with any Configuration tool such as Ansible, Chef, Puppet.
- Experience working with Checkmarx, Fortify, BlackDuck scanning tools
- Experience working with Linux, Tomcat, SSL, Cryptography, Forgerock, Ping Identify, ServiceNow or equivalents
- Proficiency with Continuous Integration and Delivery (CI/CD) pipelines (e.g., Jira, Jenkins, Gradle, Bitbucket, Artifactory etc.)
- Must possess excellent verbal and written communication skills, as well as strong problem-solving skills coupled with the ability to collaborate with and lead teams toward to resolution.
- Strong working experience with incident management and setting up monitoring alerts.
- A proactive approach to spotting problems, areas for improvement, and performance bottlenecks. Be self-motivated, autonomous and a team player in a fast-paced environment.
What's in it for you?
- Diversity, Equity, Inclusion & Allyship - We strive to create an inclusive culture where every employee is empowered to reach their fullest potential, respected for who they are, and are embraced through bias-free practices and inclusive values across Scotiabank. We embrace diversity and provide opportunities for all employee to learn, grow & participate through our various Employee Resource Groups (ERGs) that span across diverse gender identities, ethnicity, race, age, ability & veterans.
- Accessibility and Workplace Accommodations - We value the unique skills and experiences each individual brings to the Bank and are committed to creating and maintaining an inclusive and accessible environment for everyone. Scotiabank continues to locate, remove and prevent barriers so that we can build a diverse and inclusive environment while meeting accessibility requirements.
- Upskilling through online courses, cross-functional development opportunities, and tuition assistance.
- Competitive Rewards program including bonus, flexible vacation, personal, sick days and benefits will start on day one.
- Community Engagement - no matter where you choose to work from; we offer opportunities for community engagement & belonging with our various programs such as hackathons, contests, Humans of Digital and much more!
Location(s): Canada : Ontario : Toronto
Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.
Job Segment:
Test Engineer, Risk Management, Testing, Compliance, Software Engineer, Engineering, Finance, Legal, Technology