DevSecOps Engineer
Actalent•Scarborough, Toronto
ContractMid Level
👁️ 0 views•📝 0 applications•Posted 9/11/2026•Expires 10/11/2026
Get alerts for roles like this
More DevSecOps Engineer roles in Scarborough, Toronto — straight to your inbox. No account needed.
Applying to this role? Tailor your résumé to this job description in one click, then download it clean — no watermark, no subscription.
Job Description
DevSecOps Engineer (Embedded Firmware Security)
Job Description
The Embedded DevSecOps Engineer is responsible for securing the full firmware development lifecycle for a next-generation connected embedded controller platform. You will own firmware security across CI/CD pipelines, artifact signing, secrets management, PKI infrastructure, OTA update security, vulnerability management, and cybersecurity compliance initiatives. In this highly visible role, you work closely with firmware, hardware, QA, IoT, product, and manufacturing teams to ensure security is embedded throughout the product lifecycle, from development and manufacturing through deployment and field updates. This position offers the opportunity to shape the security strategy for cutting-edge connected products while operating at the intersection of embedded systems, cloud technologies, and cybersecurity.
Responsibilities
• Own and secure the end-to-end firmware development lifecycle for connected embedded controller platforms, from design through deployment and field updates.
• Design, build, and maintain secure CI/CD pipelines specifically tailored for firmware and embedded products.
• Implement and manage firmware artifact signing processes, ensuring integrity and authenticity of all released binaries.
• Establish and oversee secrets management practices for build environments, deployment workflows, and embedded devices.
• Design, operate, and maintain PKI infrastructure, including X.509 certificate management and device identity lifecycle.
• Implement and enforce Secure Boot and hardware Root of Trust mechanisms across embedded platforms.
• Manage HSM/KMS-backed key management processes, ensuring secure generation, storage, rotation, and usage of cryptographic keys.
• Lead vulnerability management activities, including CVE triage, remediation planning, and risk management for embedded and IoT products.
• Configure, integrate, and optimize SAST, SCA, and SBOM tools within firmware CI/CD pipelines to continuously improve code and dependency security.
• Conduct threat modeling and security risk assessments for embedded controllers, IoT products, and related services, and translate findings into actionable controls.
• Drive embedded and IoT product security initiatives, ensuring security requirements are integrated into firmware, hardware, and cloud architectures.
• Collaborate closely with firmware, hardware, QA, product, manufacturing, and IoT teams to embed security best practices into daily engineering workflows.
• Support OTA firmware update security by defining secure update mechanisms, validation processes, and rollback strategies.
• Contribute to cybersecurity compliance efforts, including security audit support and evidence collection for standards such as IEC and EN.
• Develop and maintain DevSecOps metrics and reporting that clearly communicate security posture, vulnerabilities, and progress to engineering leadership.
• Help build, mature, and continuously improve the embedded cybersecurity function, including processes, tooling, and standards.
• Provide guidance and technical leadership on embedded, IoT, and industrial automation security topics across the engineering organization.
• Participate in security incident analysis related to firmware or embedded systems and support remediation and prevention strategies.
• Document security architectures, processes, and procedures to ensure repeatability, transparency, and effective knowledge sharing.
Essential Skills
• 5+ years of experience in DevOps, DevSecOps, Embedded Software, or Firmware Engineering.
• 2+ years of experience focused specifically on cybersecurity or security engineering.
• Proven experience building and maintaining CI/CD pipelines for firmware or embedded products.
• Hands-on experience with firmware artifact signing and secure management of secrets in build and deployment workflows.
• Strong understanding of Secure Boot, hardware Root of Trust, and core firmware security concepts.
• Practical experience in vulnerability management, including CVE triage, remediation planning, and risk management.
• Experience working with SAST tools, software composition analysis (SCA), and generating and managing SBOMs.
• Solid experience in PKI and certificate management, including X.509, device certificates, and full certificate lifecycle management.
• Experience with HSM/KMS-backed key management solutions for secure cryptographic key handling.
• Experience working with Docker and containerized build environments to support secure and reproducible firmware builds.
• Hands-on experience with CI/CD tools such as Jenkins, Bitbucket, GitLab CI, GitHub Actions, or similar platforms.
• Experience performing threat modeling and security risk assessments for embedded or connected systems.
• Experience in embedded, IoT, industrial automation, automotive, or other connected device environments.
Additional Skills & Qualifications
• Experience with RTOS environments such as FreeRTOS, Zephyr, or ThreadX.
• Knowledge of OTA firmware update security, including secure delivery, validation, and rollback mechanisms.
• Experience with Embedded Linux in the context of product and platform security.
• Experience in manufacturing provisioning and factory certificate injection processes.
• Familiarity with IEC compliance requirements related to industrial or embedded systems security.
• Familiarity with EN compliance standards relevant to product and cybersecurity.
• Understanding of wireless security, including Wi-Fi, BLE, and RF protocol security considerations.
• Advanced experience with Docker and containerized build environments for secure and scalable firmware pipelines.
• Experience administering Bitbucket or similar source control and CI/CD platforms with a security focus.
• Experience with security audit support and cybersecurity compliance evidence management.
• Strong interest in learning, innovation, and continuous improvement within embedded cybersecurity and DevSecOps.
• Ability to work effectively in a highly collaborative, cross-functional engineering environment.
Work Environment
This is a highly collaborative role that works closely with firmware, hardware, QA, product, manufacturing, and IoT teams within a global engineering organization. You will partner with another cybersecurity engineer and engage directly with engineering leadership, giving you significant visibility and influence over product security strategy and best practices. The position follows a hybrid work model, typically requiring 1–2 days per week onsite or one week per month onsite, offering flexibility while maintaining strong team interaction. The environment emphasizes learning, innovation, and continuous improvement, with opportunities to help build and mature the embedded cybersecurity function. You will operate at the intersection of embedded systems, cloud technologies, and cybersecurity, using modern CI/CD tooling, containerized build environments, and advanced PKI and key management solutions to secure next-generation connected products.
**If you are interested in this opportunity, please apply to this posting or reach out to Mathuushon at mthavabalan@actalentservices.com**
Job Type & Location
This is a Contract position based out of Scarborough, ON.
Pay and Benefits
The pay range for this position is $60.00 - $80.00/hr.
Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.
Workplace Type
This is a hybrid position in Scarborough,ON.
À propos d'Actalent
Actalent est un leader mondial dans les services d’ingénierie et de sciences ainsi que dans les solutions de talents. Nous aidons des entreprises visionnaires à faire progresser leurs initiatives d’ingénierie et de science grâce à l’accès
Required Skills
CI/CDPKIOTA
Prepare to Win This Role
Everything you need to ace the interview and negotiate top-of-band compensation.