Senior DevSecOps Engineer

3 days ago

Ottawa, Ontario, Canada ComPsych Corporation Full-time

About ComPsych

ComPsych is the worldwide leader in organizational mental health, well-being, and absence management, dedicated to igniting human potential in workplaces across the globe. For over 40 years, we have combined the best in technology with unmatched human expertise to help individuals and their organizations thrive. Our GuidanceResources and AbsenceResources solutions deliver end-to-end mental health, well-being, work-life, health navigation, and absence support to more than 75,000 customers worldwide, touching more than 160 million lives across 200 countries. Visit compsych.com to find out why 40% of the Fortune 500 choose ComPsych for their mental health and absence management needs.

About the Role

We're modernizing how ComPsych builds and ships applications — moving to the cloud, standardizing CI/CD, and giving our Software Engineering teams the ability to build, deploy, and own their products end to end. You'll be part of our CloudSecOps team, working alongside your peers there and across multiple application teams to bring consistent, high-quality CI/CD, infrastructure, and deployment practices to the products we ship.

We're looking for a Senior DevSecOps Engineer who already works this way and wants to help shape how our engineering organization delivers software. This is a high-leverage role: your time goes toward infrastructure design and technical direction across the teams you support, directing AI to build pipelines and automation and validating what it produces before it ships.

What You'll Do

AI changes what your time goes toward. You're still accountable for the full delivery lifecycle across the application teams you support — design, pipelines, security, and production — but your hands‐on role in each shifts.

  • Own CI/CD and infrastructure design across the teams you support. Architecture, deployment strategy (blue/green, canary, feature flags), and the specs that direct AI-built pipelines, infrastructure code, and automation — coding yourself when it counts.
  • Decide what needs verification and prove it does the job. Pipeline tests, policy-as-code, and security gates are a design decision, not a default — you validate that they actually prove what they claim.
  • Build shared standards with the rest of CloudSecOps, not one-off fixes per team. Work with your CloudSecOps peers on the common patterns, tooling, and practices that make every team you support faster and safer, and contribute your own experience back into what the group builds.
  • Own application observability and unblock teams in production. Instrument the services you support, tie alerting to product SLOs, and help engineers across teams debug and resolve issues quickly when something breaks.
  • Keep judgment and accountability human. Reviews, deployment calls, on‐call response, and what an incident teaches you stay yours, regardless of who or what wrote the code.
  • Raise the bar for how the teams you support work with AI, coaching engineers on specifying, delegating, and validating rather than treating DevOps as someone else's problem.

What We're Looking For

  • You already work this way. Agentic AI is your primary surface for planning and building CI/CD and infrastructure — you write specs it can execute against and catch what it gets subtly wrong, not just what fails a test.
  • You've built and operated production CI/CD and cloud infrastructure at real scale (AWS or Azure), including carrying on‐call load, so you know what good looks like independent of who, or what, writes the code.
  • You treat testing, security, and observability as designed‐in requirements, not something a separate function catches later. In a system that carries behavioral health data, "it works" and "it's safe" are the same bar.
  • You work effectively across multiple application teams and with your CloudSecOps peers, building practices that generalize rather than solving the same problem differently each time — judgment AI doesn't replace.
  • You have hands‐on depth building application CI/CD and deployment automation: containers and Kubernetes for application workloads (Helm or similar), serverless functions, and one or more IaC tools (Terraform, CloudFormation, or ARM) used in production, plus fluency in at least one modern language (for example, Python or Java).
  • You build security in, shift-left by default. SAST/DAST/SCA and secrets scanning in the pipeline, least‐privilege IAM, and encryption in transit and at rest are the norm, built within the compliance frameworks we operate under, including HIPAA/HITRUST and SOC 2.

Pay