RemoteAtlas
Find Jobs
CompaniesBlogPost a Job
RemoteAtlas

Discover curated remote jobs and work from anywhere. Updated daily with roles from top companies worldwide.

13,800+ live remote jobs

Follow us on:

Remote Jobs by Role

  • Remote Engineering Jobs
  • Remote Design Jobs
  • Remote Product Manager Jobs
  • Remote Marketing Jobs
  • Remote Sales Jobs
  • Remote Data Jobs
  • Remote DevOps Jobs
  • Remote Support Jobs
  • Remote Customer Success Jobs
  • Remote Cybersecurity Jobs
  • Remote Mobile Developer Jobs
  • Remote QA Jobs

More Roles

  • Remote HR & People Jobs
  • Remote Finance Jobs
  • Remote Operations Jobs
  • Remote Management Jobs
  • Remote AI & Machine Learning Jobs
  • Remote Writing & Content Jobs
  • Remote Video & Animation Jobs
  • Remote Translation & Localization Jobs
  • Remote IT Support Jobs
  • Remote Community Management Jobs
  • Remote Legal Jobs
  • Remote General Jobs

Remote Jobs by Location

  • Remote Jobs in the US
  • Remote Jobs in Europe
  • International Remote Jobs
  • Remote Jobs in the UK
  • Remote Jobs in the Americas
  • Remote Jobs in EMEA
  • Remote Jobs in APAC
  • Remote Jobs in Canada
  • Remote Jobs in Germany
  • Remote Jobs in India
  • Remote Jobs in Australia
  • Remote Jobs in Singapore
  • Remote Jobs in Brazil
  • Remote Jobs in the Netherlands

Company

  • Browse All Jobs
  • Digital Nomad Jobs
  • Blog
  • Companies
  • About Us
  • Post a Job
  • Contact Us

Remote Jobs by Skill

  • Remote Python Jobs
  • Remote TypeScript Jobs
  • Remote React Jobs
  • Remote Java Jobs
  • Remote Golang Jobs
  • Remote Ruby Jobs
  • Remote Rust Jobs
  • Remote Kotlin Jobs
  • Remote AWS Jobs
  • Remote Kubernetes Jobs
  • Remote Frontend Jobs
  • Remote Backend Jobs
  • Remote iOS Jobs
  • Remote Android Jobs
© 2026 RemoteAtlas. All rights reserved.
Terms & ConditionsPrivacy Policy
Home/Remote Management Jobs/Workleap/DevSecOps Lead
Workleap

DevSecOps Lead

Workleap

Canada - RemoteFull-timePosted 28 days ago
Management

Company Description

Workleap is a Montreal-based tech company, founded in 2006. We're builders at heart, we make simple products that actually matter to the people who use them. We have two product lines: The Workleap Agent, our agentic HR platform that helps managers become better leaders, and ShareGate, the world's leading solution for Microsoft 365 migration and governance. More than 15,000 companies worldwide trust us to do exactly that. We're intentional about who joins us. If you're the kind of person who gets excited by a hard problem and wants to help shape what comes next, there's a place for you here.

Job Description

So, what will your new role look like?

As a DevSecOps Lead, you will be an operational individual contributor responsible for embedding security directly into our products, pipelines, and development workflows — with a focus on CI/CD, C#/.NET applications, Azure, and AI-driven software delivery. This is a deeply technical role where you will write code, build tooling, and work closely with developers to ensure security is a natural part of how we build and ship software.

You will join the AI-SDLC team, which builds internal platforms and tooling that enable AI agents to operate across the development lifecycle. Your mission will be to ensure that security is integrated from the ground up across these tools, pipelines, and agentic workflows—enabling secure-by-default product development at scale.

Responsibilities

  • Ensure security is embedded into CI/CD pipelines by delivering scalable, automated tooling and integrated security checks (SAST, DAST, SCA, secret scanning);
  • Enable secure-by-default development by designing and implementing automated, policy-driven security review workflows;
  • Establish robust security guardrails within AI-assisted development and agent workflows to reduce risk while maintaining developer velocity;
  • Reduce risk exposure by proactively identifying, assessing, and driving remediation of application security vulnerabilities;
  • Strengthen application security posture by leading threat modeling and security assessments for new features and architectural changes;
  • Improve detection and response capabilities through the development of automation, tooling, and streamlined vulnerability management processes;
  • Elevate cloud and application security by partnering with Infrastructure SecOps to harden Azure environments and deployment practices;
  • Enhance external security feedback loops by contributing to and scaling the bug bounty program and vulnerability intake processes.

A typical week?   

  • Writing code for security tooling, CI/CD configurations, and automated review workflows;
  • Designing and refining policy-based security checks in pipelines;
  • Building and improving guardrails for AI-assisted development and agent workflows;
  • Participating in architecture and design discussions with engineering teams;
  • Collaborating with Infrastructure SecOps on shared security initiatives;
  • Triaging and prioritizing security alerts and vulnerabilities;
  • Sharing knowledge through pairing, code reviews, and informal coaching.

What does your future team look like?   

You will join the AI-SDLC team, responsible for building the internal platform that enables AI agents to operate across the Workleap and ShareGate development lifecycle. This includes developing agent pipelines, safety mechanisms, and developer-facing tooling.

You will work closely with Infrastructure SecOps and partner with multiple product teams across the organization. This is a highly collaborative environment where your impact comes from building scalable solutions and making secure development the default for everyone.

What are the next challenges awaiting your team?   

  • Scaling automated security practices across a growing portfolio of SaaS products;
  • Deepening security integration within GitHub Actions and CI/CD pipelines;
  • Ensuring security guardrails evolve alongside AI-assisted and agentic development workflows;
  • Strengthening secure-by-default practices and developer security awareness across teams.

Qualifications

  • 8+ years of experience in application security, DevSecOps, or security-focused software development;
  • Strong software engineering background combined with deep security expertise;
  • Deep understanding of web application security principles, OWASP Top 10, and CWE Top 25;
  • Hands-on experience performing secure code reviews in C#;
  • Experience building and maintaining security automation in CI/CD pipelines (GitHub Actions preferred);
  • Solid understanding of Azure cloud services, infrastructure security, and deployment patterns;
  • Experience integrating SAST, DAST, SCA, and secret scanning tools into development workflows;
  • Proficiency in scripting (Python, Bash) for automation and tooling;
  • Extensive hands-on experience with AI-assisted and agentic development workflows, with deep expertise in their security implications; recognized for major contributions in this space and driven by strong curiosity to push the boundaries of AI in the SDLC;
  • Familiarity with authentication protocols such as OIDC, SAML, and OAuth;
  • Ability to clearly communicate security risks and trade-offs to both technical and non-technical stakeholders.

 

Salary range: $150–200k CAD.
This range reflects our Canada-wide compensation scale. Final offers may be adjusted based on the candidate’s region to align with local market conditions.

Please note: this position is posted under the title DevSecOps Lead but carries the official title of Application Security Manager within the organization.

What drives us

At Workleap, we build software that sits at the center of how people experience work, every day, at every level.

We move fast. Priorities shift, decisions get made with the information we have, and we iterate. If you thrive on intensity and ambiguity doesn't slow you down, you'll feel right at home.
We're builders. We do what it takes to move forward. AI is part of our toolkit. We use it to go faster and decide smarter, not to replace judgment.

If you want real impact and a place where your decisions matter, this is it.

How we hire 

Transparency is how we hire — for you and for us.

Your journey starts with a recruiter conversation, followed by a virtual interview with the hiring manager and one additional interviewer. Next, you'll complete a take-home case study and meet potential teammates to discuss and collaborate on your work. If it's a match on both sides, we move to an offer. Some positions follow a slightly different path — your recruiter will walk you through it on the call if that's the case.

In the spirit of transparency: we use AI to support parts of the process, but every hiring decision remains firmly human.

We're committed to making this an inclusive and thoughtful experience for every candidate. We're looking forward to showing you that.

By applying, you confirm you've read and agree to our privacy policy.

#LI-Remote

Want to see the full job details?

Create a free account to view complete descriptions, save jobs, and apply instantly.

Related jobs

Talentful
G&A Recruitment Manager (6-month FTC) New

Talentful·Remote — Australia

Full-timeManagement
15h
Talentful
Technical Recruitment Manager (6-month FTC) New

Talentful·Remote — Australia

Full-timeManagement
15h
W
Account Manager, Supply Chain ESG

Worldly·United States - Remote

Full-time$77K - $110KCustomer SuccessManagement
16d
Centre for Effective Altruism
Head of the EA Infrastructure Fund

Centre for Effective Altruism·Worldwide - Remote

Full-time$157.4k+Management
2mo
Summation
Solution LeadNew

Summation·United States - Remote

Full-time$170K - $200KManagement
16h
More remote management jobsMore remote jobs in the Canada