nesto
Posted 6mo ago

Cloud Security Developer

nesto
Canada
RemoteFull Time
Responsibilities
  • implementing controls
  • remediating issues
  • automating deployments
Requirements
  • Requires 5+ years in infrastructure or security and 5+ years of development experience
  • With cloud security
  • Kubernetes
  • DevSecOps, IaC, GCP, Azure, and English/French proficiency
Technical tools mentioned
GoLangTypeScriptJavaScriptOWASP Top 10DASTSASTTenableSnykGitHub ActionsArgo CDAzure DevOpsWAFIDS/IPSKubernetesGCPSecurity Command CenterGKECloud IDSCloud ArmorSecrets ManagerAzureSecurity CenterAzure PaaS App ServicesVMsAzure SQLFront DoorKey VaultTerraformPulumiHelmCISNISTMITRE ATT&CKIAM

Job description


Our mission is to provide a positive, empowering, and transparent property financing experience that is simple from start to finish. Our team consists of skilled technology experts, caring mortgage specialists, and a diverse marketing team, all working together to lead change in the mortgage industry.


At nesto, we're proud of 

  • Our clients love our positive, empowering, and transparent mortgage financing experience.
  • Our 4.5-star Google reviews speak for themselves!
  • We won the 2023 & 2024 CLA Lender of the Year award, recognizing our excellence in lending services.
  • We are a B Corp certified organization, highlighting our dedication to making a positive impact on our society and our planet.
  • Our highly skilled, diverse, and collaborative team, makes everything possible!
  • Our Mortgage Cloud platform gives financial institutions full access to nesto’s proprietary technology, powering a better client experience, from start to finish.

About the team

We're a fast-paced, interdisciplinary team working on multiple tech projects simultaneously. Our team is diverse and works on different products and nesto experiences that are all interconnected. 


We are looking for a Cloud Security Developer to join our dynamic team. In this role, you will play a critical role in designing, implementing, and maintaining cloud security solutions to protect our cloud-based systems and applications. You will work closely with our development and operations teams to ensure the security and integrity of our cloud infrastructure.


We celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.


What you'll be doing

  • Implement and maintain robust security controls to protect our cloud infrastructure and applications.
  • Discover, remediate, and validate security issues across cloud infrastructure.
  • Perform architectural/design reviews through a security lens and provide timely, actionable requirements and recommendations.
  • Collaborate with security leadership, compliance, and engineering teams to execute security strategies.
  • Build, deploy, and manage security tools such as WAF, IDS/IPS, workload protection, GCP Command Center, and Azure Security Center, etc.
  • Propose and contribute to security and compliance improvements for nesto CI/CD pipelines and deployment processes.
  • Automate infrastructure provisioning and deployment processes using Infrastructure as Code (IaC) tools like Terraform or Pulumi.
  • Design and operate scalable processes to provision cloud access and maintain least privilege.
  • Participate in and support the incident detection and response process by enhancing observability and alerting and assisting the incident response team.
  • Self-organize and prioritize activities independently.
  • Support audits and first-party security questionnaires.
  • Conduct and oversee security assessments and threat modeling exercises.
  • Implement security controls within Kubernetes.
  • Build DevSecOps tools/integrations.

Who we're looking for

  • 5+ years of experience working on a team focused on infrastructure and/or security.
  • 5+ years of development experience (ideally GoLang, TypeScript/JS).
  • Knowledge of common web application vulnerabilities and the OWASP Top 10 framework.
  • The ability to analyze and act on results from DAST and SAST tools (e.g., Tenable, Snyk).
  • Skilled in DevSecOps principles and familiarity with CI/CD pipelines (GitHub Actions, Argo CD, Azure DevOps) to perform automated security testing.
  • Experience deploying and customizing security tools to address threats and lower risk, including vulnerability scanners, static analyzers, web application firewalls (WAFs), intrusion detection/prevention systems (IDS/IPS), and endpoint security monitoring.
  • A comprehensive grasp of cloud and network security, including an in-depth understanding of Kubernetes.
  • Experience in GCP specifically with one or more of the following services: Security Command Center, GKE, Cloud IDS, Cloud Armor, and Secrets Manager.
  • Experience in Azure specifically with one or more of the following services: Security Center, Azure PaaS App Services, VMs, Azure SQL, Front Door, and Key Vault.
  • Experience writing infrastructure-as-code using tooling such as Terraform, Pulumi, and Helm.
  • Knowledge of common security-related frameworks and benchmarks like CIS, NIST, and MITRE ATT&CK.
  • An understanding of identity and access management (IAM) principles and cloud-native IAM solutions.
  • Passionate about constant learning and sharing knowledge with others.
  • Bilingual (English & French).

We definitely want to talk to you if you have/are

  • Experience managing security posture by collating, digesting, and monitoring outputs from tooling.
  • Experience working with infrastructure-as-code using tooling such as Terraform, Pulumi, and Helm.
  • Skilled in DevSecOps principles and familiar with CI/CD (Github Action and Argo CD) pipelines to perform automated security testing

The Reward

  • The A-Team: Work alongside high-performing talent in the industry.
  • Accelerated Growth: The slope of your learning curve here will be vertical. You will touch more production systems in one year than you would in five years at a bank.
  • Top-Tier Coverage: Premium benefits plan fully paid by nesto, including comprehensive insurance and unlimited access to telemedicine and mental health services for you and your family.
  • Rest & Recharge: 4 weeks of vacation to ensure you stay at peak performance.
  • Best-in-Class Tools: Access to the resources and tech you need to execute without friction.
  • Working framework: The environment that makes you productive and enables teamwork (Hybrid model).

Diversity and Inclusion

At nesto, we believe that creativity and collaboration are the result of a diverse team. We are committed to fostering a culture of diversity, equity, inclusion, and belonging, and we strongly encourage women, people of color, LGBTQIA+ individuals, and individuals with disabilities to apply. We are committed to creating a workplace that is inclusive and welcoming to all.


#nestocloud

About nesto

Providing digital mortgage lending and B2B mortgage technology solutions.

Year founded
2018
Employees
1200
Organization type
Private
Latest investment
Raised $58.50M Series C (2022) — led by IGM Financial, BMO Capital Partners, NAventures
Headquarters
CA

Similar jobs

Cloud Security Developer roles
6d
Save
Mark Applied
Hide
Federal Cloud Security Engineer (11342)
United States or Canada or Australia or Sri Lanka or Europe
RemoteFull Time
InEight
InEight: Integrated construction project management software for capital projects.
5+ YOERequires 5+ years in IT, cybersecurity, cloud security, or infrastructure engineering; Azure administration and security experience; vulnerability management, monitoring, incident response, and compliance experience.
Tenable, Microsoft Sentinel, Microsoft Defender, Microsoft Azure, Azure Government, NIST 800-53, FedRAMP, IRAP, ISO 27001
2w
Save
Mark Applied
Hide
Senior Cloud Security Engineer - InfoSec
San Francisco or New York or Portland or United States or Canada
$167k-$208k/yr RemoteFull Time
Mercury
Mercury: Banking services and financial software designed for startup companies.
5+ YOE5+ years cloud security experience; familiarity with security frameworks, GRC, IaC, AWS; strong analytical and problem-solving skills; AWS certifications encouraged.
AWS
3w
Save
Mark Applied
Hide
Head of Cloud Security Engineering
Quincy or Toronto or Austin or Atlanta
$120k-$218k/yr OnsiteFull Time
State Street
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
10+ YOE3+ MgmtDeep multi-cloud security experience, 10+ years in SRE/cloud security engineering, 3+ years leading SRE/DevSecOps/cloud security teams, AWS/Azure expertise, Kubernetes experience, familiarity with NIST 800-53/CMM and MITRE, cloud posture tooling experience.
AWS, Azure, Containers, Kubernetes, OCI, Wiz, Prisma, NIST 800-53, CMM, MITRE
3w
Save
Mark Applied
Hide
Senior Cloud Security Engineer ( Global Security)
Toronto or Vancouver
OnsiteFull Time
Royal Bank of Canada
Royal Bank of CanadaTSX: RY: Provides personal, commercial, and investment banking services worldwide.
5+ years cloud engineering experience building AWS security controls; proficiency with AWS security services, Python, IaC (Terraform/CFN/CDK), containerization, CI/CD, and DevOps/SRE practices.
AWS GuardDuty, IAM, Security Hub, Control Tower, Lambda, API Gateway, EventBridge, DynamoDB, OPA Gatekeeper, Python, Terraform, CFN, CDK, Docker, Kubernetes, ECS, GitHub Actions, Jenkins, AWS Code Pipeline, Wiz, AI Agents
4w
Save
Mark Applied
Hide
Senior Staff Cloud Security Engineer – Financial Services - Office of the CISO
Toronto, Ontario, Canada
RemoteFull Time
ServiceNow
ServiceNowNYSE: NOW: Provides a cloud platform for automating enterprise digital workflows.
12+ YOE12+ years IT experience with 5+ years in cloud security, expertise in cloud operations and enterprise cyber defense, excellent communication and presentation skills, eligible for Canadian Reliability Status.
4w
Save
Mark Applied
Hide
Senior Staff Cloud Security Engineer – Financial Services - Office of the CISO
Toronto, Ontario, Canada
RemoteFull Time
ServiceNow
ServiceNowNYSE: NOW: Enterprise cloud platform for digital workflow automation.
12+ YOERequires 12 years in IT, 5 years in cloud security, cloud operations experience, Canadian Reliability Status eligibility, AI security expertise, cyber defense knowledge, strong communication, and customer-facing presentation skills.
Agentic AI, GenAI, ITIL, ITSM
4w
Save
Mark Applied
Hide
Verafin - Senior Cloud Security Developer
St. John's or Toronto
$86k-$118k/yr HybridFull Time
Nasdaq
NasdaqNASDAQ: NDAQ: Operates global electronic marketplaces and provides financial technology services.
3+ YOEBachelor's or equivalent,3+ years cloud experience,proven AWS multi-account security design,Terraform and Python (boto3) experience,DevSecOps and strong communication skills.
Prisma Cloud, Cortex XSOAR, AWS, Terraform, Python, boto3, Java, Jenkins, Linux, Bash, SIEM
1mo
Save
Mark Applied
Hide
Senior Cloud Security Engineer
Toronto or Austin or Addison or Phoenix or Kanata
HybridFull Time
Semperis
Semperis: Secures and recovers enterprise identity systems from cyber threats.
6+ YOE6+ years in cloud/security engineering; hands-on Azure or AWS experience; Kubernetes (AKS/EKS) security; cloud network and CSPM experience; IaC automation (Terraform/Bicep/CloudFormation); scripting and strong communication.
Azure, AWS, AKS, EKS, Kubernetes, CSPM, Terraform, Bicep, CloudFormation, Python, PowerShell, Bash, CI/CD, RBAC, Application Gateway, WAF, FinOps, DevSecOps, FedRAMP, SOC 2, ISO 27001, NIST