About this role
About AlayaCare
At AlayaCare, we’re more than just a fast-growing SaaS company, we’re a team of people passionate about transforming home healthcare. Our cloud-based platform empowers care providers around the world to deliver better outcomes for their clients.
With 550+ employees across Canada, the US, Australia, and Brazil, we’re united by a shared mission and a strong culture of transparency, growth, and human connection. Whether you're early in your career or a seasoned expert, AlayaCare offers the opportunity to grow your impact, your skills, and your career.
About the Role
We are seeking a Staff DevSecOps Specialist to join our Security team. Reporting to the Director, Information Security and Privacy, The Staff DevSecOps Specialist is a senior individual-contributor role driving the technical direction of AlayaCare’s security vaning practice. It is a builder's role at the level where the thing being built is not only tooling but the technical standards and architecture other engineers design against, from our cloud and platform controls to the review practices those designs pass through and the automation that lets a small team protect a large surface.
As a member of AlayaCare's Information Security & Privacy team, you will drive the technical direction of how security is engineered across Site Reliability Engineering, Developer Experience, and platform teams, and carry it through in code. You will own the architecture and operation of our edge security on Cloudflare, lead the Wiz cloud security program across our AWS and Kubernetes estate, define how security is enforced in CI/CD alongside DevX, build the security tooling and detections the rest of the organization runs on, and secure the agents and agentic pipelines our developers are shipping.
You will lead through design, code, and influence rather than through reporting lines: the technical direction you shape is the direction you build. It is a rare scope for an individual contributor, spanning healthcare data, SOC 2, HIPAA, and Canadian privacy obligations across a platform where one engineer's work is visible everywhere.
What You’ll Do
- Contribute to defining the multi-year technical roadmap for security engineering at AlayaCare, and personally build its most difficult components: the security tooling, services, and automation the organization depends on, and the engineering standards and review practices for security-owned code.
- Own the architecture and operation of Cloudflare edge security: WAF rule strategy, custom rules, rate limiting, bot management, and DDoS posture, tuned against real production traffic with SRE and product teams.
- Own cloud and container security architecture with SRE, and the Wiz program that verifies it: AWS identity boundaries, network segmentation, secrets management and encryption patterns; Kubernetes cluster hardening, admission control, image supply chain and runtime posture; and prioritized remediation and posture metrics across AWS accounts.
- Establish preventive guardrails in code: policy-as-code in Terraform and CI so entire classes of misconfiguration become impossible rather than detected, and, with Developer Experience, CI/CD security testing (SAST, SCA, secrets, container scanning) enforced at a signal-to-noise bar developers accept.
- Own the vulnerability management program as a system: intake across all sources, exploitability-based prioritization, SLAs, automation of the toil, and reporting to engineering and executive stakeholders.
- Lead detection engineering in support of the SOC, including detection-as-code practices and log source onboarding, and serve as senior technical lead during security incidents affecting cloud and application infrastructure, owning the engineering follow-through that prevents recurrence.
- Lead threat modelling and security design reviews for major architectural changes, and serve as the technical escalation point within security engineering for complex design and implementation decisions.
- Secure how AlayaCare builds with AI: threat model the agents, agentic workflows, and pipelines our developers ship; set guardrails for tool use, non-human identity, secrets, and data access; and define the review standards those systems are designed against.
- Build the technical control automation that makes SOC 2, HIPAA, and customer assurance continuous, partnering with GRC so evidence is a by-product of how systems run.
- Mentor and level up engineers inside and outside the security team, growing the practice beyond what one person can operate, and represent our security engineering approach to customers and auditors when technical depth is required.
What You Bring to the Team
- Bachelor’s or advanced degree in Computer Science, Cybersecurity, Software Engineering, Computer Engineering, Information Technology, or a related technical field.
- Extensive hands-on experience in DevSecOps, cloud security engineering, or platform and SRE work with deep security ownership, at staff or principal level of technical scope, with a track record of setting technical direction and delivering it rather than advising on it.
- Deep expertise securing AWS at scale: IAM, VPC networking, KMS, organizational controls, and the trade-offs between them.
- Deep command of container and Kubernetes security, evidenced by production clusters you have hardened and kept hardened as they grew.
- Production experience owning a WAF and edge security platform, ideally Cloudflare, including rule strategy and managing false positives on live customer traffic.
- Strong software engineering ability in Python, Go, or a comparable language, with production systems other teams rely on and the judgment to set the quality bar for them.
- Deep hands-on Terraform experience, including module design and review at scale, and policy-as-code approaches to preventive controls.
- Experience designing CI/CD security enforcement that developers adopt rather than route around.
- Strong application security fundamentals: OWASP Top 10, secure design, threat modelling, and secure code review at architectural depth.
- Detection engineering experience with a modern SIEM (Panther, Splunk, or similar) and experience leading incident response in cloud environments.
- Fluency working AI-natively: builds agents and agentic automation as a matter of course in their own engineering, with clear judgment about how these systems fail and what that means for security.
- Ability to reason about real risk rather than scanner severity, and to defend that reasoning to engineers, executives, and auditors.
- Demonstrated ability to lead and influence across an engineering organization without direct authority, and to mentor senior engineers.
- Experience in healthcare, home health, or medical devices is an asset.
- Bilingual in French and English
Why Join AlayaCare?
Work With Purpose
At AlayaCare, you’ll help build technology that empowers care providers and improves outcomes for patients and families. Every line of code and every customer interaction contributes to making care more connected, accessible, and human.
Grow in a High-Trust Culture
We believe in transparency, feedback, and assuming positive intent. Here, you’ll feel safe to share your ideas and career goals, and be supported to achieve them through mentorship, career mobility, and a promote-from-within philosophy.
Balance That Works for You
We value flexibility and well-being. From “Wellness Fridays” to volunteer time off, to flexible vacation, we make sure you have the space to recharge, contribute to your community, and live your best life.
Benefits That Matter
- Equity in a well-funded, scaling company.
- Comprehensive health benefits, telemedicine, and lifestyle spending accounts.
- Parental leave top-up and family support programs.
Inclusive by Design
We celebrate diverse perspectives and foster belonging through our DEIB initiatives. Employee-led events, summits, and social activities, both in-person and virtual, create meaningful connections across our global teams.
Location and Work Model
This role is based in Montreal. At AlayaCare, our hybrid model includes 2 set in-office collaboration days/week, and it is expected that team members are present in the office on those days to foster connection, innovation, and teamwork.
Ready to Join Us?
Apply today and be part of a company that makes a real difference in the future of home and community care. Not the right role for you? Share this posting with someone who might be a great fit.
AlayaCare uses AI tools during our hiring process to support fair, consistent, and objective decision-making. Some initial screening steps may be automated to help identify qualified candidates. If your application is declined automatically, you may request a human review.
We’re committed to creating a workplace where everyone belongs. If you require accommodation during the application process, please reach out to [email protected] .
