DevSecOps Engineer
Software Engineering · Full-time
Toronto, ON, Canada
About Maxima
Nobody went into accounting to spend the first week of every month matching transactions by hand. Maxima was built so they don't have to. Our agents do the accounting work itself: journal entries, transaction matching, reconciliations, and flux analysis, in real time and to SOX standards. Accountants review and approve. Nothing posts without a person signing off. We remove the grind, not the human.
Maxima is the first agentic AI platform for enterprise accounting. Our founders oversaw the finance org at Rubrik and built the month-end close systems at Twitter and Netflix. We've raised $41M from Redpoint Ventures, Kleiner Perkins, and Audacious Ventures, and we're backed by finance leaders at OpenAI, Rubrik, and Vanta. Maxima runs in production at Scale AI, Rippling, Glean, and SpotOn.
We are early, we are growing fast, and we are hiring people who would rather build the category than join it. Here is one way to do that.
The role
We are working on some of the hardest problems in enterprise automation, with an engineering team that includes staff-level talent from Robinhood, Glean, Google, Netflix, and Meta. The system handles high-volume financial data and complex accounting workflows, and every execution has to be accurate and reliable, because the output is a company's books.
You will own security across Maxima's software development lifecycle: CI/CD pipelines, cloud infrastructure on GCP, container and artifact hardening, secrets and key management, and the controls behind our SOC 1, SOC 2, and ISO 42001 compliance. Customers trust Maxima with their general ledger, and their auditors ask how we protect it. Your work is a large part of the answer.
It is a hands-on role in a full-stack environment, with a shift-left approach to security and a share of developer infrastructure work.
What you'll do
Implement and manage DevSecOps practices across the SDLC with a shift-left approach to security
Design and harden CI/CD pipelines such as GitHub Actions, with minimal permissions and OIDC with Workload Identity Federation for cloud deployments
Integrate and enforce SAST, dependency scanning, and secret scanning (for example Trufflehog or GitGuardian) so builds fail on high-severity issues
Secure GCP infrastructure with least-privilege IAM, VPC firewall rules, and Google Secret Manager, and manage encryption and key rotation with Cloud KMS
Harden containers and artifacts: multi-stage builds, image vulnerability scanning, and artifact signing with tools such as Cosign
Keep application code to secure coding practices, including input validation, output encoding, and secure authentication and session management through our Descope integration
Monitor CI/CD pipelines and production (GCP and Datadog) for anomalies, security events, and audit logs
Maintain the documentation and controls for SOC 2, SOC 1, and ISO 42001
Help with developer infrastructure, including deployment automation and internal tooling
What we're looking for
4 or more years in DevSecOps, security engineering, or a related role focused on CI/CD pipeline security
Bachelor's degree in any engineering discipline; computer science preferred but not required
Experience securing cloud environments, preferably GCP, including IAM, Secret Manager, VPC controls, and Cloud KMS
Hands-on experience hardening CI/CD systems such as GitHub Actions or Blacksmith
Proficiency in application security practices (SAST, DAST, secret scanning) and a deep understanding of common anti-patterns such as hard-coded secrets and insufficient input validation
Proficiency in Go, TypeScript, Python, or similar languages for automation and development
Comfort with Kubernetes and other container orchestration platforms
Familiarity with SOC 2, PCI DSS, or ISO 42001, and experience producing evidence for auditors
Strong verbal and written communication skills, and the ability to handle the pace of a startup
Where and how you'll work
This role is based in our downtown Toronto office, near Union Station. We value in-person collaboration and are in office four to five days a week for our on-site roles.
Why join Maxima
The work. Agentic accounting is a category being defined right now, and Maxima is one of the companies defining it. The product does the accounting work itself, so what you build, sell, or deploy shows up in a customer's books
The people. Founders who ran the finance org at Rubrik and built the close systems at Twitter and Netflix. Engineers from Robinhood, Glean, Google, Netflix, and Meta. Controllers and accountants on the team who have closed books themselves. Small teams in San Mateo and Toronto that work in the same room, say what they think, and hold a high bar
The benefits. Competitive salary, 401(k) for US employees, unlimited PTO, lunch in the office, and commuter benefits
The process. A person reads every application, and we tell you where you stand at every stage
A note on AI
We build AI and we expect you to use it. Use it to research us and to prepare. In live conversations we want your own thinking in your own words, and if you use AI on a take-home exercise, tell us where it helped.
Equal opportunity
Maxima is an equal opportunity employer. We do not discriminate on the basis of race, color, ethnicity, ancestry, national origin, religion, sex, gender, gender identity, gender expression, sexual orientation, age, disability, veteran status, genetic information, marital status, or any other legally protected status. If you need an accommodation at any point in the process, tell us and we will arrange it.