DevSecOps Engineer
About Maxima
Nobody went into accounting to spend the first week of every month matching transactions by hand. Maxima was built so they don't have to. Our agents do the accounting work itself: journal entries, transaction matching, reconciliations, and flux analysis, continuously and with a full audit trail. Accountants review and approve. Nothing posts without a person signing off. We remove the grind, not the human.
Maxima is the agentic AI platform for enterprise accounting. Our three co-founders scaled finance at Rubrik from $5M ARR to a $15B NYSE IPO, built the reconciliation and billing systems behind Netflix's $32B in annual revenue, and built AI infrastructure serving two billion monthly users at Meta. We've raised $41M from Redpoint Ventures, Kleiner Perkins and Audacious Ventures, joined by former BlackLine executives and the CFOs of Rubrik and Vanta. To date we've processed more than $400B across 350M transactions at 100.00% accuracy, for customers including Scale AI, Rippling, Glean, Zendesk, Handshake, Zip, and Decagon.
We're early and moving fast. The playbook here gets written, not inherited, and the person closest to the work makes the call. We're looking for people who build from first principles and hold themselves accountable for what actually lands — people who'd rather build the category than join it. Everything you need to know is below.
The role
We are working on some of the hardest problems in enterprise automation, with an engineering team that includes staff-level talent from Robinhood, Glean, Google, Netflix, and Meta. The system handles high-volume financial data and complex accounting workflows, and every execution has to be accurate and reliable, because the output is a company's books.
You will own security across Maxima's software development lifecycle: CI/CD pipelines, cloud infrastructure on GCP, container and artifact hardening, secrets and key management, and the controls behind our SOC 1, SOC 2, and ISO 42001 compliance. Customers trust Maxima with their general ledger, and their auditors ask how we protect it. Your work is a large part of the answer.
It is a hands-on role in a full-stack environment, with a shift-left approach to security and a share of developer infrastructure work.
What you'll do
Implement and manage DevSecOps practices across the SDLC with a shift-left approach to security
Design and harden CI/CD pipelines such as GitHub Actions, with minimal permissions and OIDC with Workload Identity Federation for cloud deployments
Integrate and enforce SAST, dependency scanning, and secret scanning (for example Trufflehog or GitGuardian) so builds fail on high-severity issues
Secure GCP infrastructure with least-privilege IAM, VPC firewall rules, and Google Secret Manager, and manage encryption and key rotation with Cloud KMS
Harden containers and artifacts: multi-stage builds, image vulnerability scanning, and artifact signing with tools such as Cosign
Keep application code to secure coding practices, including input validation, output encoding, and secure authentication and session management through our Descope integration
Monitor CI/CD pipelines and production (GCP and Datadog) for anomalies, security events, and audit logs
Maintain the documentation and controls for SOC 2, SOC 1, and ISO 42001
Help with developer infrastructure, including deployment automation and internal tooling
What we're looking for
4 or more years in DevSecOps, security engineering, or a related role focused on CI/CD pipeline security
Bachelor's degree in any engineering discipline; computer science preferred but not required
Experience securing cloud environments, preferably GCP, including IAM, Secret Manager, VPC controls, and Cloud KMS
Hands-on experience hardening CI/CD systems such as GitHub Actions or Blacksmith
Proficiency in application security practices (SAST, DAST, secret scanning) and a deep understanding of common anti-patterns such as hard-coded secrets and insufficient input validation
Proficiency in Go, TypeScript, Python, or similar languages for automation and development
Comfort with Kubernetes and other container orchestration platforms
Familiarity with SOC 2, PCI DSS, or ISO 42001, and experience producing evidence for auditors
Strong verbal and written communication skills, and the ability to handle the pace of a startup
Where and how you'll work
This role is based in our downtown Toronto office, near Union Station. We value in-person collaboration and are in office four to five days a week for our on-site roles.
Why join Maxima
The work. Agentic accounting is a category being defined right now, and Maxima is one of the companies defining it. The product does the accounting work itself, so what you build, sell, or deploy shows up in a customer's books
The people. Founders who ran the finance org at Rubrik and built the close systems at Twitter and Netflix. Engineers from Robinhood, Glean, Google, Netflix, and Meta. Controllers and accountants on the team who have closed books themselves. Small teams in San Mateo and Toronto that work in the same room, say what they think, and hold a high bar
The benefits. Competitive salary, 401(k) for US employees, unlimited PTO, lunch in the office, and commuter benefits
The process. A person reads every application, and we tell you where you stand at every stage
A note on AI
We build AI and we expect you to use it. Use it to research us and to prepare. In live conversations we want your own thinking in your own words, and if you use AI on a take-home exercise, tell us where it helped.
Equal opportunity
Maxima is an equal opportunity employer. We do not discriminate on the basis of race, color, ethnicity, ancestry, national origin, religion, sex, gender, gender identity, gender expression, sexual orientation, age, disability, veteran status, genetic information, marital status, or any other legally protected status. If you need an accommodation at any point in the process, tell us and we will arrange it.