Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada
$120k - $150kShift Technology
Job Description
Job Description
Shift delivers AI agents that transform insurers' most critical work. By combining deep industry expertise and unmatched data resources, Shift provides proven results that have earned the trust of hundreds of the world's leading insurers. Our insurance-grade AI is accurate, explainable, and secure—empowering human experts to move with unmatched speed, total confidence, and a renewed focus on the people they serve.
Your browser does not support the video tag.
Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.
Learn more at
As an Application Security/DevSecOps Engineer, you will drive application security and DevSecOps practices across Shift's software delivery pipeline, from the first line of code through the CI/CD pipeline, working closely with data scientists, software delivery teams, and engineers to ensure security is built in by design. You will also serve as a first responder within Shift's Security Operations function, monitoring, triaging, investigating, and responding to security alerts and incidents across our environment. Working closely with engineering, infrastructure, and helpdesk teams, you will help ensure applications are secure by design and that threats are identified, contained, and remediated efficiently while following established processes and procedures.
RESPONSIBILITIESSecure by Design (Shift Left)
- Working with data scientists, software delivery teams, and engineers to ensure technical security standards are well understood and best practices are followed.
- Driving Application Security through defining technical policies, standards, and guidelines and championing these throughout the organisation.
- Identification of systemic and cultural developer security issues, and remediation opportunities.
- Promote a mind-set of developing secure systems, transferring knowledge of security standards/processes, and acting as a subject matter expert (SME).
- Leading and facilitating threat modeling exercises.
Secure the Build & Deploy Pipeline (DevSecOps/AppSec)
- Automation of security testing (SAST, DAST, SCA, vulnerability management).
- Ensuring full benefits realisation of relevant tooling.
- Ensure maximum code and infrastructure coverage.
- Ensure code and artifact integrity through automated signing and attestation processes within the CI/CD pipeline.
- Establish guardrails and governance for AI-assisted development, ensuring AI-generated code is rigorously vetted for security vulnerabilities and adheres to internal coding standards.
- Ensure company-wide best practices for Secret Management, IaC Security, and SBOM.
- Security auditing of software developed by the company and its partners.
- Operate a software vulnerability management program, taking responsibility for the identification, production, and improvement of meaningful metrics, and reporting on progress.
- Prioritise and manage the remediation of code defects.
Security Monitoring & Incident Response (SecOps)
- Monitor and triage security alerts generated from Microsoft Sentinel, EDR platforms, cloud security tools, and other security technologies.
- Investigate suspicious activity and determine the severity, scope, and potential impact of security events.
- Validate alerts, differentiate false positives from actionable incidents, and escalate to relevant teams - following established processes - when additional investigation or response is required.
- Serve as a first responder for security incidents and operational security events, executing response procedures and containment actions in accordance with established playbooks and guidance.
- Gather relevant evidence, coordinate with internal stakeholders, and ensure timely remediation of identified issues.
- Maintain accurate records of investigations and actions taken, and participate in post-incident reviews and documentation activities.
Collaboration & Professional Development
- Communicate investigation results clearly and concisely to technical and non-technical stakeholders.
- Work closely with engineering and infrastructure teams to support remediation efforts.
- Participate in internal purple team exercises and security initiatives.
- Maintain a disciplined, process-driven approach to incident handling and operational responsibilities.
- Continuously develop technical and security knowledge through training, collaboration, and hands-on experience.
Experience & Education
- Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience.
- 7+ years of experience in Security Operations, Incident Response, Cybersecurity Monitoring, or a similar security role.
Technical Skills
- Experience working with a SIEM platform, preferably Microsoft Sentinel.
- Experience with at least one Endpoint Detection and Response (EDR) platform such as Microsoft Defender for Endpoint, CrowdStrike, Cortex XDR, or similar.
- Experience with application vulnerability management tools such as GitHub Advanced Security, Tenable, or similar.
- Knowledge of API, web application, and software supply chain security (SBOM)
- Familiarity with major language frameworks such as C#, Java, React, or Python.
- Awareness of security considerations for AI/ML integrations, such as risks like prompt injection
- Familiarity with SaaS application security concepts, such as tenant isolation and secure API design.
- Familiarity with Microsoft Azure environments and development platforms such as GitHub and GitHub Actions.
- Understanding of networking fundamentals and network security concepts.
- Proficiency in at least one scripting or programming language such as Python, PowerShell, JavaScript, or Go.
- Familiarity with KQL or similar query languages is preferred.
Knowledge & Frameworks
- Understanding of common cybersecurity threats, attack techniques, and defensive controls.
- Familiarity with the MITRE ATT&CK framework.
- Basic understanding of cloud security, identity security, endpoint security, and vulnerability management concepts.
- Awareness of common security and compliance frameworks such as ISO 27001, NIST CSF, SOC 2, HIPAA, or GDPR.
Core Competencies
- Strong analytical and investigative mindset.
- Excellent written and verbal communication skills.
- Ability to communicate technical findings clearly, accurately, and concisely.
- Strong organizational skills and attention to detail.
- Disciplined, process-oriented approach to operational work.
- Ability to prioritize effectively and manage multiple investigations simultaneously.
- Collaborative team player with a strong desire to learn and grow within cybersecurity.
- Ability to remain calm and methodical during security incidents.
RECRUITMENT PROCESS
- First fit call with our Talent Acquisition Manager
- Team fit call with the Hiring Manager
- Tech round with the Team
- A final interview with our CISO
#LI-RH1 #LI-HYBRID
The range listed is for base compensation. Your actual base salary will vary based on factors including location and individual qualifications objectively assessed during the interview process.
In addition to base salary, your total rewards package will include additional components such as incentive pay and benefits. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the specific details for this position.
Base Salary Pay Range
$120,000—$150,000 USD
To support our permanent, full time employees at every stage of their careers and lives, we provide a competitive total rewards and benefits package. Here are the global benefits we'd like to highlight:
- Flexible remote and hybrid working options
- Competitive Salary and a variable component tied to personal and company performance
- Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth
- Generous PTO and paid holidays
- Mental health benefits
- 2 MAD Days per year (Make A Difference Days for paid volunteering)
Additional benefits may be offered by country, based on your eligibility - ask your recruiter for more information. Intern and Apprentice positions may receive some of these benefits - ask your recruiter for more details.
AI tools are used to help review applications for this role. Read our AI in Recruitment Notice for what the AI considers, how to request a human review, and our most recent bias audit.
At Shift we strive to be a diverse and inclusive workforce. We welcome applications from and hire people who will contribute to the diversity of our company, without regard to race, color, religion, marital status, age, national or ethnic origin, physical or mental disability, medical condition, pregnancy, genetic information, gender identity or expression, sexual orientation, or other non-merit criteria. Shift Technology is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and employment process. Should you require accommodation, please email View email address on us.fitly.work -technology.com and we will work with you to meet your accessibility needs.
Please be aware of scammers and only trust correspondence that comes from emails ending in "shift-technology.com". We will never do initial outreach to you via Whatsapp/Text/SMS, never ask for banking information or personal identification numbers (ex. Social Security Number) as part of our recruitment process.
Shift Technology does not accept unsolicited CVs from recruiters or employment agencies in response to the Shift Technology Careers page or a Shift Technology social media post. Any unsolicited CVs, including those submitted directly to hiring managers, are deemed to be the property of Shift Technology.
$120k - $150k
...accurate, explainable, and secure—empowering human... ...in collaboration with engineering and business teams and... ...certifications such as CIPP/E, CIPP/US, CIPT CISA, CISM, CRISC... ...our permanent, full time employees at every... ...are used to help review applications for this role. Read our...ApplicationPermanent employmentFull timeContract workApprenticeshipWork experience placementInternshipRemote workFlexible hoursShift work$83.5k - $105k
...motors for industrial applications in water treatment,... ...From keeping us comfortable in our homes... ...Managers, Applications Engineers, Product Managers, customers... ...shipments to ensure timely delivery and receipt.... ...primarily during Eastern and/or Central Time Zone business hours...ApplicationWork experience placementWork at officeRemote workWorldwideShift work- ...who specialize in software engineering, logical reasoning, STEM, multilinguality... ...2+ years of continuous full-time experience at a top-tier... ...in building full-stack applications and deploying scalable,... ...Candidates must be based out of US, Canada or WEU countries (UK,...ApplicationRemote jobFull timeContract workFor contractorsFlexible hours
$72.28k - $117.52k
...salary range over time as they progress in... ...: The Central Supervision Analyst... ...Wealth, (TDPCW), a US registered Investment... ...requirements of FINRA and Securities Laws. May (or may... ...experience of an applicant for registration... ...and businesses in Canada, the United States...ApplicationFull timeLocal areaWork from homeFlexible hours$115k - $155k
...primary care, generous paid time off, 401k plan with... ...2 issues related to security configurations and... ...for Suffolk corporate applications by helping assess risks... ...skills with development, engineering, and DevOps teams,... ...Location : Location: US-MA-BostonType: Regular...ApplicationTemporary workFor contractorsWork experience placementWork at office$125k - $205k
...more at later.com.Senior Security EngineerAbout this... ...for a Senior Security Engineer to strengthen Later's company... ..., with a focus on application security, cloud and infrastructure... ...sources to help us understand the market... ...candidates located in the Canada: $110,000-160,000...ApplicationPermanent employmentLocal areaRemote work$145.9k - $234.2k
The Role: As a Cybersecurity Engineer, you will help design,... ...Moderna’s approach to API security across modern applications, platform services, and AI-... ...surrogacy supportGenerous paid time off, including vacation, volunteer... ...direct mentorship. Join us in shaping a world where...ApplicationPermanent employmentFull timeWork at officeWork from home$120k - $202.5k
...looking for a Senior Staff SaaS Security Engineer reporting within the... ...enterprise adoption of SaaS applications and AI-enabled services continues... ...teams across multiple time zones.Standard business hours... ...institutional investors rely on us to help them manage risk, respond...ApplicationFull timeTemporary workFlexible hours$117.6k - $176.4k
...As a Senior Security Engineer at EnergySage, you will play a pivotal role in fortifying our application security through both hands-on technical work... ...range for this full-time position applies to candidates... ...Curiosity, Teamwork starts with us. IMPACT is also your invitation...ApplicationFull timeTemporary workFlexible hours$121.6k - $194.5k
...Role As a Cybersecurity Engineer, you will help design,... ...Moderna’s approach to API security across modern applications, platform services, and AI-... ...support Generous paid time off, including vacation, volunteer... ...direct mentorship. Join us in shaping a world where every...ApplicationPermanent employmentWork at officeLocal areaWork from home$175k - $200k
...com and follow us on LinkedIn.... ...seeking a strategic Security Architect to... ...with Product, Engineering, and Infrastructure... ...Application & Development Security... ...Lifecycle (SDLC) and DevSecOps initiatives across... ...tools ~ Central logging/Siem practices... ...renot spending time together in one...ApplicationWork at officeLocal areaRemote workWork from homeShift work3 days per week$120k - $202.5k
...for We are seeking a Product Security Engineer / Architect - Email Security... ...global teams across multiple time zones.Standard business hours... ...primary location above, the applicable range could differ.Employees... ...institutional investors rely on us to help them manage risk, respond...ApplicationFull timeTemporary workWork at officeFlexible hours$99k - $120k
...Do you spend your free time figuring out how systems break... ...role is built for you. As a Security Engineer II on our Active Operational... ...privilege escalation paths. Web Application & API Assessment: Perform... ..., state or local law. The US base salary range for this full...ApplicationFull timeLocal areaImmediate start$99k - $120k
...Flywire, we are looking for a Security Engineer II to join our global... ...penetration testing, and real-time incident detection across Flywire... ...experience moving fluidly between Application Security, Cloud Architecture... ..., state or local law. The US base salary range for this...ApplicationFull timeLocal areaImmediate start$121k - $226k
...we're looking for a Sr. AI Security Engineer. Hi Marley is building an AI... ...why this role involves joining us in the Boston office for 3... ...years in security engineering, application security, or infrastructure security... ...- we all work hard and take time when we need it Who We Are...ApplicationWork at officeFlexible hours3 days per week- ...Working knowledge of MS Office applications, LinkedIn Sales Navigator and... ...active listening, organization, time-management and follow through... ...benefits plan A secure job in a professional environment... ...America Donna Jenkins ! About us We, eschbach GmbH with headquaters...ApplicationRemote jobFull timeWork experience placementFlexible hours
$75k - $220k
...exploration to biomedical engineering, lives often depend on... ...Designs and operates secure, automated CI/CD pipelines... ...modifications to processes and/or applications based on quantitative... ...Code: 02139-3563 The US base salary range for this full-time position is $75,000.00...ApplicationFull timeLocal area$140k - $180k
...Job Description Applicants must be authorized... ...employment visa at this time. Mark43's... ...to help our engineers write performant and... ...approved to hire in Canada, the UK, and 36 U.... ...information you provide to us when you apply for... ...part of Mark43's security measures all...ApplicationRemote workWork visaShift work$115.8k - $127.7k
...have hands-on exposure to real-time eligibility verification, bed... .... Epic Prelude and/or Grand Central certification strongly... ...familiarity with adjacent Epic applications such as Willow, Beacon, Cadence... ...plans, and coordinating with engineering/infra to implement and validate...Application$75k - $85k
construction administrator, US Are you looking for... ...push through payment application and invoices to... ...lifecycle maintain timely correspondence for all... ...Bachelor's degree in engineering, architecture, construction... ...offices in central locations with a high-...ApplicationWeekly payFull timeContract workTemporary workFor contractorsLocal area$110k - $315k
...OverviewJoin our Cyber Security team as an experienced Application Security Engineer, where you’ll play a key... ...by building a modern DevSecOps ecosystem that leverages... ...a disability, contact us to discuss the nature of... ...information.SummaryLocation: BostonType: Full timeApplicationFull timeLocal area- ...discoveries and invite all applicants to join us and experience what... ...the US, UK, Ireland, Canada, Australia and New... ...Manager plays a central role in supporting the... ...inquiries, and ensure timely communication. This role... ...environment with Eastern Time Zone working hours...ApplicationWork at officeRemote workShift work
$80k - $200k
...thrive in your ideal environment. Join us in transforming the life sciences... ...remote position with a preference for Eastern or Central Time Zone. If a candidate is in close proximity... ...the process you can expect.Follow the application process and submit your resume.Within...ApplicationWork at officeLocal areaRemote workWork from home$150k - $180k
...priorities. Job Summary As Lead Security Engineer, you will set the technical... ...Credibility: Deep hands-on seniority in application security, cloud architecture... ..., state or local law. The US base salary range for this full-time position is $150,000 - 180,000 and...ApplicationFull timeLocal areaImmediate start$98k - $193k
...to candidates across North America’s Eastern and Central Time Zones and are flexible on location for... ...relying on MongoDB for their most important applications, we’re powering the next era of... ...each other, and win. It’s what makes us MongoDB. To drive the personal growth...ApplicationLocal areaWorldwideFlexible hours$93.95k - $136.74k
...groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be... ...Brigham is seeking an Information Security Engineer III to serve as a senior leader... ...needs. Monday-Friday schedule during Eastern business hours. On remote workdays,...ApplicationRemote workMonday to FridayFlexible hoursShift work- ...Delinea is a pioneer in securing human and machine... ...intelligent, centralized authorization, empowering... ..., data, SaaS applications, and AI. It is the... ...threats in real-time. With deployment in... ...Delinea and help us make the world a safer... ..., outstanding engineers, and strategic investment...ApplicationPart timeFor contractorsWork at officeLocal area3 days per week
- ...role The Lead Corporate Security Engineer will be our domain expert for... ...program: the bar for our SaaS applications, the assessment cadence, and... ...and the SOC, and told us the three things we're wrong... ...program ownership, just-in-time access patterns or identity-...ApplicationLocal area
- ...leading AI skills across engineering, sales, product,... ...forward to reviewing your application. If this just isn’t the right role or time - sign up for job alerts... ...Tasmania, Western Australia Canada: Alberta, Manitoba,... ...privacy is important to us. By submitting an application...ApplicationLocal areaFlexible hours
$92.5k
...candidate resides within the East or Central time zones of the continental US. Responsibilities: Foster... ...Yelp's internal tool that provides secure access to a number of LLM models, to... ...opportunity employer and consider qualified applicants without regard to race, color,...ApplicationRemote jobLocal areaWork from homeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada. Be the first to apply!
- network applications engineer Boston, MA
- field applications engineer Boston, MA
- project application engineer Boston, MA
- application security engineer Boston, MA
- application support engineer Boston, MA
- hydraulic application engineer Boston, MA
- technical application engineer Boston, MA
- application performance engineer Boston, MA
- cnc applications engineer Boston, MA
- senior application support engineer Boston, MA





