Shift Technology
Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada
About this role
Shift seeks an Application Security/DevSecOps Engineer to embed security throughout the software delivery pipeline and serve as a first responder for security incidents. You'll drive secure-by-design practices, automate security testing in CI/CD, monitor and investigate security alerts, and work cross-functionally with engineering and data science teams to protect the company's AI-powered insurance platform.
What you'll do
- Define and champion application security policies, standards, and guidelines across the organization
- Automate security testing (SAST, DAST, SCA) and vulnerability management within the CI/CD pipeline
- Lead threat modeling exercises and identify systemic developer security issues
- Monitor, triage, and investigate security alerts from Microsoft Sentinel, EDR, and cloud security tools
- Serve as first responder for security incidents, executing containment and remediation procedures
- Establish guardrails for AI-assisted development and manage code/infrastructure signing and attestation
What they're looking for
- Application Security (AppSec) practices and SDLC integration
- DevSecOps and CI/CD pipeline security automation
- SAST, DAST, SCA, and vulnerability scanning tools
- Incident response and security alert triage
- Microsoft Sentinel and EDR platform experience
- Infrastructure as Code (IaC) security and secret management
- Threat modeling and security code review
- Cloud security and SBOM management
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Shift Technology
Shift Technology builds AI-driven solutions for healthcare payment integrity, helping insurers detect and prevent fraudulent or erroneous claims. The company is hiring Data Scientists and Engineers to develop data pipelines, work with diverse data sources, and implement responsible AI practices in close collaboration with clients.
- Website
- shift-technology.com
Likely interview questions
- Describe your experience implementing SAST/DAST automation in a CI/CD pipeline—what challenges did you face and how did you optimize coverage?
- Tell us about a time you discovered a systemic security issue in a development team. How did you identify it and drive remediation?