Skip to content

Open nowPosted 11 days ago

Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada

Shift Technology27 open roles

Pay
$120,000 – $150,000 a year
Where
US - Boston
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowApplication Security / DevSecOps Engineer - Central or Eastern time, US or CanadaShift Technology · US - Boston
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Shift Technology's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Shift Technology postings stay open a median of 26 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 11 days ago

Shift Technology median: 26 days open

The posting

Shift delivers AI agents that transform insurers' most critical work. By combining deep industry expertise and unmatched data resources, Shift provides proven results that have earned the trust of hundreds of the world's leading insurers. Our insurance-grade AI is accurate, explainable, and secure—empowering human experts to move with unmatched speed, total confidence, and a renewed focus on the people they serve.

Your browser does not support the video tag.

Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.

Learn more at www.shift-technology.com

As an Application Security/DevSecOps Engineer, you will drive application security and DevSecOps practices across Shift’s software delivery pipeline, from the first line of code through the CI/CD pipeline, working closely with data scientists, software delivery teams, and engineers to ensure security is built in by design. You will also serve as a first responder within Shift’s Security Operations function, monitoring, triaging, investigating, and responding to security alerts and incidents across our environment. Working closely with engineering, infrastructure, and helpdesk teams, you will help ensure applications are secure by design and that threats are identified, contained, and remediated efficiently while following established processes and procedures.

RESPONSIBILITIES

Secure by Design (Shift Left)

  • Working with data scientists, software delivery teams, and engineers to ensure technical security standards are well understood and best practices are followed.
  • Driving Application Security through defining technical policies, standards, and guidelines and championing these throughout the organisation.
  • Identification of systemic and cultural developer security issues, and remediation opportunities.
  • Promote a mind-set of developing secure systems, transferring knowledge of security standards/processes, and acting as a subject matter expert (SME).
  • Leading and facilitating threat modeling exercises.

Secure the Build & Deploy Pipeline (DevSecOps/AppSec)

  • Automation of security testing (SAST, DAST, SCA, vulnerability management).
  • Ensuring full benefits realisation of relevant tooling.
  • Ensure maximum code and infrastructure coverage.
  • Ensure code and artifact integrity through automated signing and attestation processes within the CI/CD pipeline.
  • Establish guardrails and governance for AI-assisted development, ensuring AI-generated code is rigorously vetted for security vulnerabilities and adheres to internal coding standards.
  • Ensure company-wide best practices for Secret Management, IaC Security, and SBOM.
  • Security auditing of software developed by the company and its partners.
  • Operate a software vulnerability management program, taking responsibility for the identification, production, and improvement of meaningful metrics, and reporting on progress.
  • Prioritise and manage the remediation of code defects.

Security Monitoring & Incident Response (SecOps)

  • Monitor and triage security alerts generated from Microsoft Sentinel, EDR platforms, cloud security tools, and other security technologies.
  • Investigate suspicious activity and determine the severity, scope, and potential impact of security events.
  • Validate alerts, differentiate false positives from actionable incidents, and escalate to relevant teams - following established processes - when additional investigation or response is required.
  • Serve as a first responder for security incidents and operational security events, executing response procedures and containment actions in accordance with established playbooks and guidance.
  • Gather relevant evidence, coordinate with internal stakeholders, and ensure timely remediation of identified issues.
  • Maintain accurate records of investigations and actions taken, and participate in post-incident reviews and documentation activities.

Collaboration & Professional Development

  • Communicate investigation results clearly and concisely to technical and non-technical stakeholders.
  • Work closely with engineering and infrastructure teams to support remediation efforts.
  • Participate in internal purple team exercises and security initiatives.
  • Maintain a disciplined, process-driven approach to incident handling and operational responsibilities.
  • Continuously develop technical and security knowledge through training, collaboration, and hands-on experience.

SKILLS & BACKGROUND

Experience & Education

  • Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience.
  • 7+ years of experience in Security Operations, Incident Response, Cybersecurity Monitoring, or a similar security role.

Technical Skills

  • Experience working with a SIEM platform, preferably Microsoft Sentinel.
  • Experience with at least one Endpoint Detection and Response (EDR) platform such as Microsoft Defender for Endpoint, CrowdStrike, Cortex XDR, or similar.
  • Experience with application vulnerability management tools such as GitHub Advanced Security, Tenable, or similar.
  • Knowledge of API, web application, and software supply chain security (SBOM)
  • Familiarity with major language frameworks such as C#, Java, React, or Python.
  • Awareness of security considerations for AI/ML integrations, such as risks like prompt injection
  • Familiarity with SaaS application security concepts, such as tenant isolation and secure API design.
  • Familiarity with Microsoft Azure environments and development platforms such as GitHub and GitHub Actions.
  • Understanding of networking fundamentals and network security concepts.
  • Proficiency in at least one scripting or programming language such as Python, PowerShell, JavaScript, or Go.
  • Familiarity with KQL or similar query languages is preferred.

Knowledge & Frameworks

  • Understanding of common cybersecurity threats, attack techniques, and defensive controls.
  • Familiarity with the MITRE ATT&CK framework.
  • Basic understanding of cloud security, identity security, endpoint security, and vulnerability management concepts.
  • Awareness of common security and compliance frameworks such as ISO 27001, NIST CSF, SOC 2, HIPAA, or GDPR.

Core Competencies

  • Strong analytical and investigative mindset.
  • Excellent written and verbal communication skills.
  • Ability to communicate technical findings clearly, accurately, and concisely.
  • Strong organizational skills and attention to detail.
  • Disciplined, process-oriented approach to operational work.
  • Ability to prioritize effectively and manage multiple investigations simultaneously.
  • Collaborative team player with a strong desire to learn and grow within cybersecurity.
  • Ability to remain calm and methodical during security incidents.

RECRUITMENT PROCESS

  • First fit call with our Talent Acquisition Manager
  • Team fit call with the Hiring Manager
  • Tech round with the Team
  • A final interview with our CISO

#LI-RH1 #LI-HYBRID

The range listed is for base compensation. Your actual base salary will vary based on factors including location and individual qualifications objectively assessed during the interview process.

In addition to base salary, your total rewards package will include additional components such as incentive pay and benefits. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the specific details for this position.

Base Salary Pay Range

$120,000—$150,000 USD

To support our permanent, full time employees at every stage of their careers and lives, we provide a competitive total rewards and benefits package. Here are the global benefits we’d like to highlight:

  • Flexible remote and hybrid working options
  • Competitive Salary and a variable component tied to personal and company performance
  • Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth
  • Generous PTO and paid holidays
  • Mental health benefits
  • 2 MAD Days per year (Make A Difference Days for paid volunteering)

Additional benefits may be offered by country, based on your eligibility - ask your recruiter for more information. Intern and Apprentice positions may receive some of these benefits - ask your recruiter for more details.

AI tools are used to help review applications for this role. Read our AI in Recruitment Notice for what the AI considers, how to request a human review, and our most recent bias audit.

At Shift we strive to be a diverse and inclusive workforce. We welcome applications from and hire people who will contribute to the diversity of our company, without regard to race, color, religion, marital status, age, national or ethnic origin, physical or mental disability, medical condition, pregnancy, genetic information, gender identity or expression, sexual orientation, or other non-merit criteria. Shift Technology is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and employment process. Should you require accommodation, please email [email protected] and we will work with you to meet your accessibility needs.

Please be aware of scammers and only trust correspondence that comes from emails ending in "shift-technology.com". We will never do initial outreach to you via Whatsapp/Text/SMS, never ask for banking information or personal identification numbers (ex. Social Security Number) as part of our recruitment process.

Shift Technology does not accept unsolicited CVs from recruiters or employment agencies in response to the Shift Technology Careers page or a Shift Technology social media post. Any unsolicited CVs, including those submitted directly to hiring managers, are deemed to be the property of Shift Technology.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Shift Technology's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Shift Technology's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Shift Technology's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.