Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada
Core
Drive application security and DevSecOps practices across the software delivery pipeline and serve as a first responder for security incidents and alerts.
Role type
Senior Application Security / DevSecOps Engineer
Builds
Secure software delivery pipelines, AI-assisted development guardrails, and incident response capabilities for an insurance-grade AI SaaS platform.
Domain
Insurance technology, Cloud Security, DevSecOps, Application Security
Deliverable
production ML models | infrastructure | dashboards & analysis
Required skills
SIEM (Microsoft Sentinel), EDR platforms, Application Vulnerability Management, SBOM, Secret Management, IaC Security, Scripting (Python/PowerShell/Go/JS), Networking fundamentals, MITRE ATT&CK, Cloud security concepts
Preferred skills
KQL, AI/ML security (prompt injection), SaaS security concepts (tenant isolation), Major language frameworks (C#/Java/React/Python)
Responsibilities
Define and champion technical security policies and standards; Automate security testing (SAST, DAST, SCA) in CI/CD; Monitor and triage security alerts from SIEM/EDR; Investigate and respond to security incidents; Lead threat modeling exercises; Manage software vulnerability programs and remediation; Establish guardrails for AI-assisted code development.
Seniority
Senior, hands-on IC
