
DevSecOps Engineer
ePayPolicy4 hours ago
Responsibilities
- Maintain, tune, and optimize Sonar and NPM/PyPI software supply chain scanning tools and enforce actionable security quality gates.
- Integrate automated security checks into GitHub Actions and GitLab CI pipelines.
- Triage dependency vulnerabilities, zero-day package risks, exposed credentials, and edge security alerts.
- Perform targeted manual web application and API penetration testing, threat modeling, authentication and authorization reviews, and exploit validation.
- Audit codebases for exposed secrets and support vault workflows and Infrastructure-as-Code scanning.
- Partner with Tech Debt and Platform Engineering teams to prioritize and remediate vulnerabilities against SLA targets.
- Translate findings into actionable developer tickets with reproduction steps, context, and remediation guidance.
- Track and report MTTR, scan coverage, and open high- and critical-risk metrics.
- Validate and triage externally submitted security reports before escalation to engineering.
Requirements
- 3–5+ years of hands-on experience in application security, security engineering, or penetration testing within a modern SaaS or cloud environment.
- Demonstrated expertise in manual web application penetration testing, API security assessments, and security tools.
- Hands-on experience configuring and tuning SAST, SCA, or DAST tools.
- Strong understanding of OWASP Top 10, OAuth2/OIDC, JWT, CORS, CSP, and other web security fundamentals.
- Experience managing edge WAF controls and integrating security checks into automated CI/CD pipelines.
- Strong communication skills and the ability to collaborate effectively with software developers and engineering leadership.
- Preferred certifications include OSCP, GWAPT, eWPT, CISSP, or Azure Security Engineer Associate.
- Familiarity with Terraform, Docker, and Kubernetes is preferred.
Benefits
- Competitive salary and comprehensive benefits, including employer-paid basic life and disability premiums.
- 401K and flexible paid time off policy.
- Company-sponsored quarterly ePayItForward initiatives.
- Supportive, inclusive culture focused on work/life balance and growth.
- Fully stocked kitchen and lunch stipend when working onsite.
- Hybrid schedule for in-office employees, generally three days per week, with days determined by the team and manager.
Tech Stack
Categories
About ePayPolicy
ePayPolicy is the fastest, easiest and most secure way to move money in the insurance industry. It's never been easier to get paid. There are no contracts, no setup fees, and no hidden fees.