Shift Technology

Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada

Shift Technology
Apply
14 hours ago
Boston, MA, USASenior
H1B sponsor

Base Salary

$120k - $150k/yr

Responsibilities

  • Define and champion application security policies, standards, guidelines, and secure-by-design practices.
  • Lead threat modeling and identify systemic developer security issues and remediation opportunities.
  • Automate SAST, DAST, SCA, vulnerability management, signing, and attestation within CI/CD pipelines.
  • Establish governance for AI-assisted development, secret management, IaC security, SBOM, and software supply chain security.
  • Manage software vulnerability identification, metrics, prioritization, and remediation.
  • Monitor, triage, investigate, and respond to security alerts and incidents using SIEM, EDR, cloud security, and other security technologies.
  • Gather evidence, coordinate stakeholders, document investigations, execute containment procedures, and participate in post-incident reviews.
  • Collaborate with engineering and infrastructure teams and participate in purple team exercises and security initiatives.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience.
  • 7+ years of experience in security operations, incident response, cybersecurity monitoring, or a similar security role.
  • Experience with a SIEM platform, preferably Microsoft Sentinel, and at least one EDR platform such as Microsoft Defender for Endpoint, CrowdStrike, or Cortex XDR.
  • Experience with application vulnerability management tools such as GitHub Advanced Security or Tenable.
  • Knowledge of API, web application, software supply chain, SaaS application, cloud, identity, endpoint, and network security concepts.
  • Familiarity with C#, Java, React, Python, Microsoft Azure, GitHub, and GitHub Actions.
  • Proficiency in at least one scripting or programming language such as Python, PowerShell, JavaScript, or Go.
  • Awareness of AI/ML security risks such as prompt injection and familiarity with KQL or similar query languages.
  • Understanding of common cybersecurity threats, defensive controls, MITRE ATT&CK, and security and compliance frameworks such as ISO 27001, NIST CSF, SOC 2, HIPAA, or GDPR.
  • Strong analytical, investigative, communication, organizational, prioritization, and incident-handling skills.

Benefits

  • Flexible remote and hybrid working options.
  • Competitive base salary and a variable component tied to personal and company performance.
  • Learning and development opportunities, including Focus Fridays.
  • Generous paid time off and paid holidays.
  • Mental health benefits.
  • Two paid MAD Days per year for volunteering.

Tech Stack

AzureC#GitHub ActionsGoJavaJavaScriptPowerShellPythonReact

Categories

Shift Technology

About Shift Technology

501-1,000 employees

Shift Technology builds AI-driven software for insurers to detect fraud, improve claims handling, underwriting, and subrogation, and support payment integrity. Its products are delivered as enterprise SaaS and data services to property and casualty and other insurance carriers. Founded in 2014 and headquartered in Paris, the privately held company serves global insurers and emphasizes explainable, industry-grade models integrated into core insurance workflows.

Contact me