Remote job
Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada
Job details
About this role
Role overview This role embeds security into every stage of the software delivery lifecycle while serving as a first responder inside a security operations function. The engineer partners with data scientists, software developers, and platform teams to shift security left, automate testing across the CI/CD pipeline, and triage alerts from cloud and endpoint detection tools. It is a hands-on, cross-functional position bridging application security, DevSecOps, and incident response for an AI-driven platform serving regulated customers.
Responsibilities - Define and champion technical security policies, standards, and guidelines across engineering teams, and act as the subject matter expert on secure-by-design practices. - Lead threat modeling exercises and identify systemic developer security issues, driving remediation through coaching and structural change. - Automate static, dynamic, software composition analysis, and vulnerability management within CI/CD pipelines, including signing and attestation of code and artifacts. - Establish governance for AI-assisted development, ensuring generated code meets internal security standards, alongside best practices for secrets management, IaC security, and SBOM. - Monitor and triage alerts from SIEM, EDR, and cloud security tools; investigate suspicious activity, differentiate false positives, and execute incident response playbooks. - Coordinate evidence collection, remediation, and post-incident reviews with engineering, infrastructure, and helpdesk stakeholders.
Requirements - Proven experience embedding application security and DevSecOps practices into modern software delivery pipelines. - Hands-on expertise with SAST, DAST, SCA, secrets management, IaC scanning, SBOM, and vulnerability management tooling. - Operational experience with SecOps platforms such as Microsoft Sentinel, EDR solutions, and cloud-native security monitoring. - Demonstrated ability to lead threat modeling, communicate risk clearly to both technical and non-technical audiences, and run incident response. - Comfortable working remotely across Central or Eastern time zones in the US or Canada.
Benefits and work setup - Base salary range of $120,000 to $150,000 USD, with additional incentive pay and a benefits package. - Flexible remote and hybrid working options, generous PTO, paid holidays, and mental health benefits. - Dedicated learning time including a half-day each month for personal growth, plus paid volunteering days. - Country-specific benefits may apply based on eligibility.