← Back to jobs

Remote job

Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada

Other Full-time Permanent US, Canada

Job details

$120,000 — $150,000 Salary
US, Canada Eligibility
Intern Experience
Full-time Employment

About this role

Role overview This role embeds security into every stage of the software delivery lifecycle while serving as a first responder inside a security operations function. The engineer partners with data scientists, software developers, and platform teams to shift security left, automate testing across the CI/CD pipeline, and triage alerts from cloud and endpoint detection tools. It is a hands-on, cross-functional position bridging application security, DevSecOps, and incident response for an AI-driven platform serving regulated customers.

Responsibilities - Define and champion technical security policies, standards, and guidelines across engineering teams, and act as the subject matter expert on secure-by-design practices. - Lead threat modeling exercises and identify systemic developer security issues, driving remediation through coaching and structural change. - Automate static, dynamic, software composition analysis, and vulnerability management within CI/CD pipelines, including signing and attestation of code and artifacts. - Establish governance for AI-assisted development, ensuring generated code meets internal security standards, alongside best practices for secrets management, IaC security, and SBOM. - Monitor and triage alerts from SIEM, EDR, and cloud security tools; investigate suspicious activity, differentiate false positives, and execute incident response playbooks. - Coordinate evidence collection, remediation, and post-incident reviews with engineering, infrastructure, and helpdesk stakeholders.

Requirements - Proven experience embedding application security and DevSecOps practices into modern software delivery pipelines. - Hands-on expertise with SAST, DAST, SCA, secrets management, IaC scanning, SBOM, and vulnerability management tooling. - Operational experience with SecOps platforms such as Microsoft Sentinel, EDR solutions, and cloud-native security monitoring. - Demonstrated ability to lead threat modeling, communicate risk clearly to both technical and non-technical audiences, and run incident response. - Comfortable working remotely across Central or Eastern time zones in the US or Canada.

Benefits and work setup - Base salary range of $120,000 to $150,000 USD, with additional incentive pay and a benefits package. - Flexible remote and hybrid working options, generous PTO, paid holidays, and mental health benefits. - Dedicated learning time including a half-day each month for personal growth, plus paid volunteering days. - Country-specific benefits may apply based on eligibility.

Skills detected in the listing

JavaScriptReactPythonJavaGoC#Stakeholder ManagementInformation SecurityGDPRAzure
Detected Sep 24, 2026
Last verified Sep 24, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight