Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada

Hidden Jobs

United States

Hybrid

USD 120,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible remote options
Hybrid work model

Job summary

Hidden Jobs is seeking a hands-on Security Engineer to embed security across the software development lifecycle and act as a first responder within our security operations function. You will partner with data scientists, engineers, and platform teams to shift security left, automate testing in CI/CD, and triage alerts from cloud and endpoint tools.

You will lead threat modeling, enforce secure-by-design practices, and drive remediation through coaching and governance.

Qualifications

  • Proven experience embedding application security and DevSecOps practices into modern software delivery pipelines.
  • Hands-on expertise with SAST, DAST, SCA, secrets management, IaC scanning, SBOM, and vulnerability management tooling.
  • Operational experience with SecOps platforms such as Microsoft Sentinel, EDR solutions, and cloud-native security monitoring.
  • Demonstrated ability to lead threat modeling, communicate risk clearly to both technical and non-technical audiences, and run incident response.
  • Comfortable working remotely across Central or Eastern time zones in the US or Canada.

Responsibilities

  • Define and champion technical security policies, standards, and guidelines across engineering teams, and act as the subject matter expert on secure-by-design practices.
  • Lead threat modeling exercises and identify systemic developer security issues, driving remediation through coaching and structural change.
  • Automate static, dynamic, software composition analysis, and vulnerability management within CI/CD pipelines, including signing and attestation of code and artifacts.
  • Establish governance for AI-assisted development, ensuring generated code meets internal security standards, alongside best practices for secrets management, IaC security, and SBOM.
  • Monitor and triage alerts from SIEM, EDR, and cloud security tools; investigate suspicious activity, differentiate false positives, and execute incident response playbooks.
  • Coordinate evidence collection, remediation, and post-incident reviews with engineering, infrastructure, and helpdesk stakeholders.

Skills

Application security
DevSecOps
Threat modeling
Incident response
Security tooling

Tools

SAST
DAST
SCA
Secrets management
IaC scanning
SBOM
Vulnerability management
Microsoft Sentinel
EDR

Job description

Role overview

This role embeds security into every stage of the software delivery lifecycle while serving as a first responder inside a security operations function. The engineer partners with data scientists, software developers, and platform teams to shift security left, automate testing across the CI/CD pipeline, and triage alerts from cloud and endpoint detection tools. It is a hands‑on, cross‑functional position bridging application security, DevSecOps, and incident response for an AI‑driven platform serving regulated customers.

Responsibilities
  • Define and champion technical security policies, standards, and guidelines across engineering teams, and act as the subject matter expert on secure‑by‑design practices.
  • Lead threat modeling exercises and identify systemic developer security issues, driving remediation through coaching and structural change.
  • Automate static, dynamic, software composition analysis, and vulnerability management within CI/CD pipelines, including signing and attestation of code and artifacts.
  • Establish governance for AI‑assisted development, ensuring generated code meets internal security standards, alongside best practices for secrets management, IaC security, and SBOM.
  • Monitor and triage alerts from SIEM, EDR, and cloud security tools; investigate suspicious activity, differentiate false positives, and execute incident response playbooks.
  • Coordinate evidence collection, remediation, and post‑incident reviews with engineering, infrastructure, and helpdesk stakeholders.
Requirements
  • Proven experience embedding application security and DevSecOps practices into modern software delivery pipelines.
  • Hands‑on expertise with SAST, DAST, SCA, secrets management, IaC scanning, SBOM, and vulnerability management tooling.
  • Operational experience with SecOps platforms such as Microsoft Sentinel, EDR solutions, and cloud‑native security monitoring.
  • Demonstrated ability to lead threat modeling, communicate risk clearly to both technical and non‑technical audiences, and run incident response.
  • Comfortable working remotely across Central or Eastern time zones in the US or Canada.
Benefits and work setup
  • Base salary range of $120,000 to $150,000 USD, with additional incentive pay and a benefits package.
  • Flexible remote and hybrid working options, generous PTO, paid holidays, and mental health benefits.
  • Dedicated learning time including a half‑day each month for personal growth, plus paid volunteering days.
  • Country‑specific benefits may apply based on eligibility.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer [Remote-US]
Application Security Engineer [Remote-US]

Hidden Jobs • United States

Remote
USD 175,000 - 215,000
Medical, dental, vision insurance
401(k) with company match
Home office stipend
+6
Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada New US - Boston
Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada New US - Boston

Shift Technology • Boston (MA)

Hybrid
USD 140,000 - 190,000
Application Security Engineer - Senior
Application Security Engineer - Senior

platacard • United States

Hybrid
USD 120,000 - 180,000
Relocation with visa support
Flexible work office or remote
Healthcare coverage
+3
Security Research Engineer
Security Research Engineer

AI Security Assurance • Northern (KY)

Hybrid
USD 160,000 - 230,000
Remote‑first
Life Insurance
Disability coverage
+1
Senior Security Engineer
Senior Security Engineer

Wintermeyer Ventures • San Francisco (CA)

On-site
USD 200,000 - 330,000
Equity
Senior Security Engineer
Senior Security Engineer

muonspace • United States

Hybrid
USD 193,000 - 218,000
Competitive equity grant
Comprehensive benefits
Hybrid/remote work options
+3
Security Solution Architect
Security Solution Architect

Jobgether • United States

Hybrid
USD 190,000 - 250,000
Competitive base salary
Discretionary bonuses
Equity package through RSU
+2
Senior Director, Security Engineering
Senior Director, Security Engineering

iterable • United States

Remote
USD 220,000 - 300,000
Equity
401(k) plan
Medical insurance
+8
Application Security Lead
Application Security Lead

Hidden Jobs • United States

Remote
USD 180,000 - 400,000
Equity compensation
Remote-first policy
DevSecOps Engineer
DevSecOps Engineer

VDart Inc • United States

Remote
USD 140,000 - 170,000