Application Security
19 hours ago
Winnipeg, Manitoba, Canada
Shift Technology
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
Shift delivers AI agents that transform insurers' most critical work. By combining deep industry expertise and unmatched data resources, Shift provides proven results that have earned the trust of hundreds of the world's leading insurers. Our insurance-grade AI is accurate, explainable, and secure-empowering human experts to move with unmatched speed, total confidence, and a renewed focus on the people they serve.
Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.
Learn more at www.shift-technology.com
As an Application Security/DevSecOps Engineer, you will drive application security and DevSecOps practices across Shift's software delivery pipeline, from the first line of code through the CI/CD pipeline, working closely with data scientists, software delivery teams, and engineers to ensure security is built in by design. You will also serve as a first responder within Shift's Security Operations function, monitoring, triaging, investigating, and responding to security alerts and incidents across our environment. Working closely with engineering, infrastructure, and helpdesk teams, you will help ensure applications are secure by design and that threats are identified, contained, and remediated efficiently while following established processes and procedures.
RESPONSIBILITIES Secure by Design (Shift Left)
Working with data scientists, software delivery teams, and engineers to ensure technical security standards are well understood and best practices are followed.
Driving Application Security through defining technical policies, standards, and guidelines and championing these throughout the organisation.
Identification of systemic and cultural developer security issues, and remediation opportunities.
Promote a mind-set of developing secure systems, transferring knowledge of security standards/processes, and acting as a subject matter expert (SME).
Leading and facilitating threat modeling exercises.
Secure the Build & Deploy Pipeline (DevSecOps/AppSec)
Automation of security testing (SAST, DAST, SCA, vulnerability management).
Ensuring full benefits realisation of relevant tooling.
Ensure maximum code and infrastructure coverage.
Ensure code and artifact integrity through automated signing and attestation processes within the CI/CD pipeline.
Establish guardrails and governance for AI-assisted development, ensuring AI-generated code is rigorously vetted for security vulnerabilities and adheres to internal coding standards.
Ensure company-wide best practices for Secret Management, IaC Security, and SBOM.
Security auditing of software developed by the company and its partners.
Operate a software vulnerability management program, taking responsibility for the identification, production, and improvement of meaningful metrics, and reporting on progress.
Prioritise and manage the remediation of code defects.
Security Monitoring & Incident Response (SecOps)
Monitor and triage security alerts generated from Microsoft Sentinel, EDR platforms, cloud security tools, and other security technologies.
Investigate suspicious activity and determine the severity, scope, and potential impact of security events.
Validate alerts, differentiate false positives from actionable incidents, and elevate to relevant teams - following established processes - when additional investigation or response is required.
Serve as a first responder for security incidents and operational security events, executing response procedures and containment actions in accordance with established playbooks and guidance.
Gather relevant evidence, coordinate with internal stakeholders, and ensure timely remediation of identified issues.
Maintain accurate records of investigations and actions taken, and participate in post-incident reviews and documentation activities.
Collaboration & Professional Development
Communicate investigation results clearly and concisely to technical and non-technical stakeholders.
Work closely with engineering and infrastructure teams to support remediation efforts.
Participate in internal purple team exercises and security initiatives.
Maintain a disciplined, process-driven approach to incident handling and operational responsibilities.
Continuously develop technical and security knowledge through training, collaboration, and hands-on experience.
SKILLS & BACKGROUND Experience & Education
Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience.
7+ years of experience in Security Ope
Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.
Learn more at www.shift-technology.com
As an Application Security/DevSecOps Engineer, you will drive application security and DevSecOps practices across Shift's software delivery pipeline, from the first line of code through the CI/CD pipeline, working closely with data scientists, software delivery teams, and engineers to ensure security is built in by design. You will also serve as a first responder within Shift's Security Operations function, monitoring, triaging, investigating, and responding to security alerts and incidents across our environment. Working closely with engineering, infrastructure, and helpdesk teams, you will help ensure applications are secure by design and that threats are identified, contained, and remediated efficiently while following established processes and procedures.
RESPONSIBILITIES Secure by Design (Shift Left)
Working with data scientists, software delivery teams, and engineers to ensure technical security standards are well understood and best practices are followed.
Driving Application Security through defining technical policies, standards, and guidelines and championing these throughout the organisation.
Identification of systemic and cultural developer security issues, and remediation opportunities.
Promote a mind-set of developing secure systems, transferring knowledge of security standards/processes, and acting as a subject matter expert (SME).
Leading and facilitating threat modeling exercises.
Secure the Build & Deploy Pipeline (DevSecOps/AppSec)
Automation of security testing (SAST, DAST, SCA, vulnerability management).
Ensuring full benefits realisation of relevant tooling.
Ensure maximum code and infrastructure coverage.
Ensure code and artifact integrity through automated signing and attestation processes within the CI/CD pipeline.
Establish guardrails and governance for AI-assisted development, ensuring AI-generated code is rigorously vetted for security vulnerabilities and adheres to internal coding standards.
Ensure company-wide best practices for Secret Management, IaC Security, and SBOM.
Security auditing of software developed by the company and its partners.
Operate a software vulnerability management program, taking responsibility for the identification, production, and improvement of meaningful metrics, and reporting on progress.
Prioritise and manage the remediation of code defects.
Security Monitoring & Incident Response (SecOps)
Monitor and triage security alerts generated from Microsoft Sentinel, EDR platforms, cloud security tools, and other security technologies.
Investigate suspicious activity and determine the severity, scope, and potential impact of security events.
Validate alerts, differentiate false positives from actionable incidents, and elevate to relevant teams - following established processes - when additional investigation or response is required.
Serve as a first responder for security incidents and operational security events, executing response procedures and containment actions in accordance with established playbooks and guidance.
Gather relevant evidence, coordinate with internal stakeholders, and ensure timely remediation of identified issues.
Maintain accurate records of investigations and actions taken, and participate in post-incident reviews and documentation activities.
Collaboration & Professional Development
Communicate investigation results clearly and concisely to technical and non-technical stakeholders.
Work closely with engineering and infrastructure teams to support remediation efforts.
Participate in internal purple team exercises and security initiatives.
Maintain a disciplined, process-driven approach to incident handling and operational responsibilities.
Continuously develop technical and security knowledge through training, collaboration, and hands-on experience.
SKILLS & BACKGROUND Experience & Education
Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience.
7+ years of experience in Security Ope