03 Oct
|
Shift Technology
|
Toronto
03 Oct
Shift Technology
Toronto
Shift delivers AI agents that transform insurers' most critical work. By combining deep industry expertise and unmatched data resources, Shift provides proven results that have earned the trust of hundreds of the world's leading insurers. Our insurance-grade AI is accurate, explainable, and secure-empowering human experts to move with unmatched speed, total confidence, and a renewed focus on the people they serve.
Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance. As an Application Security/DevSecOps Engineer, you will drive application security and DevSecOps practices across Shift's software delivery pipeline, from the first line of code through the CI/CD pipeline, working closely with data scientists, software delivery teams, and engineers to ensure security is built in by design.
You will also serve as a first responder within Shift's Security Operations function, monitoring, triaging, investigating, and responding to security alerts and incidents across our environment. Working closely with engineering, infrastructure, and helpdesk teams, you will help ensure applications are secure by design and that threats are identified, contained, and remediated efficiently while following established processes and procedures. Secure by Design (Shift Left) Working with data scientists, software delivery teams, and engineers to ensure technical security standards are well understood and best practices are followed.
Driving Application
Security through defining technical policies, standards, and guidelines and championing these throughout the organisation. Identification of systemic and cultural developer security issues, and remediation opportunities. Promote a mind-set of developing secure systems, transferring knowledge of security standards/processes, and acting as a subject matter expert (SME).
Secure the Build & Deploy Pipeline (DevSecOps/AppSec) Automation of security testing (SAST, DAST, SCA, vulnerability management). Ensure code and artifact integrity through automated signing and attestation processes within the CI/CD pipeline. Establish guardrails and governance for AI-assisted development, ensuring AI-generated code is rigorously vetted for security vulnerabilities and adheres to internal coding standards.
Ensure company-wide best practices for Secret Management, IaC Security, and SBOM. Security auditing of software developed by the company and its partners. Operate a software vulnerability management program, taking responsibility for the identification, production, and improvement of meaningful metrics, and reporting on progress.
Security
Monitoring & Incident Response (SecOps) Monitor and triage security alerts generated from Microsoft Sentinel, EDR platforms, cloud security tools, and other security technologies. Investigate suspicious activity and determine the severity, scope, and potential impact of security events. Serve as a first responder for security incidents and operational security events, executing response procedures and containment actions in accordance with established playbooks and guidance.
Communicate investigation results clearly and concisely to technical and non-technical stakeholders. Participate in internal purple team exercises and security initiatives. Continuously develop technical and security knowledge through training, collaboration, and hands-on experience.
Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience. ~7+ years of experience in Security Operations, Incident Response, Cybersecurity Monitoring, or a similar security role.
Technical Skills
Experience working with a SIEM platform, preferably Microsoft Sentinel.
Experience with at least one Endpoint Detection and Response (EDR) platform such as Microsoft Defender for Endpoint, CrowdStrike, Cortex XDR, or similar.
Experience with application vulnerability management tools such as GitHub Advanced Security, Tenable, or similar. Knowledge of API, web application, and software supply chain security (SBOM) Familiarity with major language frameworks such as C#, Java, React, or Python. Awareness of security considerations for AI/ML integrations, such as risks like prompt injection Familiarity with SaaS application security concepts,
such as tenant isolation and secure API design.
Familiarity with Microsoft Azure environments and development platforms such as GitHub and GitHub Actions. Understanding of networking fundamentals and network security concepts. Proficiency in at least one scripting or programming language such as Python, PowerShell, JavaScript, or Go.
Familiarity with KQL or similar query languages is preferred. Understanding of common cybersecurity threats, attack techniques, and defensive controls. Basic understanding of cloud security, identity security, endpoint security, and vulnerability management concepts.
Awareness of common security and compliance frameworks such as ISO 27001, NIST CSF, SOC 2, HIPAA, or GDPR. Ability to communicate technical findings clearly, accurately, and concisely. Collaborative team player with a strong desire to learn and grow within cybersecurity.
Ability to remain calm and methodical during security incidents. To support our permanent, full time employees at every stage of their careers and lives, we provide a competitive total rewards and benefits package. Adaptable remote and hybrid working options ~ Competitive Salary and a variable component tied to personal and company performance ~ Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth ~ Generous PTO and paid holidays ~ Intern and Apprentice positions may receive some of these benefits - ask your recruiter for more details.
AI tools are used to help review applications for this role. Read our AI in Recruitment Notice for what the AI considers, how to request a human review, and our most recent bias audit. At Shift we strive to be a diverse and inclusive workforce.
We welcome applications from and hire people who will contribute to the diversity of our company, without regard to race, color, religion, marital status, age, national or ethnic origin, physical or mental disability, medical condition, pregnancy, genetic information, gender identity or expression, sexual orientation, or other non-merit criteria.
Shift
Technology is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and employment process. Should you require accommodation, please email accommodation@shift-technology.
📌 Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada (Toronto)
🏢 Shift Technology
📍 Toronto