DevSecOps Engineer

Posted 6 Hours Ago
Be an Early Applicant
Austin, TX, USA
Hybrid
Senior level
Fintech • Insurance • Payments • Software
ePayPolicy builds intuitive, modern tools to simplify payments for the entire insurance industry.
The Role
Own application security guardrails and tooling for a SaaS payment platform. Responsibilities include tuning SAST and SCA tools, integrating security checks into CI/CD pipelines, conducting manual web and API penetration tests, threat modeling, validating exploits, managing WAF and secrets security, triaging vulnerabilities, and reporting remediation metrics. The role partners closely with engineering, platform, and technology debt teams to reduce security risk while maintaining development velocity.
Summary Generated by Built In

Every day, ePayPolicy helps over 10,000 insurance companies speed up incoming and outgoing payments. By helping them move from manual, outdated forms of payment collection to modern payment tools, we help their companies work faster and more efficiently. (Check out our almost 5-star customer reviews.)

How do we do it? With powerful payment tools that just work. Our secure, online ACH and credit card payment page is the core product for many of our companies. But we also provide an integrated suite of helpful features for insurance companies of all sizes, including point-of-sale financing, payables network tools, and check reconciliation, all within a single dashboard.

Our expert, live support team helps deliver exceptional care every day, with an industry-leading 97% customer retention rate. Our customers love us. We love them.

Founded in 2014, our growing team is based in Austin, TX, and has clients in all 50 US states. We’ve grown over 300% in the last three years - with big plans for the future.

About ePayPolicy

At ePayPolicy, we’re helping make payments easier for an entire industry by building intuitive, modern financial tools for insurance. Founded in 2014, our goal has always been to eliminate outdated, inefficient payment methods by offering a secure, seamless digital payment platform for insurance carriers, agencies, MGAs, and premium finance companies.

Recognized as a Best Place to Work in Austin, we are driven by innovation, trust, and a commitment to keeping our platform fast and secure. Whether we are launching new features or scaling our platform, ePayPolicy is an exciting environment for independent thinkers who love a good challenge and are ready to make a high-impact contribution.

Role Summary

We are looking for a DevSecOps Engineer to join our Information Security team. In this role, you will bridge the gap between Security and Engineering, ensuring our SaaS payment platform remains secure by design without sacrificing development velocity or innovation speed.

Reporting directly to the Head of Information Security, you will serve as a trusted technical partner to our engineering teams. You will own application security guardrails and tooling (SAST/SCA), lead targeted internal web application penetration testing for high-risk releases, manage edge security controls (Cloudflare WAF), and collaborate closely with our Tech Debt and Platform teams to systematically triage and remediate vulnerabilities.

What You’ll Do (Key Responsibilities)

1. Application Security, Tooling & Guardrails

  • SAST & SCA Governance: Maintain, tune, and optimize static analysis (Sonar) and software supply chain scanning tools (NPM/PyPI scanners) to eliminate noise, build developer trust, and enforce actionable quality gates.

  • CI/CD Security Integration: Embed automated security checks seamlessly into GitHub Actions / GitLab CI pipelines, minimizing build latency while catching vulnerabilities prior to production release.

  • Supply Chain Security: Proactively triage zero-day package dependencies and software supply chain risks, establishing clear, prioritized remediation paths for engineering teams.

2. Internal Web Application Penetration Testing & Risk Assessments

  • Targeted Web App Pen Testing: Perform hands-on manual penetration testing and security assessments on high-risk feature releases, APIs, and web application workflows.

  • Threat Modeling & Logic Review: Evaluate complex business logic, authentication flows, and authorization boundaries for flaws that automated scanners miss.

  • Exploit Validation & Remediation Support: Produce clear, reproducible Proof-of-Concept (PoC) demonstrations to help developers understand vulnerability impact and guide effective fixes.

3. Edge & Infrastructure Security Alignment

  • Secrets Management & IaC: Audit codebases for exposed credentials/secrets and assist in vault workflows. Support the rollout of Infrastructure-as-Code (IaC) scanning as the security program expands.

4. Vulnerability Governance & Cross-Functional Partnership

  • Tech Debt Team Monthly Sync: Partner directly with the Tech Debt and Platform Engineering teams on a monthly cadence to review, prioritize, and burn down security vulnerabilities according to SLA targets.

  • Developer-Centric Ticketing: Translate scanner outputs and pen test findings into actionable tickets complete with reproduction steps, context, and clear fix recommendations.

  • Metrics & SLA Reporting: Track and report key performance metrics—such as Mean Time to Remediate (MTTR), scan coverage, and open high/critical risks—for joint Security and Engineering reviews.

5. Threat Monitoring & External Security

  • Triage & Escalation: Act as the primary technical escalation point for dependency alerts, exposed credentials, and edge anomaly detections.

  • Vulnerability Report Validation: Review, validate, and triage externally submitted security reports before passing verified findings to engineering.

What We’re Looking For (Qualifications)
  • Experience: 3–5+ years of hands-on experience in Application Security, Security Engineering, or Penetration Testing within a modern SaaS or cloud environment.

  • Offensive Security Skills: Demonstrated expertise in manual web application penetration testing, API security assessments, and using security tools.

  • Defensive Tooling Knowledge: Hands-on experience configuring and tuning SAST, SCA, or DAST tools.

  • Web & SaaS Fundamentals: Strong understanding of web security concepts (OWASP Top 10, modern authentication protocols like OAuth2/OIDC, JWT, CORS, CSP).

  • Edge & Pipeline Automation: Experience with edge WAF management and integrating security checks into automated CI/CD pipelines.

  • Collaborative Mindset: Strong communication skills with an ability to act as a partner—not a blocker—to software developers and engineering leadership.

Bonus Points (Nice-to-Haves)
  • Relevant industry certifications (e.g., OSCP, GWAPT, eWPT, CISSP, Azure Security Engineer Associate).

  • Familiarity with Infrastructure-as-Code (Terraform) and container security (Docker, Kubernetes).

Our Values

At ePayPolicy, our culture is shaped by five core values that drive how we work together:

  • Need for Speed: Consistently curious and proactive, we outrun competitors and get there first.

  • Trust & Transparency: Direct and honest communication creates trust, sustains speed, and fosters creative ideas.

  • Industry Aces: We're the customer's most trusted guide, caring about their problems as if they were our own.

  • Optimistic Grit: Plan to work and work the plan consistently, with an openness to change that fosters growth.

  • No Ego, Amigo: We work better when we humbly work together, across departments, roles, and titles.


Why ePayPolicy

  • Competitive salary

  • Comprehensive benefits package with employer-paid basic life and disability premiums

  • 401K

  • Flexible Paid Time Off Policy (FTO)

  • Company-sponsored quarterly “ePayItForward” initiatives 

  • Supportive and inclusive company culture with a focus on work/life balance

  • Fully-stocked kitchen

  • Lunch stipend when working onsite

  • Open communication (We won’t box you in! If you have a cool idea for a product improvement or a suggestion on how to improve the customer experience, let’s talk about it. We value everyone’s ideas and opinions.)

  • Huge opportunity for growth


We operate on a hybrid schedule for in-office employees. Standard schedules are three days per week in the office, however, the cadence and days are determined by each team and manager. 

Embracing AI at ePayPolicy - At ePayPolicy, AI is a company-wide initiative essential to how we work and innovate. All employees are expected to proactively leverage approved enterprise AI tools to drive operational productivity. While leaning into these capabilities, team members must maintain our ethical standards: thoroughly verifying AI-generated outputs, safeguarding sensitive data, and strictly prohibiting the generation of synthetic media or the use of another individual’s likeness without explicit consent.

We value diversity here at ePayPolicy and understand the importance of creating a safe and comfortable work environment, encouraging individualism and authenticity in every member of our team. We strive to create an accessible and inclusive experience for all candidates. If you need an accommodation during the application or recruiting process, please submit a request to our team via this Interview Accommodation form: https://forms.gle/xKppyKTSqfTUi7hz5

Skills Required

  • 3-5+ years of hands-on experience in application security, security engineering, or penetration testing within a modern SaaS or cloud environment
  • Expertise in manual web application penetration testing and API security assessments
  • Experience using security tools
  • Hands-on experience configuring and tuning SAST, SCA, or DAST tools
  • Strong understanding of OWASP Top 10
  • Knowledge of OAuth2, OIDC, JWT, CORS, and CSP
  • Experience with edge WAF management
  • Experience integrating security checks into automated CI/CD pipelines
  • Strong communication and collaboration skills with software developers and engineering leadership
  • OSCP, GWAPT, eWPT, CISSP, or Azure Security Engineer Associate certification
  • Familiarity with Terraform and Infrastructure-as-Code
  • Familiarity with Docker and Kubernetes container security

What the Team is Saying

Evy
Andrew
Omar
Roger
Jorge
Haley
Gopal
Kim
Christian
Divyesh
Juanita
Tyler
Robin
Koula
Jen
Sheena
Melanie
Matthew
Naresh
Zak
Deanna
Isaac
Hersson
Sushma
Alex
Navar

ePayPolicy Compensation & Benefits Highlights

  • Healthcare Strength Health coverage includes medical, dental, and vision with immediate start, supplemented by mental‑health benefits, HSA/FSA options, and pet insurance. These elements indicate robust healthcare support from day one.
  • Leave & Time Off Breadth Time off is positioned as flexible, with flexible PTO, paid holidays and sick time, and paid volunteer days via #ePayItForward. This breadth supports work‑life balance and community engagement.
  • Parental & Family Support Family support is highlighted through generous parental leave, a dedicated Mother’s Room, family medical leave, and a structured return‑to‑work program. Company‑sponsored family events further reinforce a family‑friendly environment.

ePayPolicy Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Austin, TX
155 Employees
Year Founded: 2014

What We Do

ePayPolicy offers easier payment tools, built just for insurance. ePayPolicy's products bring insurance payments up to speed for agencies, carriers, MGAs and PFCs, with secure online payment pages, automated check processing, accounting reconciliation and more. 11,000+ insurance companies trust ePayPolicy and their expert support team to handle their payments every day.

Why Work With Us

ePayPolicy is the only payment platform built by insurance pros, for insurance pros. We’re a "unicorn" culture where autonomy meets impact. Our team thrives on "No Ego, Amigo" and genuine collaboration. If you want your ideas supported and your work to make a tangible difference in a supportive, innovative environment, you belong here.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

ePayPolicy Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Our hybrid approach captures the best of both worlds by providing flexibility with the chance to connect face to face & feel part of something larger.

Typical time on-site: Flexible
HQAustin, TX
The office sits in the shadow of the Pennybacker bridge, with direct access to, and amazing views of Lake Austin.

Similar Jobs

ePayPolicy Logo ePayPolicy

Integrations Specialist - Level II

Fintech • Insurance • Payments • Software
Hybrid
Austin, TX, USA
155 Employees

ePayPolicy Logo ePayPolicy

Customer Support Representative

Fintech • Insurance • Payments • Software
Hybrid
Austin, TX, USA
155 Employees

ePayPolicy Logo ePayPolicy

Artificial Intelligence Engineer

Fintech • Insurance • Payments • Software
Hybrid
Austin, TX, USA
155 Employees

ePayPolicy Logo ePayPolicy

Customer Experience Analyst

Fintech • Insurance • Payments • Software
Hybrid
Austin, TX, USA
155 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account