DevSecOps Engineer

ePayPolicyAustin, TX
Hybrid

About The Position

Every day, ePayPolicy helps over 10,000 insurance companies speed up incoming and outgoing payments. By helping them move from manual, outdated forms of payment collection to modern payment tools, we help their companies work faster and more efficiently. Our secure, online ACH and credit card payment page is the core product for many of our companies. But we also provide an integrated suite of helpful features for insurance companies of all sizes, including point-of-sale financing, payables network tools, and check reconciliation, all within a single dashboard. Our expert, live support team helps deliver exceptional care every day, with an industry-leading 97% customer retention rate. Founded in 2014, our growing team is based in Austin, TX, and has clients in all 50 US states. We’ve grown over 300% in the last three years - with big plans for the future. At ePayPolicy, we’re helping make payments easier for an entire industry by building intuitive, modern financial tools for insurance. Founded in 2014, our goal has always been to eliminate outdated, inefficient payment methods by offering a secure, seamless digital payment platform for insurance carriers, agencies, MGAs, and premium finance companies. Recognized as a Best Place to Work in Austin, we are driven by innovation, trust, and a commitment to keeping our platform fast and secure. Whether we are launching new features or scaling our platform, ePayPolicy is an exciting environment for independent thinkers who love a good challenge and are ready to make a high-impact contribution. We are looking for a DevSecOps Engineer to join our Information Security team. In this role, you will bridge the gap between Security and Engineering, ensuring our SaaS payment platform remains secure by design without sacrificing development velocity or innovation speed. Reporting directly to the Head of Information Security, you will serve as a trusted technical partner to our engineering teams. You will own application security guardrails and tooling (SAST/SCA), lead targeted internal web application penetration testing for high-risk releases, manage edge security controls (Cloudflare WAF), and collaborate closely with our Tech Debt and Platform teams to systematically triage and remediate vulnerabilities.

Requirements

  • 3–5+ years of hands-on experience in Application Security, Security Engineering, or Penetration Testing within a modern SaaS or cloud environment.
  • Demonstrated expertise in manual web application penetration testing, API security assessments, and using security tools.
  • Hands-on experience configuring and tuning SAST, SCA, or DAST tools.
  • Strong understanding of web security concepts (OWASP Top 10, modern authentication protocols like OAuth2/OIDC, JWT, CORS, CSP).
  • Experience with edge WAF management and integrating security checks into automated CI/CD pipelines.
  • Strong communication skills with an ability to act as a partner—not a blocker—to software developers and engineering leadership.

Nice To Haves

  • Relevant industry certifications (e.g., OSCP, GWAPT, eWPT, CISSP, Azure Security Engineer Associate).
  • Familiarity with Infrastructure-as-Code (Terraform) and container security (Docker, Kubernetes).

Responsibilities

  • Maintain, tune, and optimize static analysis (Sonar) and software supply chain scanning tools (NPM/PyPI scanners) to eliminate noise, build developer trust, and enforce actionable quality gates.
  • Embed automated security checks seamlessly into GitHub Actions / GitLab CI pipelines, minimizing build latency while catching vulnerabilities prior to production release.
  • Proactively triage zero-day package dependencies and software supply chain risks, establishing clear, prioritized remediation paths for engineering teams.
  • Perform hands-on manual penetration testing and security assessments on high-risk feature releases, APIs, and web application workflows.
  • Evaluate complex business logic, authentication flows, and authorization boundaries for flaws that automated scanners miss.
  • Produce clear, reproducible Proof-of-Concept (PoC) demonstrations to help developers understand vulnerability impact and guide effective fixes.
  • Audit codebases for exposed credentials/secrets and assist in vault workflows. Support the rollout of Infrastructure-as-Code (IaC) scanning as the security program expands.
  • Partner directly with the Tech Debt and Platform Engineering teams on a monthly cadence to review, prioritize, and burn down security vulnerabilities according to SLA targets.
  • Translate scanner outputs and pen test findings into actionable tickets complete with reproduction steps, context, and clear fix recommendations.
  • Track and report key performance metrics—such as Mean Time to Remediate (MTTR), scan coverage, and open high/critical risks—for joint Security and Engineering reviews.
  • Act as the primary technical escalation point for dependency alerts, exposed credentials, and edge anomaly detections.
  • Review, validate, and triage externally submitted security reports before passing verified findings to engineering.

Benefits

  • Competitive salary
  • Comprehensive benefits package with employer-paid basic life and disability premiums
  • 401K
  • Flexible Paid Time Off Policy (FTO)
  • Company-sponsored quarterly “ePayItForward” initiatives
  • Supportive and inclusive company culture with a focus on work/life balance
  • Fully-stocked kitchen
  • Lunch stipend when working onsite
  • Open communication
  • Huge opportunity for growth
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service