Skip to main content
ePayPolicy logo

DevSecOps Engineer

ePayPolicy
7 hours ago
Full-time
Remote friendly (Austin, TX)
Worldwide

ePayPolicy, a Austin-based fintech, helps more than 10,000 insurance companies speed up payments by moving them from manual forms to modern digital tools. Their core offering is a secure online ACH and credit card payment page, complemented by an integrated suite that covers point-of-sale financing, payables network tools, and check reconciliation within a single dashboard. The team earns positive feedback from customers and has built a strong reputation in the sector.

Founded in 2014, ePayPolicy is headquartered in Austin, TX, with clients across all 50 states. The company has grown more than 300% over the last three years and has ambitious plans for the future. It has been recognized as a Best Place to Work in Austin, and the culture emphasizes innovation, trust and delivering fast, secure tools for the insurance industry. The role sits on the Information Security team, reporting to the Head of Information Security, and is offered on a hybrid schedule in Austin for in-office teammates.

The DevSecOps Engineer is a hands-on security partner to the engineering teams, focused on keeping the SaaS payments platform secure by design without slowing development velocity. This role is a bridge between security and engineering, ensuring guardrails, tooling, and processes keep pace with new features and scale.

The daily security rhythm

You’ll own application security guardrails and tooling, including governance for static analysis and software supply chain scanning, aiming to reduce noise while enforcing meaningful quality gates that developers trust. Security checks are embedded into CI/CD pipelines, with a focus on minimizing build latency while catching vulnerabilities before production. The role also prioritizes proactive supply chain security, triaging dependencies and outlining remediation paths for engineering teams.

In addition, you’ll perform targeted manual testing and security assessments on high-risk features, APIs, and workflows, and you’ll review complex authentication and authorization flows to catch problems automated scanners might miss. When you find issues, you’ll create clear, reproducible PoC demonstrations to help developers understand impact and implement fixes effectively. You’ll work with the Tech Debt and Platform teams to triage vulnerabilities and drive remediation within SLA targets, translating scanner outputs into actionable tickets with steps, context, and concrete recommendations.

You’ll align edge and infrastructure security efforts, auditing code for exposed credentials and supporting vault workflows as the program expands to Infrastructure-as-Code (IaC) scanning. You’ll also review cloud environments for misconfigurations and identity over-grants, contributing to a stronger security posture across compute, networking, and data services. Finally, you’ll participate in threat monitoring, triaging dependency alerts and externally submitted reports before passing verified findings to engineering for action.

Must-have requirements

  • Three to five years of hands-on work in Application Security, Security Engineering, or Penetration Testing within a modern Azure-hosted SaaS environment, including strong familiarity with .NET Framework, .NET 10, and SQL, plus Azure PaaS, serverless, and Cloudflare edge controls
  • Proven ability to perform manual web application testing, API security reviews, and use security tooling with results you can stand behind
  • Direct experience configuring and tuning SAST, SCA, or DAST tools to reduce noise and improve developer trust
  • Solid grasp of web security fundamentals such as OWASP Top 10, OAuth2/OIDC, JWT, CORS, and CSP
  • Experience managing edge WAFs and weaving security checks into automated CI/CD pipelines
  • Strong collaboration and communication skills, with a track record of partnering with developers and leadership to fix security gaps

Bonus points

  • Industry certifications such as OSCP, GWAPT, eWPT, CISSP, or Azure Security Engineer Associate
  • Familiarity with Infrastructure-as-Code, including Bicep

Pay, benefits and practical details

The role comes with a competitive salary and a comprehensive benefits package, including employer-paid basic life and disability premiums, and a 401K plan. The company supports a Flexible Paid Time Off policy and runs quarterly “ePayItForward” initiatives. ePayPolicy emphasizes a supportive, inclusive culture that values work–life balance, and it provides a fully-stocked office kitchen plus a lunch stipend for onsite days. There’s a strong emphasis on open communication and a belief in giving ideas a voice, along with a clear path for growth within the company.

ePayPolicy operates on a hybrid schedule for in-office employees, with standard three days per week in the office. The exact cadence is guided by each team and manager. The company actively supports AI adoption, asking all employees to use approved enterprise AI tools to boost productivity while verifying outputs, protecting sensitive data, and avoiding the creation of synthetic media or using someone else’s likeness without explicit consent.

Diversity is valued, and the organization aims to create a safe, inclusive environment. If you need an accommodation during the application or recruiting process, you can submit a request via the Interview Accommodation form: https://forms.gle/xKppyKTSqfTUi7hz5

Advice for applicants

Lead your resume with the must-have experience the role demands, three to five years in Application Security or a related field within an Azure-hosted SaaS, and hands-on work with .NET Framework, .NET 10, and SQL. Include concrete, results-driven examples that show how you aligned security with engineering goals and delivered tangible improvements.

Demonstrate your must-have skills with clear PoCs or remediation stories. Show how you translated scanner and pentest findings into actionable tickets for developers, including reproduction steps and practical fix guidance you’ve provided in the past.

Prepare for interviews by walking through threat modeling and logic review scenarios, especially around complex authentication and authorization flows. Be ready to discuss how you would approach a high-risk feature release from discovery to remediation, including prioritization and cross-team collaboration.

Ask a thoughtful question about how security guardrails are integrated into CI/CD pipelines today, and what role Cloudflare WAF plays in protecting the production surface. For example, you could inquire about how security checks are balanced with build times and how the team measures success in vulnerability remediation and SLA adherence.