Role Description
We are looking for a Senior DevSecOps Engineer (Vulnerability & Fleet Management) to design, build, and operate security controls as reliable, automated internal services across our cloud and infrastructure. This role is an exciting opportunity to take full engineering ownership of our Vulnerability Management and Fleet Security capabilities, shifting security from manual gatekeeping to a scalable, self-service platform.
What You Will Be Doing:
-
Own Vulnerability Management End-to-End:
Design and operate scanning pipelines across infrastructure and containers (Nessus, Trivy or equivalent), managing CVE correlation, asset ownership mapping, and remediation SLAs.
-
Manage Infrastructure Fleet Security:
Oversee fleet inventory, policy coverage, and configuration drift using tools like osquery or FleetDM-class solutions.
-
Build Smart Noise Reduction & Automation:
Develop correlation logic linking vulnerabilities to business criticality and exploitability (CVSS/EPSS), and automate lifecycle operations (onboarding, asset reconciliation, exception workflows).
-
Deliver Self-Service Security Products:
Build APIs, dashboards, and ChatOps/Slack integrations that allow platform and engineering teams to consume security controls independently.
-
Codify Security Standards:
Define machine-checkable security standards and ensure audit-ready compliance evidence is produced automatically as a byproduct of system operations.
-
Collaborate for Operational Resilience:
Partner directly with SOC, Infrastructure, and Platform teams to validate controls in production while protecting developer experience.
Qualifications
-
Senior Platform Mindset:
You think like a Platform Engineer building tools for internal customers, prioritizing developer experience and automated prevention over manual queue clearing.
-
Tooling & Program Ownership:
Hands-on experience running program-level infrastructure scanning (Nessus, Qualys, Tenable) and container image security (Trivy or similar).
-
Fleet & Cloud Infrastructure:
Proven experience with fleet inventory systems (osquery, FleetDM) alongside cloud platforms (AWS preferred) and containerized/Kubernetes environments.
-
Automation & Engineering Fundamentals:
Strong scripting ability in Python, Go, or Bash, with solid experience building custom APIs, dashboards, or system integrations.
-
Vulnerability & Risk Judgment:
Deep understanding of CVEs, CVSS/EPSS scoring, and remediation workflows—with the practical judgment to know when theoretical frameworks don't match production reality.
Requirements
-
Nice to have:
Experience integrating security gates into modern CI/CD pipelines (GitLab CI, GitHub Actions).
-
Exposure to Kubernetes admission control and Policy-as-Code frameworks (Kyverno, OPA).
-
Background in automating compliance evidence collection for standards like PCI DSS, SOC 2, or ISO 27001.
-
Proven track record of evolving a security function from manual reviews toward platform ownership.
Benefits
-
Remote-first, trust-based culture.
-
True flexibility with no fixed 9-to-5 schedule.
-
Extra time off including your birthday as a holiday, 10 personal days, and seven sick days without paperwork.
-
Work that matters with a mission to build a digital world that is secure, accessible, and inclusive.
-
Fair and transparent compensation, benchmarked to the market.
-
Truly global team working across continents and time zones.
-
Growth built in with clear goals and personal development plans.
-
Celebrating your big moments with financial bonuses for marriage and welcoming a new baby.
-
Team offsites to meet, collaborate, and recharge together.
-
Access to the tools and hardware you need to do your work well.
-
A friendly and open work environment that welcomes individuality and different perspectives.
Company Description
Sumsub is the first AI-powered trust infrastructure for compliance operations at scale. It connects identity and business verification, fraud prevention, transaction monitoring, and risk workflows, helping teams reduce manual work and enter new markets.
Trusted by over 4,000 clients across various sectors, including financial services, crypto, mobility, trading, marketplaces, education, and iGaming.
Sumsub is recognized as a Great Place To Work® in the US and rated 4.3 out of 5 on Glassdoor.