Senior DevSecOps Engineer @Virtuous
Devops
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2mths ago

[Hiring] Senior DevSecOps Engineer @Virtuous

2mths ago - Virtuous is hiring a remote Senior DevSecOps Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

Virtuous is hiring a Senior DevSecOps Engineer to strengthen the security posture of our products, cloud infrastructure, and software delivery ecosystem. Reporting to the Director of IT & Security, you'll partner with Engineering, Cloud Engineering, DevOps, Architecture, and Security teams to build security into the way we design, develop, deploy, and operate software. You'll improve the security of our products and cloud environment by reducing security debt, modernizing security practices, and building secure-by-default solutions through automation and engineering.

This role is embedded within a collaborative DevOps function and is ideal for someone who enjoys solving security problems through code, automation, and engineering rather than manual reviews or gatekeeping. We're looking for an engineer who is naturally curious, challenges conventional approaches, and safely leverages AI-assisted tooling and modern engineering practices to create scalable, high-impact solutions.

Responsibilities

  • Security Engineering & Cloud Security
    • Design, implement, and continuously improve secure Azure cloud architectures, networking, governance, and infrastructure to support scalable, secure-by-default engineering.
    • Strengthen cloud security posture through infrastructure hardening, segmentation, secure connectivity patterns, RBAC/PIM, Azure Policy, and automated guardrails.
    • Improve security visibility through logging, monitoring, SIEM integrations, detection engineering, and operational security tooling.
    • Continuously assess and remediate cloud security risks, inherited infrastructure weaknesses, configuration drift, and operational security gaps.
    • Embed security into infrastructure, platforms, and engineering workflows by collaborating with Cloud Engineering and DevOps teams to build secure-by-default solutions.
  • Application Security & DevSecOps
    • Identify and address security risks in application architecture, authentication, APIs, and data flows throughout the product lifecycle.
    • Integrate security capabilities into CI/CD pipelines and engineering workflows, including SAST, DAST, dependency scanning, secrets management, software supply-chain security, and policy-based controls.
    • Lead threat modeling, architecture reviews, and secure design discussions to identify security risks early in the software development lifecycle.
    • Build developer-friendly security guardrails, reusable patterns, and automations that improve security without slowing delivery velocity.
    • Drive timely remediation of security findings by enabling engineering teams with practical guidance, automation, and secure-by-default patterns.
  • Security Modernization & Operational Excellence
    • Lead efforts to reduce security backlog, cloud governance drift, stale permissions, infrastructure weaknesses, technical debt, and operational security risk.
    • Balance risk reduction, engineering impact, and business priorities when determining what to remediate, standardize, automate, or defer.
    • Collaborate with Security leadership to improve incident readiness, operational maturity, security visibility, and organizational resilience.
    • Help modernize inherited systems while improving container security, Kubernetes security, and secure cloud-native engineering practices.
  • Automation, AI & Engineering Enablement
    • Leverage automation, APIs, scripting, AI-assisted tooling, and emerging technologies to improve security operations, engineering productivity, and organizational effectiveness.
    • Continuously challenge traditional approaches by identifying opportunities to automate, simplify, or reimagine security and engineering workflows.
    • Build self-service capabilities, reusable tooling, and scalable workflows that improve developer experience while strengthening security outcomes.
    • Evaluate and adopt modern engineering practices, AI-assisted workflows, and emerging technologies that improve security outcomes, accelerate remediation, and increase engineering effectiveness.
    • Act as a force multiplier across Security, Engineering, and Cloud Operations by creating systems that increase organizational leverage and effectiveness.

Qualifications

  • 5+ years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related security-focused engineering roles within cloud-native SaaS environments.
  • Strong experience designing, securing, and modernizing Azure environments, including Azure networking, governance, RBAC/PIM, Azure Policy, and secure connectivity patterns.
  • Experience improving application security through secure SDLC practices, threat modeling, CI/CD security controls, and engineering partnership.
  • Hands-on experience implementing DevSecOps capabilities such as SAST, DAST, dependency scanning, secrets management, software supply-chain security, and policy automation.
  • Experience with Kubernetes, Docker, container security, IaC, and modern cloud-native platforms.
  • Hands-on experience with GitHub, GitHub Actions, GitHub Advanced Security (or equivalent), SIEM platforms, observability tooling, and cloud security technologies.
  • Strong automation, scripting, troubleshooting, and cross-functional collaboration skills, with a focus on scalable solutions and operational improvement.
  • Experience leveraging AI-assisted engineering tools (such as GitHub Copilot, Claude Code, or similar) and a demonstrated curiosity for applying automation and emerging technologies to improve security and engineering outcomes.

Benefits

  • Market competitive pay leveraging Carta data.
  • Employee recognition through Bonusly (birthdays, anniversaries, achievements, etc.).
  • 401(k) retirement plan with company matching - 50% match up to 6% of compensation after 90 days.
  • Unlimited PTO to support work-life balance.
  • Supportive time off including paid volunteer days and company holidays.
  • Employer-contributed healthcare benefits, encompassing medical, dental, and vision coverage, with plans available for dependents and choices for Health Savings Accounts (HSA) and Flexible Spending Accounts (FSA).
  • 12 weeks primary parent leave, 4 weeks secondary parent leave - full pay (adoption as well).
  • Community-focused company outings and events.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior DevSecOps Engineer @Virtuous
Devops
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,048+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later