DevSecOps Engineer
Build and mature Virta’s application security program by securing GCP and Kubernetes environments, automating vulnerability and compliance processes, and embedding security across engineering. The role requires 5–7+ years of experience, strong cloud and application security expertise, and proficiency with Terraform and Go or Python.
About the job
Responsibilities
- Assess and improve security controls across GCP and Kubernetes.
- Embed secure development practices into the software development lifecycle through shift-left security.
- Design, implement, and manage security tooling and automation for vulnerability detection, remediation, and compliance verification.
- Evolve identity and access management (IAM), including least-privilege access and auditing.
- Improve cloud network security architecture, policies, and controls.
- Establish, document, and communicate security policies, standards, and engineering guidelines.
- Drive vulnerability management and improve incident response preparedness.
- Promote security awareness and best practices across engineering teams.
Requirements
- 5–7+ years of overall experience, including 2+ years at a high-growth startup or similar environment.
- Practical experience securing cloud-native applications and infrastructure, particularly Kubernetes environments.
- Strong understanding of networking, IAM, encryption, and common web application vulnerabilities, including the OWASP Top 10.
- Hands-on application security experience, including secure coding practices, vulnerability management, and security testing with SAST, DAST, and IAST.
- Proficiency with Infrastructure as Code tools, specifically Terraform.
- Development experience with Go and/or Python.
- Strong communication skills and the ability to explain complex security concepts and influence technical direction across teams.
- GCP experience is strongly preferred.
- Threat modeling exposure is a plus.
Compensation
- Annual compensation range: $179,451–$187,900.
- Benefits information is available on the company's careers page.
Skills
GCP, Kubernetes, IAM, Terraform, Go, Python, Owasp Top 10, SAST, DAST, Iast, Vulnerability Management, Network Security, Encryption, Threat Modeling, CI/CD
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.
Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.
The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.