Skip to content
VapiVapi

Member of Technical Staff, DevSecOps

Hands-on DevSecOps lead building and hardening security posture for a voice AI platform serving Fortune 500 customers. Focus on shift-left security, compliance automation, and multi-tenant infrastructure.

About the job

What You'll Do

  • Make Vapi's security posture world-class for the enterprise — shift security left, catch regressions during code review and CI, and harden our multi-tenant infrastructure as we onboard the Fortune 500.
  • Build automation as a security primitive — including agentic systems that run penetration tests against staging ahead of every release, and that auto-remediate issues as they surface.
  • Own the compliance roadmap end-to-end alongside InfoSec, including Drata and the automations that keep us audit-ready as we expand into new regions and regulated industries.
  • Partner deeply with Engineering, InfoSec, and GRC — building guardrails developers actually use, not ad-hoc controls bolted on after the fact.
  • Be the authority Sales and GTM lean on — giving prospects and enterprise customers the confidence that Vapi's security posture matches the trust they're placing in us.

Who You Are

Must-Haves

  • 5–10 years of engineering experience, with significant time in modern cloud-native SaaS — AWS, Kubernetes, Postgres, and ideally VoIP.
  • Strong understanding of security in a multi-tenant cloud environment serving regulated enterprise customers with many third-party integrations.
  • High proficiency writing and reviewing code — you can ship the fix, not just file the ticket.
  • Invested in shift-left security: catching regressions during code and test, not after production incidents.
  • Collaborative by default — you build guardrails with security, engineering, and GRC partners rather than operating as a lone wolf.
  • Hands-on by preference; comfortable as a senior IC or lead, not looking to step into pure management.

Nice-to-Haves

  • Direct experience securing CI/CD pipelines.
  • Background as a backend software engineer.
  • Experience with compliance frameworks (SOC 2, ISO 27001, HIPAA) and tools like Drata.
  • Familiarity with VoIP / telephony security and the failure modes of real-time systems.

What We Offer

  • Competitive compensation: includes a strong base salary and meaningful equity ownership.
  • Comprehensive health coverage: medical, dental, and vision plans.
  • Flexible time off: take-what-you-need vacation policy with an emphasis on rest and balance.
  • Daily meals: catered lunches and dinners provided for in-office days.
  • Lifestyle & wellness stipends: monthly allowances to support rent, transportation, food, fitness, and mental well-being.
  • Professional development: annual learning stipends for courses, conferences, and upskilling.
  • Team connection: regular offsites, team events, and opportunities to build in-person relationships.

Skills

AWS, Kubernetes, Postgres, Voip, DevSecOps, CI/CD, SOC 2, ISO 27001, HIPAA, Drata

Onebrief

Onebrief

United States

Corporate Security Systems Engineer
$180k+/yrRemote4+ YOESecurity Engineering

Own and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.

Exa

Exa

San Francisco, CA

Security Engineer
$180k+/yrOn-siteSecurity Engineering

The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Huntress

Huntress

United States

QMS Manager
$185k+/yrRemote5+ YOESecurity Engineering

Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.

Glean

Glean

United States

Platform Security Engineer
$185k+/yrRemote5+ YOESecurity Engineering

Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.