Skip to content

Member of Technical Staff, DevSecOps

180k – 280kSan Francisco, CAHybrid5+ YOE
Summary

Hands-on DevSecOps lead building and hardening security posture for a voice AI platform serving Fortune 500 customers. Focus on shift-left security, compliance automation, and multi-tenant infrastructure.

About the role

What You'll Do

  • Make Vapi's security posture world-class for the enterprise — shift security left, catch regressions during code review and CI, and harden our multi-tenant infrastructure as we onboard the Fortune 500.
  • Build automation as a security primitive — including agentic systems that run penetration tests against staging ahead of every release, and that auto-remediate issues as they surface.
  • Own the compliance roadmap end-to-end alongside InfoSec, including Drata and the automations that keep us audit-ready as we expand into new regions and regulated industries.
  • Partner deeply with Engineering, InfoSec, and GRC — building guardrails developers actually use, not ad-hoc controls bolted on after the fact.
  • Be the authority Sales and GTM lean on — giving prospects and enterprise customers the confidence that Vapi's security posture matches the trust they're placing in us.

Who You Are

Must-Haves

  • 5–10 years of engineering experience, with significant time in modern cloud-native SaaS — AWS, Kubernetes, Postgres, and ideally VoIP.
  • Strong understanding of security in a multi-tenant cloud environment serving regulated enterprise customers with many third-party integrations.
  • High proficiency writing and reviewing code — you can ship the fix, not just file the ticket.
  • Invested in shift-left security: catching regressions during code and test, not after production incidents.
  • Collaborative by default — you build guardrails with security, engineering, and GRC partners rather than operating as a lone wolf.
  • Hands-on by preference; comfortable as a senior IC or lead, not looking to step into pure management.

Nice-to-Haves

  • Direct experience securing CI/CD pipelines.
  • Background as a backend software engineer.
  • Experience with compliance frameworks (SOC 2, ISO 27001, HIPAA) and tools like Drata.
  • Familiarity with VoIP / telephony security and the failure modes of real-time systems.

What We Offer

  • Competitive compensation: includes a strong base salary and meaningful equity ownership.
  • Comprehensive health coverage: medical, dental, and vision plans.
  • Flexible time off: take-what-you-need vacation policy with an emphasis on rest and balance.
  • Daily meals: catered lunches and dinners provided for in-office days.
  • Lifestyle & wellness stipends: monthly allowances to support rent, transportation, food, fitness, and mental well-being.
  • Professional development: annual learning stipends for courses, conferences, and upskilling.
  • Team connection: regular offsites, team events, and opportunities to build in-person relationships.
Skills
AWSKubernetesPostgreSQLVoIPDevSecOpsCI/CDSOC 2ISO 27001HIPAADrata
Similar roles at this salary range
All Security Engineering jobs →
Shield AI

Senior Staff Cybersecurity Engineer, Platform Security

Senior technical owner building secure-by-default infrastructure, IaC modules, policy-as-code guardrails, and CI/CD security tooling for cloud and platform engineering teams.

160k – 240kSan Diego, CASecurity EngineeringOn-site7+ YOEGoOPA
Upstart

Principal Security Engineer, Data Security

Principal-level security engineer defining infrastructure security strategy and leading cross-functional efforts to secure cloud, Kubernetes, and developer platforms at scale.

191k – 264kUnited StatesSecurity EngineeringRemote8+ YOEGoAWS
Brex

Senior Application Security Engineer

Senior Application Security Engineer focused on finding vulnerabilities, performing penetration testing, and building security tooling across Brex's platform. Requires 5+ years in application security with strong Python and AI workflow knowledge.

192k – 240kUnited StatesSecurity EngineeringRemote5+ YOEAWSgRPC
Rula

Staff Software Engineer - Trust & Safety

Staff-level engineer to found and lead a new Trust & Safety engineering team, architecting systems to detect fraud, billing anomalies, and credential abuse for a mental healthcare platform.

207k – 243kLos Angeles, CASecurity EngineeringRemote8+ YOESQLAWS
Apollo

Senior Application Security Engineer

Senior individual contributor responsible for strengthening Apollo's secure software development lifecycle, performing application security reviews, threat modeling, vulnerability management, and AI security for product, platform, and AI-powered features.

190k – 273kUnited StatesSecurity EngineeringRemote5+ YOEGCPRuby