
DevSecOps Engineer
Posted 8 hours ago

Posted 8 hours ago
This is a fully remote position, open to applicants in United States.
• Evaluate security measures within GCP and Kubernetes while enhancing Virta’s security framework.
• Collaborate with Engineering, Product, and Platform teams to embed security best practices throughout the software development lifecycle.
• Create, implement, and oversee security tools and automation for identifying vulnerabilities, remediation efforts, and compliance checks.
• Advance the IAM strategy by promoting least-privilege access and comprehensive auditing procedures.
• Enhance the architecture, policies, and controls related to network security in the cloud setting.
• Develop, document, and disseminate security policies, standards, and guidelines.
• Lead vulnerability management initiatives and bolster incident response readiness.
• Foster security awareness and advocate for best practices within the engineering team.
• Acquire knowledge of Virta’s systems, CI/CD pipelines, security tools, and cloud configurations during the initial 90 days.
• Assess IAM/RBAC, data security measures, network controls, and security policies, then initiate foundational security improvement and automation projects.
• Comprehensive understanding and hands-on experience in securing cloud-native applications and infrastructure, especially in Kubernetes settings.
• Experience with GCP is highly preferred.
• Strong knowledge of networking principles, identity management (IAM), encryption, and prevalent web application vulnerabilities, including OWASP Top 10.
• Practical application security experience, encompassing secure coding methodologies, vulnerability management, and security testing (SAST, DAST, IAST).
• Familiarity with threat modeling is an advantage.
• Proficient in Infrastructure as Code tools, particularly Terraform.
• Development experience in Go and/or Python.
• 5–7+ years of professional experience, including a minimum of 2 years in a high-growth startup or similar environment.
• Ability to effectively communicate complex security concepts to varied audiences and influence technical direction across teams.
• Expected to adhere to Virta's security and privacy protocols for HIPAA-regulated patient information.
• Remote-first work environment.
• Office hubs located in Denver and San Francisco.
• Training in security and privacy practices.
• Equal employment opportunity protections.
4Pharma Ltd
4Pharma Ltd
Verity Group
Segware
Get handpicked remote jobs straight to your inbox weekly.