
Senior DevSecOps
Posted Jul 25

Posted Jul 25
This is a fully remote position, open to applicants in Alabama, +32 more states.
• Develop, construct, and sustain automated pipelines for the creation of golden images for Linux-based virtual machines and container base images, ensuring CIS hardening standards are enforced during the build process and validating compliance prior to promotion through configuration management tools.
• Establish and oversee automated workflows for Linux patching.
• Create and manage configuration management pipelines to consistently enforce hardened baselines across Linux workloads while detecting and addressing any drift.
• Incorporate security scanning (including vulnerability, secrets, SBOM, and compliance) into CI/CD pipelines.
• Apply policy-as-code controls to enforce security guardrails, preventing non-compliant workloads and misconfigured systems from being deployed to production.
• Take ownership of the golden image factory, from upstream source validation through automated CIS benchmark testing and image promotion gates, encompassing both virtual machine and container images utilized in CI/CD.
• Oversee the lifecycle and distribution of secrets, ensuring that no secrets are embedded in images.
• Address configuration drift, vulnerability notifications, and patch compliance gaps with root-cause analysis and durable automation solutions rather than temporary manual fixes.
• Implement telemetry pipelines to highlight image drift, configuration deviations, and unpatched CVEs in near real-time.
• Over 5 years of experience in DevSecOps, platform engineering, or infrastructure security.
• Strong Linux administration expertise with a comprehensive understanding of CIS benchmarks and hardening practices.
• Experience utilizing configuration management tools in production settings.
• Practical experience with Kubernetes security, including RBAC, network policies, and workload identity.
• Proficient in building CI/CD pipelines that integrate security scanning (for vulnerabilities, secrets, SBOM, and compliance).
• Familiarity with policy-as-code frameworks.
• Knowledge of golden image pipelines for both virtual machines and containers, along with image promotion processes.
• Strong scripting capabilities (Bash, Python) for automation and remediation tasks.
• Experience with observability tools for infrastructure security telemetry.
• Exceptional medical benefits with 100% company-paid premiums for the employee-only plan, plus 100% company-paid dental and vision premiums.
• 401(k) plan that matches 100% up to 4% with immediate vesting.
• Professional development reimbursement of $2,500 annually.
• 11 holidays plus Paid Time Off accrual, rollover plan, and the option to take your birthday off.
• Commitment is valued at Vultr! Increased PTO at the 3-year and 10-year anniversaries, plus a one-month paid sabbatical every 5 years, and an anniversary bonus each year.
• $500 for the first-year remote office setup, with $400 each subsequent year for new equipment.
• Internet reimbursement up to $75 per month.
• Gym membership reimbursement up to $50 per month.
• Company-paid Wellable subscription.
DATAGROUP
Ambush
DuoKey
TEKsystems
Get handpicked remote jobs straight to your inbox weekly.