Senior DevSecOps Engineer
Job description
About the role
Virtuous is on the lookout for a Senior DevSecOps Engineer to elevate the security posture of our products, cloud infrastructure, and software delivery frameworks. In this position, you will work closely with diverse engineering and security teams to weave security practices into every phase of software development and operational processes. The primary focus of this role is to tackle security challenges through coding, automation, and engineering within a DevOps setting.
Key facts
What you'll do
- Design and refine secure architectures for Azure cloud environments, ensuring that networking and governance are scalable and inherently secure.
- Fortify cloud security by implementing infrastructure hardening techniques, segmentation, secure connectivity, Role-Based Access Control (RBAC), Privileged Identity Management (PIM), Azure Policy, and automated security guardrails.
- Improve security visibility by integrating logging, monitoring solutions, Security Information and Event Management (SIEM) systems, and detection engineering practices.
- Identify and mitigate security vulnerabilities in application architecture, authentication mechanisms, APIs, and data flows throughout the entire product lifecycle.
- Incorporate security measures into Continuous Integration/Continuous Deployment (CI/CD) pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), dependency scanning, secrets management, and software supply chain security.
- Lead initiatives in threat modeling, conduct architecture reviews, and facilitate secure design discussions to proactively identify potential risks.
- Develop developer-friendly security guardrails and automation tools that enhance security without hindering delivery timelines.
- Ensure prompt remediation of security issues by offering guidance and establishing secure-by-default patterns for engineering teams.
- Minimize security backlogs, address cloud governance discrepancies, eliminate stale permissions, and rectify infrastructure vulnerabilities.
- Balance the need for risk reduction with engineering impact and business objectives when it comes to remediation and standardization efforts.
- Collaborate with security leadership to enhance incident response readiness and operational maturity.
- Modernize legacy systems and enhance security practices related to containers, Kubernetes, and cloud-native technologies.
- Utilize automation, APIs, scripting, and AI-assisted tools to boost security operations and enhance engineering productivity.
- Create self-service capabilities and reusable tools that improve the developer experience while achieving better security outcomes.
- Assess and implement modern engineering practices and emerging technologies to expedite remediation efforts and enhance overall effectiveness.
Requirements
- A minimum of 5 years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related security-focused engineering roles within cloud-native Software as a Service (SaaS) environments.
- Proven expertise in designing, securing, and modernizing Azure environments, including networking, governance, RBAC/PIM, Azure Policy, and secure connectivity.
- Experience in enhancing application security through secure Software Development Life Cycle (SDLC) practices, threat modeling, and implementing security controls in CI/CD pipelines.
- Practical experience in deploying DevSecOps capabilities such as SAST, DAST, dependency scanning, secrets management, and software supply chain security.
- Familiarity with Kubernetes, Docker, container security, Infrastructure as Code (IaC), and contemporary cloud-native platforms.
- Hands-on experience with GitHub, GitHub Actions, GitHub Advanced Security (or similar tools), SIEM platforms, observability tools, and cloud security technologies.
- Strong skills in automation, scripting, troubleshooting, and cross-functional collaboration, with a focus on scalable solutions.
- Experience with AI-assisted engineering tools (e.g., GitHub Copilot, Claude Code) and a keen interest in leveraging automation and emerging technologies for security improvements.
Nice to have
- Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST.
- Experience with security incident response and management.
- Knowledge of threat intelligence and vulnerability management tools.
- Familiarity with agile methodologies and DevOps practices.
- Experience in mentoring junior team members or leading security training initiatives.
Skills & tools
- Proficiency in Azure cloud services and security features.
- Strong understanding of security protocols and standards.
- Experience with programming and scripting languages such as Python, Bash, or PowerShell.
- Familiarity with configuration management tools like Terraform or Ansible.
- Knowledge of container orchestration and security best practices.
Practical notes
The benefits package includes unlimited paid time off (PTO), paid volunteer days, company holidays, and employer-contributed healthcare options (medical, dental, vision) with Health Savings Account (HSA) and Flexible Spending Account (FSA) options. Additionally, the company offers 12 weeks of fully paid primary parent leave and 4 weeks of fully paid secondary parent leave, including for adoption. All official communication from Virtuous will originate from the @virtuous.org domain.
About the company
Virtuous is on a mission to inspire global generosity by helping nonprofits build better relationships with their donors. We offer a modern software platform that provides mid-sized charities with elegant tools for fundraising, marketing, volunteerism, and online giving.