
DevSecOps Engineer
Virta Health10 days ago
Base Salary
$179k - $188k/yr
Responsibilities
- Assess and improve security controls across GCP and Kubernetes.
- Integrate secure development practices into the software development lifecycle in partnership with engineering, product, and platform teams.
- Design, implement, and manage security tooling and automation for vulnerability detection, remediation, and compliance verification.
- Evolve IAM strategy, least-privilege access, auditing, and RBAC implementation.
- Improve cloud network security architecture, policies, and controls.
- Establish, document, and communicate security policies, standards, and guidelines.
- Drive vulnerability management and improve incident response preparedness.
- Promote security awareness and best practices across the engineering organization.
Requirements
- Practical experience securing cloud-native applications and infrastructure, particularly in Kubernetes environments; GCP experience is strongly preferred.
- Strong understanding of networking, IAM, encryption, and common web application vulnerabilities such as the OWASP Top 10.
- Hands-on application security experience, including secure coding, vulnerability management, and security testing with SAST, DAST, and IAST; threat-modeling exposure is a plus.
- Proficiency with Terraform and other Infrastructure as Code practices.
- Development experience with Go and/or Python.
- Strong communication skills and the ability to influence technical direction across teams.
- 5–7+ years of experience, including 2+ years at a high-growth startup or similar environment.
Benefits
- Remote-first work arrangement with office hubs in Denver and San Francisco.
- Location-based compensation structure with benefits information available on Virta’s Careers page.
- Security and privacy training provided; the role involves handling HIPAA-governed sensitive patient information.
- Corporate roles are not hired in AK, AR, DE, HI, ME, MS, NM, OK, SD, VT, or WI.