Senior DevSecOps Engineer
WFA Digital Insight
Vytalize Health is looking for a senior‑level DevSecOps engineer who will sit at the intersection of security and delivery pipelines. The role isn’t just about configuring scanners; it demands building reusable tooling that makes security the default path for developers and infrastructure teams. What sets this opening apart is the explicit mandate to embed policy‑as‑code in GitHub, automate AI‑driven triage, and maintain hardening baselines across servers, containers, and workstations. Candidates will work hand‑in‑hand with engineering and IT, translating abstract compliance requirements into concrete, auditable controls. If you thrive on turning security policy into production‑grade automation, Vytalize offers a focused environment where those solutions directly shape the product’s risk posture.
Job Description
Description of the Role The Senior DevSecOps Engineer builds and operates the tooling, automation, and guardrails that embed security into how software is built, deployed, and run. This is a hands-on engineering role focused on CI/CD pipeline security, infrastructure-as-code, cloud configuration, and endpoint tooling. The role works day to day inside engineering and IT workflows, writing automation, tuning scanners, and driving fixes with the teams that own the code and infrastructure. Security policy, risk, and compliance requirements are set by the Information Security team; this role translates them into working technical controls. AI capabilities, including AWS AI services and Claude, are used to scale triage, remediation, and reporting. Essential Functions of the Role Secure Pipeline & SDLC Engineering: - Build and maintain security tooling in CI/CD pipelines, including SAST, DAST, software composition analysis, secret scanning, and container image scanning.
- Implement policy-as-code gates, branch protections, and build and artifact integrity controls in GitHub.
- Conduct threat modeling and secure design reviews for applications, services, and pipelines.
- Scan infrastructure-as-code before deployment and remediate configuration drift and unintended network exposure. Vulnerability Remediation Engineering: - Operate the vulnerability scanning stack across GitHub, AWS Inspector, Microsoft Defender, and CrowdStrike Falcon, including deployment, coverage, tuning, and integrations.
- Triage findings, eliminate false positives, and work directly with engineering and IT owners to land fixes within defined SLAs.
- Automate patching, dependency upgrades, and remediation workflows wherever possible.
- Develop hardening baselines for servers, containers, and developer workstations, and automate their deployment. Secrets & Pipeline Identity: - Implement secrets management and short-lived credential patterns, such as OIDC federation, for build and deployment systems.
- Eliminate long-lived credentials and maintain hygiene of service accounts and pipeline permissions.
- Ensure AI-assisted output is reviewed, auditable, and explainable. Engineering Enablement & Reporting: - Partner with Engineering and IT teams to make the secure path the default path through guidance, documentation, and self-service tooling.
- Produce coverage, remediation, and exception metrics, and supply technical evidence and telemetry to the Information Security team for audit and reporting purposes.
Skills
- Strong hands-on experience with AWS, GitHub Actions, Microsoft Defender, and CrowdStrike Falcon.
- Proficiency in scripting and automation (Python, Bash, or similar) and infrastructure-as-code (Terraform, CloudFormation, or similar).
- Working knowledge of containers and orchestration, including securing container build and runtime.
- Expertise in vulnerability management tooling and application threat modeling.
- Proficiency using AI tools (AWS AI services, Claude) to improve engineering workflows.
- Excellent documentation and communication skills, with the ability to influence engineering teams without direct authority.
How to Stand Out
- Highlight concrete examples of CI/CD security pipelines you built, preferably with GitHub Actions and policy‑as‑code.
- Prepare a short walkthrough of a past vulnerability remediation project, showing detection, triage, and automation.
- Demonstrate familiarity with AWS AI services by describing a prototype or proof‑of‑concept you delivered.
- Include a GitHub or GitLab repository link that showcases Terraform or CloudFormation modules you authored.
- During interviews, be ready to discuss how you balance security rigor with developer velocity.
- Ask about the team’s current security tooling stack to show genuine interest and identify where you can add value.
- Negotiate remote‑work stipend or equipment allowance if not explicitly listed in the offer.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.