Senior DevSecOps Engineer

Vultr

United States

On-site

USD 130,000 - 145,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical benefits
Dental & vision coverage
401(k) plan
Professional development reimbursement
Paid time off
Birthday off
Sabbatical program
Remote office setup allowance
Equipment stipend
Internet reimbursement
Gym membership reimbursement
Wellable subscription

Job summary

Vultr is seeking a DevSecOps Engineer to design, build, and secure the automated infrastructure that underpins our cloud platform. You will own the security lifecycle of golden images, Kubernetes clusters, and configuration management pipelines, embedding compliance and hardening at build time, not as an afterthought.

The ideal candidate brings deep expertise in Linux security, container hardening, and policy-as-code, with a bias toward durable automation over manual remediation.

Qualifications

  • 5+ years of experience in DevSecOps, platform engineering, or infrastructure security.
  • Strong Linux administration skills with deep understanding of CIS benchmarks and hardening practices.
  • Experience with configuration management tools in production environments.
  • Hands-on experience with Kubernetes security including RBAC, network policies, and workload identity.
  • Proficiency building CI/CD pipelines with integrated security scanning (vulnerability, secrets, SBOM, compliance).
  • Experience with policy-as-code frameworks.
  • Familiarity with golden image pipelines for VMs and containers, and image promotion workflows.
  • Strong scripting skills (Bash, Python) for automation and remediation.
  • Experience with observability tooling for infrastructure security telemetry.

Responsibilities

  • Design, build, and maintain automated golden image creation pipelines for Linux-based VM and container base images, enforcing CIS hardening standards at build time and validating compliance before promotion through configuration management tooling.
  • Implement and manage automated Linux patching workflows.
  • Build and maintain configuration management pipelines to enforce hardened baselines across Linux workloads, detecting and remediating drift.
  • Integrate security scanning (vulnerability, secrets, SBOM, and compliance) into CI/CD pipelines.
  • Implement policy-as-code controls to enforce security guardrails preventing non-compliant workloads and misconfigured systems from reaching production.
  • Own the golden image factory from upstream source validation through automated CIS benchmark testing and image promotion gates, for VM and container images used in CI/CD.
  • Manage secrets lifecycle and distribution ensuring no secrets are baked into images.
  • Respond to configuration drift, vulnerability alerts, and patch compliance gaps with root-cause analysis and durable automation fixes.
  • Instrument telemetry pipelines to surface image drift, configuration deviation, and unpatched CVEs in near-real time.

Skills

Linux security
Kubernetes security
CI/CD security
Policy as code
Bash
Python
Automation
Observability tooling

Tools

CIS benchmarking
Configuration management
RBAC & network policies
CI/CD pipelines

Job description

Who We Are
Vultr is on a mission to make high-performance cloud infrastructure easy to use, affordable, and locally accessible for enterprises and AI innovators around the world. With 33 global cloud data center locations, Vultr is trusted by hundreds of thousands of active customers across 185 countries for its flexible, scalable, global Cloud Compute, Cloud GPU, Bare Metal, and Cloud Storage solutions. In December 2024 Vultr announced an equity financing at a $3.5 billion valuation. Founded by David Aninowsky and self-funded for over a decade, Vultr has grown to become the world’s largest privately‑held cloud infrastructure company.

Vultr Cares
  • Excellent Medical Benefits w/ 100% company-paid premiums for employee only plan + 100% company-paid dental & vision premiums
  • 401(k) plan that matches 100% up to 4% with immediate vesting
  • Professional Development Reimbursement of $2,500 each year
  • 11 Holidays + Paid Time Off Accrual + Rollover Plan + take your birthday off
  • Commitment matters to Vultr! Increased PTO at 3 year & 10 year anniversary + 1 month paid sabbatical every 5 years + Anniversary Bonus each year
  • $500 first year remote office setup + $400 each following year for new equipment
  • Internet reimbursement up to $75 per month
  • Gym membership reimbursement up to $50 per month
  • Company-paid Wellable subscription
Join Vultr

Vultr is seeking a DevSecOps Engineer to design, build, and secure the automated infrastructure that underpins our cloud platform. You will own the security lifecycle of golden images, Kubernetes clusters, and configuration management pipelines, embedding compliance and hardening at build time, not as an afterthought. The ideal candidate brings deep expertise in Linux security, container hardening, and policy-as-code, with a bias toward durable automation over manual remediation.

Key Responsibilities
  • Design, build, and maintain automated golden image creation pipelines for Linux-based VM and container base images, enforcing CIS hardening standards at build time and validating compliance before promotion through configuration management tooling
  • Implement and manage automated Linux patching workflows
  • Build and maintain configuration management pipelines to continuously enforce hardened baselines across Linux workloads, detecting and remediating drift
  • Integrate security scanning (vulnerability, secrets, SBOM, and compliance) into CI/CD pipelines
  • Implement policy-as-code controls to enforce security guardrails preventing non-compliant workloads and misconfigured systems from reaching production
  • Own the golden image factory from upstream source validation through automated CIS benchmark testing and image promotion gates, covering both VM and container images used in CI/CD
  • Manage secrets lifecycle and distribution ensuring no secrets are baked into images
  • Respond to configuration drift, vulnerability alerts, and patch compliance gaps with root-cause analysis and durable automation fixes rather than one-off manual remediation
  • Instrument telemetry pipelines to surface image drift, configuration deviation, and unpatched CVEs in near-real time
Qualifications
  • 5+ years of experience in DevSecOps, platform engineering, or infrastructure security
  • Strong Linux administration skills with deep understanding of CIS benchmarks and hardening practices
  • Experience with configuration management tools in production environments
  • Hands-on experience with Kubernetes security including RBAC, network policies, and workload identity
  • Proficiency building CI/CD pipelines with integrated security scanning (vulnerability, secrets, SBOM, compliance)
  • Experience with policy-as-code frameworks
  • Familiarity with golden image pipelines for VMs and containers, and image promotion workflows
  • Strong scripting skills (Bash, Python) for automation and remediation
  • Experience with observability tooling for infrastructure security telemetry
Compensation

$130,000 - $145,000

This salary can vary based on location, years of experience, background and skill set.

[We are currently accepting applications from candidates residing in the following states: Alabama, Arizona, Colorado, Connecticut, Florida, Georgia, Idaho, Illinois, Indiana, Iowa, Kentucky, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Montana, Nebraska, Nevada, New Jersey, New Mexico, New York, North Carolina, Ohio, Oklahoma, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Wisconsin.]

Inclusion & Privacy

Vultr is committed to an inclusive workforce where diversity is celebrated and supported. All employment decisions at Vultr are based on business needs, job requirements, and individual qualifications.

Vultr regards the lawful and correct use of personal information as important to the accomplishment of our objectives, to the success of our operations and to maintaining confidence between those with whom we deal and ourselves. As such the use of various key privacy controls enables Vultr’s treatment of personal information to meet current regulatory guidelines and laws.

Workforce members have the right under US state law where and when applicable and certain other privacy and data protection laws, as applicable, to: fair and equal treatment, knowing what personal data we gather and retain, for what purpose, and the ability to access and/or delete such data. You also have the right to opt out of communications from Vultr and approved third- parties at any time.

Inclusion & Privacy

We are an equal opportunity employer and are committed to creating an inclusive environment for all employees. We welcome applications from individuals of all backgrounds and experiences, and we prohibit discrimination based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected status under applicable laws. Vultr will consider qualified applicants with arrest or conviction records in accordance with applicable laws and will not conduct a background check until after an offer of employment has been extended and accepted.

We also take your privacy seriously. We handle personal information responsibly and follow applicable laws, including U.S. privacy rules and India’s Digital Personal Data Protection Act, 2023. Your data is used only for legitimate business purposes and is protected with proper security measures.

Where allowed by law, applicants may request details about the data we collect, access or delete their information, withdraw consent for its use, and opt out of nonessential communications. For more details, please see our Privacy Policy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineering Architect
Senior Security Engineering Architect

Doist • United States

Remote
USD 130,000 - 145,000
100% company-paid insurance premiums
401(k) plan that matches 100% up to 4%
Professional Development Reimbursement
+6
Platform Engineer - Cloud Native
Platform Engineer - Cloud Native

Vultr • United States

On-site
USD 90,000 - 100,000
Senior Linux System Administrator
Senior Linux System Administrator

Vultr • United States

On-site
USD 80,000 - 100,000
Health insurance
401(k) match
Professional Development Reimbursement
+6
Linux Systems Administrator
Linux Systems Administrator

Vultr • United States

Hybrid
USD 60,000 - 75,000
100% company-paid insurance premiums
401(k) matching plan
Professional Development Reimbursement
+4
Platform Engineer - Imaging & Provisioning
Platform Engineer - Imaging & Provisioning

Vultr • United States

Remote
USD 90,000 - 100,000
Insurance premiums
401(k) matching
Professional development
+2
Project Coordinator - Data Center and Network Delivery
Project Coordinator - Data Center and Network Delivery

Vultr • United States

On-site
USD 50,000 - 65,000
Medical, dental, and vision insurance
401(k) 100% match up to 4%
Professional development reimbursement
+5
Senior Linux System Administrator
Senior Linux System Administrator

Webhosting • Northern (KY)

Hybrid
USD 80,000 - 100,000
Health insurance
401(k) with match
Professional development reimbursement
+6
Technical Support Specialist
Technical Support Specialist

Vultr • United States

Remote
USD 34,440 - 41,328
100% company-paid insurance premiums
401(k) plan with matching
Professional Development Reimbursement
+4
Senior Software Engineer, Cloud Networking
Senior Software Engineer, Cloud Networking

Vultr • United States

Remote
USD 128,000 - 145,000
100% company paid medical benefits
401(k) matching
Professional development reimbursement
+4
Senior Technical Project Manager, Data Center & Network Delivery
Senior Technical Project Manager, Data Center & Network Delivery

Vultr • United States

On-site
USD 110,000 - 140,000
100% company-paid insurance premiums for medical, dental, and vision plans
401(k) plan with 100% match up to 4%
Professional Development Reimbursement of $2,500 each year
+6