Senior DevSecOps & Network Infrastructure Engineer

KWI

Melville (NY)

Hybrid

USD 165,000 - 175,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Full Medical, Dental and Vision
Annual bonus eligible
Free gym in the building
Generous PTO policy
Tuition Reimbursement
401(K) with company match
Employee Referral Program

Job summary

KWI is seeking a senior systems engineer to design, secure, and run our on-prem infrastructure powering a unified commerce platform for luxury brands. You will manage VMware vSphere, Linux VMs, and Docker workloads across datacenters, while embedding security into CI/CD pipelines and IaC templates.

You will own the network edge, secrets management, incident response, and observability, with a hybrid work model and opportunities to influence architecture at scale.

Qualifications

  • 5+ years operating production Linux/UNIX (RHEL, CentOS/Rocky, Debian/Ubuntu) in on-prem or hybrid at scale.
  • Hands-on enterprise firewall experience (FortiGate/FortiOS; NAT, VIPs, IPsec/SSL VPN)
  • Strong networking fundamentals (TCP/IP, VLANs, DNS, TLS, HTTP/S, load balancing)
  • Production VMware vSphere experience (clusters, hosts, datastores, patches)
  • Docker in production: images, registries, deployment, networking, troubleshooting
  • DevSecOps: CI/CD with security gates, vulnerability management at fleet scale
  • Git, CI/CD pipelines, Ansible/Terraform/OpenTofu, Docker
  • Bash scripting; basic Python, programming fundamentals

Responsibilities

  • Design, harden, and operate our on-prem footprint (VMware vSphere, Linux VMs, Docker workloads) across multiple datacenters.
  • Own the network edge: FortiGate policy design, NAT/VIPs, IPsec VPNs, segmentation, IPS/UTM, change control.
  • Build security into the delivery pipeline: container image scanning, SAST, secrets detection, IaC policy checks.
  • Containerize and template services with Docker and IaC for repeatable deployments.
  • Manage secrets and PKI: centralized secrets, internal CA, automated certificate rotation.
  • Own incidents end-to-end: triage, root-cause analysis, post-incident documentation.

Job description

Department: Systems Ops

Employment Type: Full Time

Location: Melville, NY

Reporting To: VP of Infrastructure & Operations

Compensation: $165,000 - $175,000 / year

Description

About KWI

KWI builds the unified commerce platform that powers some of the world's most recognized specialty and luxury retail brands. Behind every transaction, every clienteling interaction, and every store opening is an infrastructure team that keeps the lights on and is continuously raising the bar on how modern, and how secure, that platform runs. This is a role on that team.

The opportunity

If innovation lives in your DNA and AI is already part of how you think, build, and operate, you're going to love what we're doing at KWI. You'll join a small, senior team with a real mandate to design, build, secure, and run the systems that power retail at scale. This is hands-on, on-prem infrastructure work: our own hypervisors, our own network edge, our own containers, and our own pipelines. We move fast, we automate aggressively, and we expect security to be built into the platform rather than bolted onto it. Your fingerprints will be on the platform every day.

The impact you'll make
  • Design, harden, and operate our on-prem footprint: VMware vSphere clusters, Linux virtual machines, and Docker workloads running across multiple datacenters and serving retail clients 24x7.
  • Own the network edge. FortiGate policy design, NAT and VIPs, IPsec site-to-site and remote-access VPN, segmentation, IPS and UTM profiles, and disciplined change control on every rule you touch.
  • Build security into the delivery pipeline. Container image and dependency scanning, SAST, secrets detection, IaC policy checks, signed artifacts, and vulnerability findings you drive to closure instead of to a spreadsheet.
  • Containerize and template services with Docker and infrastructure-as-code so deployments are repeatable, declarative, and boring.
  • Run the secrets and PKI plane: centralized secrets management, an internal certificate authority, automated certificate issuance and rotation, and a standing campaign to get hardcoded credentials out of the environment.
  • Own incidents end to end: triage alerts, drive root-cause analysis across the application, network, database, and hypervisor layers, and write the post-incident docs that stop recurrence.
  • Improve observability across the fleet. Metrics, logs, traces, dashboards, and firewall and flow telemetry, so problems are seen before customers feel them.
  • Support audit, compliance, and penetration-test work: evidence collection, remediation SLAs, access reviews, and hardening baselines that hold up under scrutiny.
  • Use modern AI-augmented engineering tools (Claude Code, MCP-based workflows, agentic automation) as a daily multiplier, to operate faster and extend what one engineer can deliver.
  • Document and mentor. Runbooks, network diagrams, and design docs aren't an afterthought here. They're how the team scales.
What you will bring

Required

  • 5+ years operating production Linux/UNIX (RHEL, CentOS/Rocky, Debian/Ubuntu) in an on-prem or hybrid environment at meaningful scale.
  • Hands-on enterprise firewall experience, ideally FortiGate/FortiOS: policy design, NAT and VIPs, IPsec and SSL VPN, routing, HA pairs, and the judgment to change a live rule set safely. Deep Palo Alto or Cisco ASA/Firepower experience plus a genuine willingness to go deep on Fortinet also works.
  • Strong networking fundamentals: TCP/IP, VLANs and segmentation, routing, DNS, TLS, HTTP/S, and load balancing. You can read a packet capture and a certificate chain and say what is actually happening.
  • Production VMware vSphere experience: clusters and hosts, datastores, resource contention, snapshots and templates, and patching without an outage.
  • Docker in production: image builds and hardening, registries, compose-based or orchestrated deployment, container networking, and troubleshooting the container that will not stay up.
  • Practical DevSecOps: CI/CD pipelines with security gates, vulnerability management and CVE remediation at fleet scale, secrets management, and image scanning.
  • Solid DevOps fundamentals: Git, CI/CD pipelines, Ansible (or similar configuration management), Terraform/OpenTofu (or similar IaC), and Docker.
  • Comfortable scripting in Bash. Python is not required, but you should have a working understanding of programming fundamentals and be able to read, modify, and write straightforward code.
  • Strong troubleshooting instincts and the temperament to lead under pressure.

Key skills (we'll weigh heavily)

  • Real day-to-day experience using AI-augmented engineering tools (Claude, Cursor, Copilot, MCP servers, agentic workflows), not just demos.
  • Firewall and network security operations at the edge of a production e-commerce platform: rule hygiene, attack-surface reduction, and closing external pen-test findings.
  • Experience with a centralized secrets manager (HashiCorp Vault, OpenBao, or comparable) and internal PKI or certificate automation.
  • Experience with Datadog, Grafana, or comparable observability platforms.

Nice to have

  • Security certifications such as Fortinet NSE 4 or higher, Security+, CISSP, or OSCP, or equivalent demonstrated depth.
  • Exposure to compliance frameworks that touch retail (PCI DSS, SOC 2) and the evidence work that comes with them.
  • MySQL operational experience: replication, performance tuning, backups, and recovery.
  • Load balancer experience (Kemp/LoadMaster, F5, HAProxy, NGINX), including SSL offload and WAF policy.
  • Multi-datacenter, disaster-recovery, or failover-testing experience.
  • Retail, e-commerce, or POS-adjacent operational experience.
As a member of the KWI team you will receive
  • Full Medical, Dental and Vision
  • Annual bonus eligible
  • Free gym in the building
  • Generous PTO policy
  • Summer Fridays....all year round
  • Tuition Reimbursement
  • Discount from building café
  • 401(K) with a 50% company match (up to 6% of employee contribution)
  • Employee Referral Program
  • (1) Volunteer day each year

Our work space

We understand that our teams need flexibility, which is why we follow a hybrid schedule. Our in-office days of Monday, Tuesday and Thursday, and employees are allowed to work remotely on Wednesdays and Friday.

We are also a collaborative group and believe that getting together in person allows our team to do their best work. Together we enjoy monthly events, bagels every Thursday, a state-of-the-art coffee machine, a full snack pantry and many more surprise and delight moments throughout the year.

Our commitment to you

At KWI, we know that cultivating diversity and fostering an inclusive work environment is critical to our impact and success. We create an environment where no individual is advantaged or disadvantaged because of their background. We offer equal opportunity employment regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability status, age, marital status, or protected veteran status.

With a commitment to maintaining a bias-free environment in which harassment is prohibited, we respect cultural diversity and comply with the laws of the places in which we operate. We expect our business partners, suppliers, clients, and all our team members to uphold these commitments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP of Technical Operations
VP of Technical Operations

KWI • Melville (NY)

Hybrid
USD 180,000 - 240,000
Full Medical, Dental and Vision
Annual bonus eligible
Free gym in the building
+7
Technical Program Manager
Technical Program Manager

KWI • Melville (NY)

Hybrid
USD 135,000 - 140,000
Full Medical, Dental and Vision
Annual bonus eligible
Free gym in the building
+7
Technical Lead
Technical Lead

KWI • Melville (NY)

On-site
USD 153,000 - 187,000
Full Medical, Dental and Vision
Annual bonus eligible
Free gym in the building
+6
Sr Software Engineer
Sr Software Engineer

KWI • Melville (NY)

Hybrid
USD 135,000 - 165,000
Full Medical, Dental and Vision
Annual bonus eligible
Free gym in the building
+4
Application Support Analyst
Application Support Analyst

KWI • Melville (NY)

Hybrid
USD 28,000 - 40,000
Full Medical, Dental and Vision
Annual bonus eligible
Free gym in the building
+7
Head of Finance and Operations
Head of Finance and Operations

KWI • Melville (NY)

On-site
USD 180,000 - 220,000
Full Medical, Dental and Vision
Annual bonus eligible
Free gym in the building
+7
Solutions Consultant
Solutions Consultant

KWI • Melville (NY)

Hybrid
USD 130,000 - 140,000
Full Medical, Dental and Vision
Annual bonus eligible
Free gym in the building
+5
Senior Product Designer
Senior Product Designer

KWI • Melville (NY)

Hybrid
USD 117,000 - 143,000
Full medical, dental and vision
Annual bonus eligible
Free gym in the building
+7
SDET
SDET

KWI • Melville (NY)

On-site
USD 144,000 - 176,000
Full Medical, Dental and Vision
Annual bonus eligible
Free gym in the building
+7
Senior Product Manager
Senior Product Manager

KWI • Melville (NY)

Hybrid
USD 100,000 - 130,000
Full Medical, Dental and Vision
Free gym in the building
Generous PTO policy
+2