Staff DevSecOps Engineer

Red Ventures

United States

Hybrid

USD 180,000 - 240,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid Schedule
Flexible PTO
Mentorship Culture
Purpose & Community
World-Class Wellness

Job summary

Red Ventures is seeking a Senior Security Engineer to own the engineering side of our SOC 2 Type 2 compliance program and drive security across our developer platforms. You will design and implement automation for evidence collection, CI/CD security gates, and AI-assisted remediation, shaping secure-by-default infrastructure and protecting multi-cloud environments.

Hybrid work arrangement with strong emphasis on security governance, automation, and collaboration with product and platform teams

Qualifications

  • 5+ years in security engineering, DevSecOps, or platform engineering with a security focus.
  • Staff level: 8+ years with a track record of building security functions or programs.
  • Deep hands-on cloud security experience across major cloud providers.

Responsibilities

  • Own the engineering side of our SOC 2 Type 2 compliance program: controls, evidence, audit readiness.
  • Operate our compliance automation platform: integrations, evidence pipelines, mapping controls to implementation.
  • Productize compliance: policy-as-code, automated evidence generation, and guardrails.
  • Own cloud security posture management and runtime security tooling across our environment.
  • Triage and remediate findings with SLA-driven automation and AI-assisted remediation.

Skills

Cloud security
Automation coding
Multi-cloud security
Terraform / IaC
Security monitoring

Tools

CSPM
ASPM/SAST
Secret scanning
SBOM generation
Drata / Vanta / Snyk
Terraform

Job description

  • Own the engineering side of our compliance program (SOC 2 Type 2): implementing controls, collecting evidence, and keeping us audit-ready
  • Operate our compliance automation platform — integrations, evidence pipelines, and mapping controls to real implementation
  • Productize compliance: policy-as-code, automated evidence generation, and guardrails so passing audits doesn’t slow product delivery
  • Own cloud security posture management and runtime security tooling: posture monitoring, container and IaC scanning, and runtime coverage across our environment
  • Triage and remediate findings against demanding SLAs, and design the automation and alerting that keeps pace with volume manual effort can’t
  • Build auto-remediation workflows — including AI-assisted pipelines — that detect, file, and (where safe) fix findings with minimal human intervention
  • Build and maintain CI/CD security gates: SAST/SCA, secret scanning, SBOM generation, dependency management, and container/IaC scanning — implemented as reusable pipeline components and enforced through automated policy
  • Encode security and compliance controls into infrastructure-as-code and policy-as-code so the easy path is the secure path
  • Help close the prototype-to-production gap: turn fast-moving prototypes into production-grade, secure-by-default systems with automated guardrails
  • Make secure-by-default the norm through our internal tooling, so the right controls are applied automatically rather than relying on engineers to remember
  • Build the automation the team runs on — reusable modules, pipeline components, and AI/agentic tooling that turn manual security work into self-service capability
  • Partner with corporate security and GRC functions while building and maturing our in-house security capability, so the team can make sound security decisions quickly and independently
Benefits
  • Hybrid Schedule & Flexible PTO: Take advantage of 3-4 days in-office per week and 1-2 WFH days per week (varying by team), and a robust Paid Time Off program that includes logging off for “Winter Week.”
  • Family Support, Planning, and Fertility: Our benefit offerings support every unique path to parenthood including fertility, egg freezing, adoption, surrogacy, parental bonding, and more.
  • Mentorship Culture: Find a mentor, be a mentor, say yes to something new. This is a place where you’re guaranteed to build connections that extend past your immediate team and even your tenure at RV.
  • Purpose & Community: We empower employees to make an impact for causes they care about, and we invest heavily in systemic impact through nonprofits like Road to Hire.
  • World-Class Wellness: In addition to the on-site amenities at HQ, our unique wellness benefits include free therapy sessions and counseling for U.S. employees and family members.
  • Security monitoring and detection/alerting design
  • Fluency with the categories of modern cloud security tooling — CSPM, ASPM/SAST and secret scanning, compliance automation, and SIEM (e.g., tools such as Wiz, Prisma Cloud, Snyk, Drata, Vanta, or equivalents)
  • Experience standing up or maturing an in-house security function
  • Strong coding/scripting ability to build automation, not just configure tools — you write the pipelines, modules, and tooling that scale security across many services
  • Multi-cloud exposure and experience securing an internal developer platform
  • Strong infrastructure-as-code skills, especially Terraform, including policy-as-code
  • Experience applying AI/LLM tooling to security operations — auto-remediation, evidence generation, agentic workflows
  • Hands‑on vulnerability management at scale: triage, prioritization, SLA-driven remediation, and the automation to make it sustainable
  • Proven CI/CD security experience: building pipeline security controls (SAST/SCA, secret scanning, dependency and container scanning) into developer workflows
  • Working knowledge of SOC 2 (or comparable frameworks) and what it takes to implement and evidence controls in a real engineering environment
  • 5+ years in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus (Staff level: 8+ years and a track record of building security functions or programs)
  • Deep hands‑on cloud security experience (compute, networking, IAM, key management, logging) on a major cloud provider
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff DevSecOps Engineer
Staff DevSecOps Engineer

Bankrate • United States

Hybrid
USD 150,000 - 225,000
Health Insurance
Life Insurance
Disability Insurance
+6
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • Northern (KY)

Hybrid
USD 120,000 - 160,000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+3
Security Compliance Analyst
Security Compliance Analyst

Harbinger Motors • Garden Grove (CA)

On-site
USD 110,000 - 160,000
Stock options
Flexible PTO
Health coverage
+2
Cloud Security Engineer
Cloud Security Engineer

YGO GmbH • United States

Remote
USD 140,000 - 190,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Bankrate • United States

Hybrid
USD 120,000 - 180,000
Sr. CyberSecurity Engineer
Sr. CyberSecurity Engineer

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Security Operations Engineer
Security Operations Engineer

Yellow Card • Tulsa (OK)

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

Sperry Rail, Inc. • Shelton (CT)

On-site
USD 110,000 - 170,000
Systems & Security Engineer
Systems & Security Engineer

Fairly Inc. • Portland (OR)

Hybrid
USD 120,000 - 180,000
Collaborative environment
Impactful role in growth
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Virtuous • United States

Remote
USD 150,000 - 190,000
Competitive pay and Carta data-based另外
Bonus and recognition (Bonusly)
401(k) with company matching
+5