高级DevSecOps工程师
Senior DevSecOps Engineer
## **职位概述**
Virtuous 正在招聘一名高级 DevSecOps 工程师,以加强我们产品的安全态势、云基础设施和软件交付生态系统。
向 IT 与安全总监汇报,您将与工程、云工程、DevOps、架构和安全团队合作,将安全融入我们设计、开发、部署和运营软件的方式中。您将通过自动化和工程手段,减少安全债务、现代化安全实践,并构建默认安全的解决方案,从而提升产品和云环境的安全性。
此职位嵌入在一个协作的 DevOps 功能中,适合喜欢通过代码、自动化和工程解决安全问题的人,而不是通过手动审查或门控。我们寻找一位天生好奇、挑战传统方法,并安全地利用 AI 辅助工具和现代工程实践来创建可扩展、高影响力的解决方案的工程师。
## **职责**
### **安全工程与云安全**
- 设计、实施并持续改进安全的 Azure 云架构、网络、治理和基础设施,以支持可扩展的默认安全工程。
- 通过基础设施加固、分段、安全连接模式、RBAC/PIM、Azure 策略和自动化防护措施,加强云安全态势。
- 通过日志记录、监控、SIEM 集成、检测工程和操作安全工具,提高安全可见性。
- 持续评估和修复云安全风险、继承的基础设施弱点、配置漂移和操作安全缺口。
- 通过与云工程和 DevOps 团队合作,将安全嵌入基础设施、平台和工程工作流程,构建默认安全的解决方案。
### **应用安全与 DevSecOps**
- 在产品生命周期中识别并解决应用架构、身份验证、API 和数据流中的安全风险。
- 将安全功能集成到 CI/CD 管道和工程工作流程中,包括 SAST、DAST、依赖项扫描、密钥管理、软件供应链安全和基于策略的控制。
- 领导威胁建模、架构评审和安全设计讨论,以在软件开发生命周期早期识别安全风险。
- 构建开发者友好的安全防护措施、可重用模式和自动化工具。
查看英文原文
## **Position Summary**
Virtuous is hiring a Senior DevSecOps Engineer to strengthen the security posture of our products, cloud infrastructure, and software delivery ecosystem.
Reporting to the Director of IT & Security, you'll partner with Engineering, Cloud Engineering, DevOps, Architecture, and Security teams to build security into the way we design, develop, deploy, and operate software. You'll improve the security of our products and cloud environment by reducing security debt, modernizing security practices, and building secure-by-default solutions through automation and engineering.
This role is embedded within a collaborative DevOps function and is ideal for someone who enjoys solving security problems through code, automation, and engineering rather than manual reviews or gatekeeping. We're looking for an engineer who is naturally curious, challenges conventional approaches, and safely leverages AI-assisted tooling and modern engineering practices to create scalable, high-impact solutions.
## **Responsibilities**
### **Security Engineering & Cloud Security**
- Design, implement, and continuously improve secure Azure cloud architectures, networking, governance, and infrastructure to support scalable, secure-by-default engineering.
- Strengthen cloud security posture through infrastructure hardening, segmentation, secure connectivity patterns, RBAC/PIM, Azure Policy, and automated guardrails.
- Improve security visibility through logging, monitoring, SIEM integrations, detection engineering, and operational security tooling.
- Continuously assess and remediate cloud security risks, inherited infrastructure weaknesses, configuration drift, and operational security gaps.
- Embed security into infrastructure, platforms, and engineering workflows by collaborating with Cloud Engineering and DevOps teams to build secure-by-default solutions.
### **Application Security & DevSecOps**
- Identify and address security risks in application architecture, authentication, APIs, and data flows throughout the product lifecycle.
- Integrate security capabilities into CI/CD pipelines and engineering workflows, including SAST, DAST, dependency scanning, secrets management, software supply-chain security, and policy-based controls.
- Lead threat modeling, architecture reviews, and secure design discussions to identify security risks early in the software development lifecycle.
- Build developer-friendly security guardrails, reusable patterns, and automations that improve security without slowing delivery velocity.
- Drive timely remediation of security findings by enabling engineering teams with practical guidance, automation, and secure-by-default patterns.
### **Security Modernization & Operational Excellence**
- Lead efforts to reduce security backlog, cloud governance drift, stale permissions, infrastructure weaknesses, technical debt, and operational security risk.
- Balance risk reduction, engineering impact, and business priorities when determining what to remediate, standardize, automate, or defer.
- Collaborate with Security leadership to improve incident readiness, operational maturity, security visibility, and organizational resilience.
- Help modernize inherited systems while improving container security, Kubernetes security, and secure cloud-native engineering practices.
### **Automation, AI & Engineering Enablement**
- Leverage automation, APIs, scripting, AI-assisted tooling, and emerging technologies to improve security operations, engineering productivity, and organizational effectiveness.
- Continuously challenge traditional approaches by identifying opportunities to automate, simplify, or reimagine security and engineering workflows.
- Build self-service capabilities, reusable tooling, and scalable workflows that improve developer experience while strengthening security outcomes.
- Evaluate and adopt modern engineering practices, AI-assisted workflows, and emerging technologies that improve security outcomes, accelerate remediation, and increase engineering effectiveness.
- Act as a force multiplier across Security, Engineering, and Cloud Operations by creating systems that increase organizational leverage and effectiveness.
## **What Success Looks Like**
- Security controls are embedded into engineering workflows without creating unnecessary friction or slowing delivery velocity.
- Application and cloud security posture improve through strong engineering adoption, operational ownership, and scalable guardrails.
- Security backlog, infrastructure debt, and operational risk are consistently reduced through pragmatic remediation and automation.
- Cloud infrastructure is secure, resilient, observable, and governed through secure-by-default engineering practices.
- Automation, AI-assisted engineering, and intelligent workflows measurably improve team effectiveness, remediation velocity, and operational scalability.
- Engineering, Security, and Cloud teams operate as trusted partners with shared ownership of reliability, security, and business outcomes.
## **You Must Have**
- 5+ years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related security-focused engineering roles within cloud-native SaaS environments.
- Strong experience designing, securing, and modernizing Azure environments, including Azure networking, governance, RBAC/PIM, Azure Policy, and secure connectivity patterns.
- Experience improving application security through secure SDLC practices, threat modeling, CI/CD security controls, and engineering partnership.
- Hands-on experience implementing DevSecOps capabilities such as SAST, DAST, dependency scanning, secrets management, software supply-chain security, and policy automation.
- Experience with Kubernetes, Docker, container security, IaC, and modern cloud-native platforms.
- Hands-on experience with GitHub, GitHub Actions, GitHub Advanced Security (or equivalent), SIEM platforms, observability tooling, and cloud security technologies.
- Strong automation, scripting, troubleshooting, and cross-functional collaboration skills, with a focus on scalable solutions and operational improvement.
- Experience leveraging AI-assisted engineering tools (such as GitHub Copilot, Claude Code, or similar) and a demonstrated curiosity for applying automation and emerging technologies to improve security and engineering outcomes.
## **About Us**
Virtuous software is powering the world’s leading nonprofits and inspiring a new generation of generosity.
At Virtuous, we believe generosity has the power to transform the world - and so we are on a mission to create $10B in net new generosity by helping nonprofits better connect with and inspire their donors.
Our talented team is hungry, humble, and committed to delivering best-in-class software solutions, customer success interactions, and sales experiences to the nonprofit community.
Our values are more than just a poster on the wall. Instead, our mission and values are precisely why candidates choose Virtuous. Our core values are:
1. **Build Better**: We build audacious ideas to accelerate philanthropy and dismantle the status quo.
2. **Display Radical Generosity**: We are generous with our time & talent as we serve our team and the nonprofit community.
3. **Stay Humble & Enjoy the Journey**: We take our work seriously, but we don't take ourselves too seriously.
Virtuous should act as a career accelerator for everyone on our team. Team members should look back at their time at Virtuous as one of the most productive and stretching seasons in their professional lives. This means that working at Virtuous isn't for everybody. It is for the select few who are ready to do hard things and build something truly great.
If this sounds like you, we’d love for you to apply!
## **What We Offer**
- Market competitive pay leveraging Carta data
- Employee recognition through Bonusly (birthdays, anniversaries, achievements, etc.)
- 401(k) retirement plan with company matching- 50% match up to 6% of compensation after 90 days
- We value our employee’s work-life balance and encourage taking advantage of Unlimited PTO
- Supportive time off including paid volunteer days and company holidays
- Employer-contributed healthcare benefits, encompassing medical, dental, and vision coverage, with plans available for dependents and choices for Health Savings Accounts (HSA) and Flexible Spending Accounts (FSA).
- 12 weeks primary parent leave, 4 weeks secondary parent leave - full pay (adoption as well)
- We pride ourselves on Community and host exciting company outings and events.
We’ve recently noticed an increase in recruitment scams where individuals are impersonating recruiters to obtain personal or financial information through fraudulent interviews and job offers.
Please note that all legitimate communication from Virtuous will only come from the @ [virtuous.org](http://virtuous.org) domain. If you receive a message from other domains, even if they look similar (e.g., [virtuouscareers.org](http://virtuouscareers.org) or [virtuousjobs.com](http://virtuousjobs.com)), they are **not legitimate** and we recommend disregarding it immediately.