网络安全运营分析师 III,产品应用安全
Cyber-Security Operations Analyst III, Product AppSec
Veeam 是数据和 AI 信任公司,专注于帮助组织确保其数据和 AI 得到充分理解、保护,并具备弹性,以推动安全 AI 的规模化发展。作为数据弹性和数据安全态势管理领域的市场领导者,Veeam 专为身份、数据、安全和 AI 风险的融合而设计。总部位于西雅图,在超过 30 个国家设有办公室,Veeam 全球保护着 55 万多家客户,他们信任 Veeam 来保障业务的持续运行。与我们一同勇敢前行,共同成长、学习,并为一些全球最大的品牌带来真正的影响力。
##### #LI-REMOTE #LI-JC2
##### 关于职位
我们正在寻找一名网络安全运营分析师,负责在云和平台工程环境中操作、监控和支持安全软件交付基础设施。你将与软件工程、安全、基础设施和平台团队合作,加强 CI/CD 管道,自动化部署流程,并提升运营可靠性。该职位处于开发速度与安全的交汇点,帮助现代化工作流程并实施可扩展的 DevSecOps 实践,以支持企业软件、云原生服务和 AI 驱动的产品。
_由于该职位将处理高度敏感的数据并支持联邦客户,目前我们仅考虑美国公民。不需要安全许可,但未来可能会有轻微的可能性需要_
##### 你将负责
- 操作和维护 CI/CD 管道、构建代理和支撑基础设施,涵盖开发、预发布和生产环境
- 配置和集成应用安全工具,包括日志记录、监控、警报和仪表板管理
- 支持 SIEM 运营,包括日志接入、检测调优、警报分类和事件响应
- 管理 CI/CD 基础设施、构建代理、容器基础镜像和平台依赖项的补丁
- 监控安全工具和 DevSecOps 平台组件的健康状况、可用性和性能
- 与 IT 和工程团队合作支持 CI/CD 工具链,包括升级、容量规划和访问管理
- 与工程团队协作进行问题分类、文档编写和操作知识分享
##### 你将使用的技术
- CI/CD 平台:GitHub Actions、Azure DevOps、Jenkins、GitLab CI
- IaC 工具:Terraform、Ansible、Chef、Puppet
- 安全工具:Splunk、ELK Stack、OpenSearch、SonarQube、Checkmarx、Snyk
- 云平台:AWS、Azure、Google Cloud
- 容器技术:Docker、Kubernetes
- 编程语言:Python、Go、Shell 脚本
查看英文原文
Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.
##### #LI-REMOTE #LI-JC2
##### About the Role
We're looking for a Cyber-Security Operations Analyst to operate, monitor, and support secure software delivery infrastructure across cloud and platform engineering environments. You'll partner with Software Engineering, Security, Infrastructure, and Platform teams to strengthen CI/CD pipelines, automate deployment workflows, and enhance operational reliability. This role sits at the intersection of development velocity and security, helping modernize workflows and implement scalable DevSecOps practices that support enterprise software, cloud-native services, and AI-enabled products.
_Due to the fact that this position will deal with highly sensitive data and will support federal customers, we are only considering US citizens at this time. Security clearance is not required, but there is a slight chance it maybe requested in the future_
##### What You'll Do
- Operate and maintain CI/CD pipelines, build agents, and supporting infrastructure across development, staging, and pre-production environments
- Configure and integrate application security tooling, including logging, monitoring, alerting, and dashboard management
- Support SIEM operations including log onboarding, detection tuning, alert triage, and incident response
- Manage patching of CI/CD infrastructure, build agents, container base images, and platform dependencies
- Monitor health, availability, and performance of security tools and DevSecOps platform components
- Partner with IT and Engineering teams on CI/CD toolchain support, including upgrades, capacity planning, and access management
- Collaborate with engineering teams to triage issues, document workflows, and share operational knowledge
##### Technologies You'll Work With
- CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins, GitLab CI
- IaC tools: Terraform, Ansible, CloudFormation, or Pulumi
- Security tooling: Trivy, SAST, DAST, SCA, container scanning platforms
- Cloud providers: AWS, Azure, or GCP
- Containerization: Kubernetes, Docker, Helm
- Artifact management: JFrog Artifactory
- Scripting: Python, Bash, PowerShell
- SIEM and observability platforms
##### What You'll Bring
- 5+ years of experience in DevOps, Platform Engineering, SRE, or a related technical role
- 3+ years of hands-on experience with security testing tools (SAST, DAST, SCA)
- Experience designing and maintaining CI/CD pipelines using GitHub Actions, Azure DevOps, Jenkins, or similar
- Proficiency with IaC tools (Terraform, Ansible, or equivalent) and cloud environments (AWS, Azure, or GCP)
- Strong Linux administration skills and experience with Kubernetes, Docker, and Git
- Familiarity with regulated or compliance-driven environments
- Bachelor's degree in Computer Science, Engineering, or equivalent experience
##### Bonus Skills
- Experience with software supply chain security frameworks (SLSA, NIST SSDF, OWASP SCVS)
- Relevant certifications such as CDP, GCSA, CCSP, CKS, or cloud security certifications (Azure, AWS, GCP)
- Experience with agentic AI development practices
- Familiarity with TCP/IP networking, DNS, SSL/TLS, and network security fundamentals
**What you'll get**
- Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
- Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
- Medical, dental, and vision coverage starting on your first day
- Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
- 401(k) retirement plan with company matching contributions
- Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
- AirVet: 24/7 virtual veterinary care at no cost
- Legal services, identity protection, and supplemental health insurance options
- Tax-advantaged spending accounts for healthcare, dependent care, and commuting
- Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning
**Compensation Transparency**
Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.
In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.
**U.S. Geographic Zones & Compensation Ranges (TTC / OTE)**
Zone 1: San Francisco Bay Area, New York City Boroughs
$140,900—$234,800 USD
Zone 2: Washington, California (excluding San Francisco Bay Area)
$129,200—$215,300 USD
Zone 3: Texas, Illinois, North Carolina, Colorado, Massachusetts, Pennsylvania, Virginia, Oregon, Nevada, Hawaii, New York (excluding NYC boroughs); Sales roles located in Georgia, Ohio, and Arizona
$117,400—$195,700 USD
Zone 4: All other US locations
$102,200—$170,300 USD
**Veeam Software is an equal opportunity employer** and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.
Personal data collected during the recruitment process will be processed in accordance with our [Recruiting Privacy Notice](https://www.veeam.com/legal/recruiting-privacy-notice.html), which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing.
By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.