{"schemaVersion":"jobsearcher.job.v1","id":"71cf74db740609278733a422","url":"https://jobsearcher.com/jobs/71cf74db740609278733a422","canonicalUrl":"https://jobsearcher.com/jobs/71cf74db740609278733a422","title":"Senior DevSecOps Engineer","description":"About Us\nVirtuous is on a mission to inspire global generosity by helping nonprofits build better relationships with their donors. We offer a modern software platform that provides mid-sized charities with elegant tools for fundraising, marketing, volunteerism, and online giving.\nOur talented team is driven to disrupt the status quo in the nonprofit sector. We are hungry, humble, and committed to delivering best-in-class software solutions, customer success interactions, and sales experiences to the world’s leading nonprofits\n\nWe also recognize the importance of giving back and making a difference in the communities where we live and work. That's why we practice radical generosity by volunteering at nonprofits or going the extra mile for our team and the customers we serve. We take our work seriously, but we don’t take ourselves too seriously. We believe that life is too short not to love what you do.\nThe ideal candidate for Virtuous embodies our values by:\nAsking questions with a spirit of curiosity\nGiving feedback freely with candor & grace, welcoming it in return\nDisplaying a passion for philanthropy and technology\nServing with joy. Everyone is willing to make the coffee!\nCelebrating the wins & milestones of others\nAssuming good intent & demonstrating trust in others\nPursuing relationships with people different from themselves & creates space to be human\nFind our core values & more here.\n\nPosition Summary\nVirtuous is hiring a Senior DevSecOps Engineer to strengthen the security posture of our products, cloud infrastructure, and software delivery ecosystem.\n\nReporting to the Director of IT & Security, you'll partner with Engineering, Cloud Engineering, DevOps, Architecture, and Security teams to build security into the way we design, develop, deploy, and operate software. You'll improve the security of our products and cloud environment by reducing security debt, modernizing security practices, and building secure-by-default solutions through automation and engineering.\n\nThis role is embedded within a collaborative DevOps function and is ideal for someone who enjoys solving security problems through code, automation, and engineering rather than manual reviews or gatekeeping. We're looking for an engineer who is naturally curious, challenges conventional approaches, and safely leverages AI-assisted tooling and modern engineering practices to create scalable, high-impact solutions.\n\nResponsibilities\nSecurity Engineering & Cloud Security\nDesign, implement, and continuously improve secure Azure cloud architectures, networking, governance, and infrastructure to support scalable, secure-by-default engineering.\nStrengthen cloud security posture through infrastructure hardening, segmentation, secure connectivity patterns, RBAC/PIM, Azure Policy, and automated guardrails.\nImprove security visibility through logging, monitoring, SIEM integrations, detection engineering, and operational security tooling.\nContinuously assess and remediate cloud security risks, inherited infrastructure weaknesses, configuration drift, and operational security gaps.\nEmbed security into infrastructure, platforms, and engineering workflows by collaborating with Cloud Engineering and DevOps teams to build secure-by-default solutions.\nApplication Security & DevSecOps\nIdentify and address security risks in application architecture, authentication, APIs, and data flows throughout the product lifecycle.\nIntegrate security capabilities into CI/CD pipelines and engineering workflows, including SAST, DAST, dependency scanning, secrets management, software supply-chain security, and policy-based controls.\nLead threat modeling, architecture reviews, and secure design discussions to identify security risks early in the software development lifecycle.\nBuild developer-friendly security guardrails, reusable patterns, and automations that improve security without slowing delivery velocity.\nDrive timely remediation of security findings by enabling engineering teams with practical guidance, automation, and secure-by-default patterns.\nSecurity Modernization & Operational Excellence\nLead efforts to reduce security backlog, cloud governance drift, stale permissions, infrastructure weaknesses, technical debt, and operational security risk.\nBalance risk reduction, engineering impact, and business priorities when determining what to remediate, standardize, automate, or defer.\nCollaborate with Security leadership to improve incident readiness, operational maturity, security visibility, and organizational resilience.\nHelp modernize inherited systems while improving container security, Kubernetes security, and secure cloud-native engineering practices.\nAutomation, AI & Engineering Enablement\nLeverage automation, APIs, scripting, AI-assisted tooling, and emerging technologies to improve security operations, engineering productivity, and organizational effectiveness.\nContinuously challenge traditional approaches by identifying opportunities to automate, simplify, or reimagine security and engineering workflows.\nBuild self-service capabilities, reusable tooling, and scalable workflows that improve developer experience while strengthening security outcomes.\nEvaluate and adopt modern engineering practices, AI-assisted workflows, and emerging technologies that improve security outcomes, accelerate remediation, and increase engineering effectiveness.\nAct as a force multiplier across Security, Engineering, and Cloud Operations by creating systems that increase organizational leverage and effectiveness.\n\nWhat Success Looks Like\nSecurity controls are embedded into engineering workflows without creating unnecessary friction or slowing delivery velocity.\nApplication and cloud security posture improve through strong engineering adoption, operational ownership, and scalable guardrails.\nSecurity backlog, infrastructure debt, and operational risk are consistently reduced through pragmatic remediation and automation.\nCloud infrastructure is secure, resilient, observable, and governed through secure-by-default engineering practices.\nAutomation, AI-assisted engineering, and intelligent workflows measurably improve team effectiveness, remediation velocity, and operational scalability.\nEngineering, Security, and Cloud teams operate as trusted partners with shared ownership of reliability, security, and business outcomes.\n\nYou Must Have\n5+ years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related security-focused engineering roles within cloud-native SaaS environments.\nStrong experience designing, securing, and modernizing Azure environments, including Azure networking, governance, RBAC/PIM, Azure Policy, and secure connectivity patterns.\nExperience improving application security through secure SDLC practices, threat modeling, CI/CD security controls, and engineering partnership.\nHands-on experience implementing DevSecOps capabilities such as SAST, DAST, dependency scanning, secrets management, software supply-chain security, and policy automation.\nExperience with Kubernetes, Docker, container security, IaC, and modern cloud-native platforms.\nHands-on experience with GitHub, GitHub Actions, GitHub Advanced Security (or equivalent), SIEM platforms, observability tooling, and cloud security technologies.\nStrong automation, scripting, troubleshooting, and cross-functional collaboration skills, with a focus on scalable solutions and operational improvement.\nExperience leveraging AI-assisted engineering tools (such as GitHub Copilot, Claude Code, or similar) and a demonstrated curiosity for applying automation and emerging technologies to improve security and engineering outcomes.\nWhat We Offer\nMarket competitive pay leveraging Carta data\nEmployee recognition through Bonusly (birthdays, anniversaries, achievements, etc.)\n401(k) retirement plan with company matching- 50% match up to 6% of compensation after 90 days\nWe value our employee’s work-life balance and encourage taking advantage of Unlimited PTO\nSupportive time off including paid volunteer days and company holidays\nEmployer-contributed healthcare benefits, encompassing medical, dental, and vision coverage, with plans available for dependents and choices for Health Savings Accounts (HSA) and Flexible Spending Accounts (FSA).\n12 weeks primary parent leave, 4 weeks secondary parent leave - full pay (adoption as well)\nWe pride ourselves on Community and host exciting company outings and events.\nWe’ve recently noticed an increase in recruitment scams where individuals are impersonating recruiters to obtain personal or financial information through fraudulent interviews and job offers.\n\nPlease note that all legitimate communication from Virtuous will only come from the @virtuous.org domain. If you receive a message from other domains, even if they look similar (e.g., virtuouscareers.org or virtuousjobs.com), they are not legitimate and we recommend disregarding it immediately.","company":"Virtuous","rawCompany":"virtuous","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-14T13:50:32.962Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior DevSecOps Engineer","description":"About Us\nVirtuous is on a mission to inspire global generosity by helping nonprofits build better relationships with their donors. We offer a modern software platform that provides mid-sized charities with elegant tools for fundraising, marketing, volunteerism, and online giving.\nOur talented team is driven to disrupt the status quo in the nonprofit sector. We are hungry, humble, and committed to delivering best-in-class software solutions, customer success interactions, and sales experiences to the world’s leading nonprofits\n\nWe also recognize the importance of giving back and making a difference in the communities where we live and work. That's why we practice radical generosity by volunteering at nonprofits or going the extra mile for our team and the customers we serve. We take our work seriously, but we don’t take ourselves too seriously. We believe that life is too short not to love what you do.\nThe ideal candidate for Virtuous embodies our values by:\nAsking questions with a spirit of curiosity\nGiving feedback freely with candor & grace, welcoming it in return\nDisplaying a passion for philanthropy and technology\nServing with joy. Everyone is willing to make the coffee!\nCelebrating the wins & milestones of others\nAssuming good intent & demonstrating trust in others\nPursuing relationships with people different from themselves & creates space to be human\nFind our core values & more here.\n\nPosition Summary\nVirtuous is hiring a Senior DevSecOps Engineer to strengthen the security posture of our products, cloud infrastructure, and software delivery ecosystem.\n\nReporting to the Director of IT & Security, you'll partner with Engineering, Cloud Engineering, DevOps, Architecture, and Security teams to build security into the way we design, develop, deploy, and operate software. You'll improve the security of our products and cloud environment by reducing security debt, modernizing security practices, and building secure-by-default solutions through automation and engineering.\n\nThis role is embedded within a collaborative DevOps function and is ideal for someone who enjoys solving security problems through code, automation, and engineering rather than manual reviews or gatekeeping. We're looking for an engineer who is naturally curious, challenges conventional approaches, and safely leverages AI-assisted tooling and modern engineering practices to create scalable, high-impact solutions.\n\nResponsibilities\nSecurity Engineering & Cloud Security\nDesign, implement, and continuously improve secure Azure cloud architectures, networking, governance, and infrastructure to support scalable, secure-by-default engineering.\nStrengthen cloud security posture through infrastructure hardening, segmentation, secure connectivity patterns, RBAC/PIM, Azure Policy, and automated guardrails.\nImprove security visibility through logging, monitoring, SIEM integrations, detection engineering, and operational security tooling.\nContinuously assess and remediate cloud security risks, inherited infrastructure weaknesses, configuration drift, and operational security gaps.\nEmbed security into infrastructure, platforms, and engineering workflows by collaborating with Cloud Engineering and DevOps teams to build secure-by-default solutions.\nApplication Security & DevSecOps\nIdentify and address security risks in application architecture, authentication, APIs, and data flows throughout the product lifecycle.\nIntegrate security capabilities into CI/CD pipelines and engineering workflows, including SAST, DAST, dependency scanning, secrets management, software supply-chain security, and policy-based controls.\nLead threat modeling, architecture reviews, and secure design discussions to identify security risks early in the software development lifecycle.\nBuild developer-friendly security guardrails, reusable patterns, and automations that improve security without slowing delivery velocity.\nDrive timely remediation of security findings by enabling engineering teams with practical guidance, automation, and secure-by-default patterns.\nSecurity Modernization & Operational Excellence\nLead efforts to reduce security backlog, cloud governance drift, stale permissions, infrastructure weaknesses, technical debt, and operational security risk.\nBalance risk reduction, engineering impact, and business priorities when determining what to remediate, standardize, automate, or defer.\nCollaborate with Security leadership to improve incident readiness, operational maturity, security visibility, and organizational resilience.\nHelp modernize inherited systems while improving container security, Kubernetes security, and secure cloud-native engineering practices.\nAutomation, AI & Engineering Enablement\nLeverage automation, APIs, scripting, AI-assisted tooling, and emerging technologies to improve security operations, engineering productivity, and organizational effectiveness.\nContinuously challenge traditional approaches by identifying opportunities to automate, simplify, or reimagine security and engineering workflows.\nBuild self-service capabilities, reusable tooling, and scalable workflows that improve developer experience while strengthening security outcomes.\nEvaluate and adopt modern engineering practices, AI-assisted workflows, and emerging technologies that improve security outcomes, accelerate remediation, and increase engineering effectiveness.\nAct as a force multiplier across Security, Engineering, and Cloud Operations by creating systems that increase organizational leverage and effectiveness.\n\nWhat Success Looks Like\nSecurity controls are embedded into engineering workflows without creating unnecessary friction or slowing delivery velocity.\nApplication and cloud security posture improve through strong engineering adoption, operational ownership, and scalable guardrails.\nSecurity backlog, infrastructure debt, and operational risk are consistently reduced through pragmatic remediation and automation.\nCloud infrastructure is secure, resilient, observable, and governed through secure-by-default engineering practices.\nAutomation, AI-assisted engineering, and intelligent workflows measurably improve team effectiveness, remediation velocity, and operational scalability.\nEngineering, Security, and Cloud teams operate as trusted partners with shared ownership of reliability, security, and business outcomes.\n\nYou Must Have\n5+ years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related security-focused engineering roles within cloud-native SaaS environments.\nStrong experience designing, securing, and modernizing Azure environments, including Azure networking, governance, RBAC/PIM, Azure Policy, and secure connectivity patterns.\nExperience improving application security through secure SDLC practices, threat modeling, CI/CD security controls, and engineering partnership.\nHands-on experience implementing DevSecOps capabilities such as SAST, DAST, dependency scanning, secrets management, software supply-chain security, and policy automation.\nExperience with Kubernetes, Docker, container security, IaC, and modern cloud-native platforms.\nHands-on experience with GitHub, GitHub Actions, GitHub Advanced Security (or equivalent), SIEM platforms, observability tooling, and cloud security technologies.\nStrong automation, scripting, troubleshooting, and cross-functional collaboration skills, with a focus on scalable solutions and operational improvement.\nExperience leveraging AI-assisted engineering tools (such as GitHub Copilot, Claude Code, or similar) and a demonstrated curiosity for applying automation and emerging technologies to improve security and engineering outcomes.\nWhat We Offer\nMarket competitive pay leveraging Carta data\nEmployee recognition through Bonusly (birthdays, anniversaries, achievements, etc.)\n401(k) retirement plan with company matching- 50% match up to 6% of compensation after 90 days\nWe value our employee’s work-life balance and encourage taking advantage of Unlimited PTO\nSupportive time off including paid volunteer days and company holidays\nEmployer-contributed healthcare benefits, encompassing medical, dental, and vision coverage, with plans available for dependents and choices for Health Savings Accounts (HSA) and Flexible Spending Accounts (FSA).\n12 weeks primary parent leave, 4 weeks secondary parent leave - full pay (adoption as well)\nWe pride ourselves on Community and host exciting company outings and events.\nWe’ve recently noticed an increase in recruitment scams where individuals are impersonating recruiters to obtain personal or financial information through fraudulent interviews and job offers.\n\nPlease note that all legitimate communication from Virtuous will only come from the @virtuous.org domain. If you receive a message from other domains, even if they look similar (e.g., virtuouscareers.org or virtuousjobs.com), they are not legitimate and we recommend disregarding it immediately.","datePosted":"2026-08-14T13:50:32.962Z","dateModified":"2026-08-14T13:50:32.962Z","hiringOrganization":{"@type":"Organization","name":"Virtuous","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"71cf74db740609278733a422"},"url":"https://jobsearcher.com/jobs/71cf74db740609278733a422"}}