Senior DevSecOps Engineer

Other Jobs To Apply

<h2>About Us</h2><p style="min-height:1.5em">We’re a startup with big ambitions: to make estate planning modern, visual, and intelligent. <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.justvanilla.com/"><u>Vanilla</u></a> is the first AI-powered estate advisory platform, built by advisors, planners, and attorneys to transform how wealth is transferred across generations. Our technology unifies scenario modeling, client visualization, and document creation into one seamless, digital experience.</p><p style="min-height:1.5em">Our team brings together diverse subject matter expertise across estate planning, wealth management, and scaling SaaS startups. We’re distributed across the U.S., with a mix of fully remote and hybrid roles, and we embrace flexibility while staying closely connected. At Vanilla, you’ll join curious builders and problem-solvers who thrive on speed, autonomy, and impact. Here, you won’t just join a company, you’ll help create it. If you’re excited to tackle hard problems, move quickly, and see your work shape both an industry and a growing startup, we’d love to meet you.</p><p style="min-height:1.5em"></p><h1><strong>Working Location</strong></h1><p style="min-height:1.5em"><strong>This role is a remote position, you must be based out of one of the following states: </strong>Arizona, California, Colorado, Connecticut, Florida, Georgia, Idaho, Illinois, Kentucky, Maine, Massachusetts, Minnesota, New Jersey, New York, Ohio, Pennsylvania, Texas, Utah or Washington.</p><p style="min-height:1.5em"></p><h1><strong>Job Summary</strong></h1><p style="min-height:1.5em">We’re looking for a Senior DevSecOps Engineer to own and operate our security tooling, manage key vendor relationships, and drive our application and cloud security programs forward. This is a hands-on, high-ownership role: you’ll be the day-to-day operator of our security stack, the point person for our vCISO engagement, and the engineer building the processes that keep Vanilla’s platform and infrastructure secure.</p><p style="min-height:1.5em">You’ll also own the operational cadence of our security program: managing vendor-led pen tests, running tabletop exercises, maintaining our incident response playbook, and building a multi-quarter security roadmap.</p><p style="min-height:1.5em">This role is ideal for a strong DevOps or infrastructure engineer who is security-minded, eager to own a security program, and comfortable operating in a fast-moving Series B environment. You’ll report to the Director of Engineering and collaborate closely with our vCISO (Latacora) and external partners.</p><p style="min-height:1.5em"></p><h1><strong>Responsibilities</strong></h1><p style="min-height:1.5em"><strong>Cloud & Infrastructure Security</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Secure AWS infrastructure, systems, and networking</p></li><li><p style="min-height:1.5em">Review infrastructure-as-code (Terraform) changes for security implications</p></li><li><p style="min-height:1.5em">Support secrets management, IAM policy reviews, and encryption standards</p></li><li><p style="min-height:1.5em">Triage and respond to cross-team IT requests that carry security implications</p></li></ul><p style="min-height:1.5em"><strong>Security Operations & Tooling</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Operate and tune security tooling including SentinelOne (EDR), Sublime (email security), Panther (SIEM), and Cloudflare</p></li><li><p style="min-height:1.5em">Monitor and triage security alerts across dedicated channels</p></li><li><p style="min-height:1.5em">Serve as the primary responder for cross-team security requests</p></li></ul><p style="min-height:1.5em"><strong>Vendor & Program Management</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Manage the vCISO relationship, including coordinating on cloud security posture, endpoint coverage, and SOC 24x7 operations</p></li><li><p style="min-height:1.5em">Own the annual penetration test lifecycle: vendor selection, scoping, coordination, remediation tracking, and reporting</p></li><li><p style="min-height:1.5em">Scope and coordinate AI red team engagements</p></li><li><p style="min-height:1.5em">Run tabletop exercises and maintain the incident response playbook</p></li><li><p style="min-height:1.5em">Build and maintain a multi-quarter security roadmap in partnership with engineering leadership</p></li></ul><p style="min-height:1.5em"><strong>Application Security</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Own and evolve pre-deploy security gates across CI/CD pipelines</p></li><li><p style="min-height:1.5em">Run vulnerability management for libraries and application code: scanning, prioritization, and remediation workflows</p></li><li><p style="min-height:1.5em">Conduct threat modeling for new features, integrations, and architecture changes</p></li><li><p style="min-height:1.5em">Champion secure coding practices across engineering teams</p></li></ul><p style="min-height:1.5em"><strong>AI Security</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Scope and coordinate AI red team exercises against Vanilla’s AI-powered features</p></li><li><p style="min-height:1.5em">Assess security of AI/ML pipelines, inference endpoints, and third-party AI vendor integrations</p></li><li><p style="min-height:1.5em">Implement and maintain guardrails for AI outputs, including controls against prompt injection and data exfiltration</p></li><li><p style="min-height:1.5em">Establish data governance practices for sensitive training data (PII/PHI in estate and financial documents)</p></li></ul><p style="min-height:1.5em"></p><h1><strong>What This Role Is Not</strong></h1><p style="min-height:1.5em">This role is focused on infrastructure and security engineering, not compliance or customer trust. SOC 2, security questionnaires, and audit documentation sit elsewhere in the org.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>Required Qualifications</strong></p><p style="min-height:1.5em"><strong>Must Have</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Hands-on AWS experience: infrastructure, networking, and cloud security posture</p></li><li><p style="min-height:1.5em">Experience with infrastructure-as-code (Terraform or CloudFormation)Strong understanding of IAM, network security, encryption, and secrets management</p></li><li><p style="min-height:1.5em">Hands-on vulnerability management experience: scanning, triage, remediation workflows</p></li><li><p style="min-height:1.5em">Experience with threat modeling, secure code review, and CI/CD security gating.</p></li><li><p style="min-height:1.5em">Strong scripting and automation skills (Python, Bash, or similar)</p></li></ul><p style="min-height:1.5em"><strong>Nice to Have</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Experience operating security tooling: EDR, SIEM, email security, WAF, or similar</p></li><li><p style="min-height:1.5em">Familiarity with SentinelOne, Sublime, Panther, or Cloudflare specifically</p></li><li><p style="min-height:1.5em">Prior incident response or tabletop exercise facilitation</p></li><li><p style="min-height:1.5em">Exposure to AI/ML security: LLM risks, securing inference endpoints, or data privacy in ML contexts</p></li><li><p style="min-height:1.5em">Experience in fintech, wealthtech, or other regulated industries</p></li><li><p style="min-height:1.5em">Familiarity with supply chain security<br></p></li></ul><p style="min-height:1.5em"><em>The salary range for this role is $180,000 to $210,000. Our compensation packages also include a performance-based bonus and equity. Compensation is based on a number of factors and may vary depending on job-related knowledge, skills, and experience.</em></p><p style="min-height:1.5em"></p><h2>Benefits:</h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Flexible paid time off policy and 10 company-wide paid holidays </p></li><li><p style="min-height:1.5em">Parental leave, 6 weeks for all full-time employees and up to 14 weeks for birthing parents</p></li><li><p style="min-height:1.5em">Medical, dental, and vision benefits coverage for employees and their families </p></li><li><p style="min-height:1.5em">401K eligibility after one month of employment</p></li><li><p style="min-height:1.5em">Free estate planning documents</p></li><li><p style="min-height:1.5em">Budget for learning & development and home office setup </p></li><li><p style="min-height:1.5em">Paid parking or transit for hybrid and in office employees </p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em"><em>Vanilla Technologies Inc. (dba "Vanilla") provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training. </em></p><p style="min-height:1.5em"><em>Vanilla participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. </em></p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...