DevSecOps Engineer
United StatesJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Vultr is seeking a DevSecOps Engineer to design, build, and secure the automated infrastructure that underpins our cloud platform. You will own the security lifecycle of golden images, Kubernetes clusters, and configuration management pipelines, embedding compliance and hardening at build time, not as an afterthought. The ideal candidate brings deep expertise in Linux security, container hardening, and policy-as-code, with a bias toward durable automation over manual remediation.
Key Responsibilities
Design, build, and maintain automated golden image creation pipelines for Linux-based VM and container base images, enforcing CIS hardening standards at build time and validating compliance before promotion through configuration management tooling
Implement and manage automated Linux patching workflows
Build and maintain configuration management pipelines to continuously enforce hardened baselines across Linux workloads, detecting and remediating drift
Integrate security scanning (vulnerability, secrets, SBOM, and compliance) into CI/CD pipelines
Implement policy-as-code controls to enforce security guardrails preventing non-compliant workloads and misconfigured systems from reaching production
Own the golden image factory from upstream source validation through automated CIS benchmark testing and image promotion gates, covering both VM and container images used in CI/CD
Manage secrets lifecycle and distribution ensuring no secrets are baked into images
Respond to configuration drift, vulnerability alerts, and patch compliance gaps with root-cause analysis and durable automation fixes rather than one-off manual remediation
Instrument telemetry pipelines to surface image drift, configuration deviation, and unpatched CVEs in near-real time
Qualifications
5+ years of experience in DevSecOps, platform engineering, or infrastructure security
Strong Linux administration skills with deep understanding of CIS benchmarks and hardening practices
Experience with configuration management tools in production environments
Hands-on experience with Kubernetes security including RBAC, network policies, and workload identity
Proficiency building CI/CD pipelines with integrated security scanning (vulnerability, secrets, SBOM, compliance)
Experience with policy-as-code frameworks
Familiarity with golden image pipelines for VMs and containers, and image promotion workflows
Strong scripting skills (Bash, Python) for automation and remediation
Experience with observability tooling for infrastructure security telemetry
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.