Virta Health Logo

Virta Health

DevSecOps Engineer

Posted 23 Days Ago
Remote
Hiring Remotely in USA
179K-188K Annually
Senior level
Remote
Hiring Remotely in USA
179K-188K Annually
Senior level
Secure Virta’s cloud-native applications and platform by improving GCP and Kubernetes controls, integrating security into the software lifecycle, automating vulnerability detection and compliance, refining IAM and network security, developing security standards, supporting incident response, and promoting security awareness. The role requires hands-on application security, secure coding, vulnerability management, security testing, Terraform, and Go or Python development experience.
The summary above was generated by AI

Virta Health is pioneering a new standard of care for people to reclaim their lives. We are in the midst of a public health crisis: obesity rates are at an all-time high and over half of US adults have type 2 diabetes or prediabetes, and despite billions spent on new treatments, outcomes are largely worse. Virta reverses these diseases and delivers life-changing results by pairing individualized nutrition with ongoing care from a clinical support team. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives.

As we rapidly scale our impact, we're seeking a passionate DevSecOps engineer to help build and mature our application security program. Working closely with our security lead, you'll implement best practices and help embed security principles across the org. If you thrive on building secure systems, automation, fostering a security-conscious culture, and making a tangible difference in protecting sensitive health information, this role is for you.

Responsibilities

As a DevSecOps Engineer, you will help secure Virta's applications and platform, directly contributing to the trust our members and partners place in us. You'll collaborate across teams to ensure security is a seamless part of our development lifecycle.

  • Improve Security Design: Help assess our current security controls within GCP and Kubernetes, identify areas for improvement, and contribute to the maturation of our security posture from good to great.

  • Champion Secure Development: Partner closely with Engineering, Product, and Platform teams to integrate security best practices early and often ("shift-left") into the software development lifecycle.

  • Build and Automate: Design, implement, and manage security tooling and automation to streamline vulnerability detection, remediation, and compliance verification. Replace manual processes with efficient, automated solutions.

  • Refine Access Control: Evolve our identity and access management (IAM) strategy, ensuring least-privilege access and robust auditing capabilities across our systems.

  • Strengthen Network Security: Continuously improve our network security architecture, policies, and controls within our cloud environment.

  • Develop Clear Standards: Establish, document, and communicate practical security policies, standards, and guidelines for engineering teams.

  • Support Security Initiatives: Drive vulnerability management efforts and enhance our incident response preparedness, ensuring we are ready to handle potential threats effectively.

  • Cultivate Security Awareness: Act as a security evangelist, promoting security awareness and best practices throughout the engineering organization.

90 Day Plan

Joining a new company and stepping into a foundational role takes time. Here’s what you can expect as you get started and begin making your mark:

  • Immerse Yourself: Your initial focus will be on understanding Virta's culture, our mission, our engineering workflows, and the nuances of our cloud platform (GCP/Kubernetes). You'll connect with key engineers and stakeholders across different teams.

  • Learn the Landscape: You'll dive into our existing systems, CI/CD pipelines, and current security tooling and configurations to get a clear picture of where we stand today.

  • Assess & Identify Opportunities: Leveraging your expertise, you'll begin evaluating our current security posture, including critical areas like our IAM implementation (RBAC), data security practices, network controls, and existing security policies. You'll help identify high-impact areas for improvement.

  • Start Building: You'll quickly move into hands-on work, likely starting with foundational projects such as refining IAM roles, enhancing specific security configurations, or beginning to develop key security automation or documentation.

Must-Haves
  • Understanding and practical experience in securing cloud-native applications and infrastructure, particularly in Kubernetes environments. GCP experience is strongly preferred.

  • Strong grasp of networking concepts, identity management (IAM), encryption, and common web application vulnerabilities (e.g., OWASP Top 10).

  • Strong communication skills with the ability to clearly articulate complex security concepts to diverse audiences and influence technical direction across teams.

  • Hands-on experience in application security, including secure coding practices, vulnerability management, and security testing (SAST, DAST, IAST); exposure to threat modeling is a plus.

  • Proficiency in Infrastructure as Code (IaC) tools, specifically Terraform.

  • Development experience with Go and/or Python.

  • 5-7+ years of experience with 2+ at a high growth startup or similar environment

Values-driven culture

Virta’s company values drive our culture, so you’ll do well if:

  • You put people first and take care of yourself, your peers, and our patients equally

  • You have a strong sense of ownership and take initiative while empowering others to do the same

  • You prioritize positive impact over busy work

  • You have no ego and understand that everyone has something to bring to the table regardless of experience

  • You appreciate transparency and promote trust and empowerment through open access of information

  • You are evidence-based and prioritize data and science over seniority or dogma

  • You take risks and rapidly iterate

Is this role not quite what you're looking for? Join our Talent Community and follow us on Linkedin to stay connected!

Virta has a location based compensation structure. Starting pay will be based on a number of factors and commensurate with qualifications & experience. For this role, the compensation range is $179,451 - 187,900 Information about Virta’s benefits is on our Careers page at: https://www.virtahealth.com/careers.

As part of your duties at Virta, you may come in contact with sensitive patient information that is governed by HIPAA. Throughout your career at Virta, you will be expected to follow Virta's security and privacy procedures to ensure our patients' information remains strictly confidential. Security and privacy training will be provided.

As a remote-first company, our team is spread across various locations with office hubs in Denver and San Francisco.

Clinical roles: We currently do not hire in the following states: AK, HI, RI

Corporate roles: We currently do not hire in the following states: AK, AR, DE, HI, ME, MS, NM, OK, SD, VT, WI.

Virta uses Ashby as its applicant tracking system, which incorporates AI-powered tools (provided by OpenAI, AWS, and Google Gemini) in certain aspects of the recruiting process, including application review, candidate screening, and interview note taking; your data is not used to train AI models, and all final hiring decisions are made by Virta Health personnel. For more information, see Ashby's AI Terms at https://www.ashbyhq.com/resources/terms-ai-features

#LI-remote

Similar Jobs

Yesterday
Easy Apply
Remote
United States
Easy Apply
150K-225K Annually
Senior level
150K-225K Annually
Senior level
Artificial Intelligence • Consumer Web • Digital Media • Fintech • Marketing Tech • Software • Financial Services
Own and mature the company’s DevSecOps and cloud security function. Responsibilities include implementing SOC 2 controls, automating compliance evidence, managing cloud security posture and runtime security, embedding security gates into CI/CD, leading vulnerability remediation, developing auto-remediation and AI-assisted workflows, and securing infrastructure through Terraform and policy-as-code. The role also partners with GRC and corporate security teams while building reusable security tooling and developer-platform guardrails.
Top Skills: Ai/Llm ToolingAspmCi/CdContainer ScanningCspmDependency ScanningInfrastructure As Code (Iac)Policy As CodeSastSbomScaSecret ScanningSIEMSoc 2TerraformVulnerability Management
2 Days Ago
In-Office or Remote
Senior level
Senior level
Professional Services • Software
Operate and improve AWS-based infrastructure and complex production systems. Build infrastructure as code, containerized deployments, CI/CD pipelines, monitoring, observability, rollback processes, and load-testing practices. Manage Aurora/PostgreSQL reliability, security hardening, vulnerability scanning, compliance evidence, incident response, on-call rotations, and root-cause analysis. Collaborate with clients and teams while supporting secure, multi-tenant environments and audit-sensitive workloads.
Top Skills: Amazon RdsApplication Load BalancerAuroraAWSCi/CdCloudFormationCloudwatchDockerEcsFargateIamK6KmsOpentelemetryPostgresPostgresql Row-Level SecurityS3S3 Object LockTerraformVpc
3 Days Ago
Remote
Maryland, USA
Senior level
Senior level
Information Technology • Software
Leads DevSecOps and system administration activities, including Red Hat patching through AWS automation, CI/CD implementation, cloud application support, monitoring, provisioning, testing, containerization, logging, security, and release management. Maintains DevOps toolchains, supports Agile teams, leads system administrators, serves as an escalation point, and collaborates with customers and cross-functional teams. Requires substantial AWS, DevOps, Linux, containerization, and enterprise systems experience.
Top Skills: Amazon Ec2Amazon Elastic File SystemAmazon S3Amazon VpcAnsibleAntArtifactoryAWSAws CodedeployAws Elastic Load BalancingAws Systems Manager AutomationBambooBitbucketChefCruisecontrolCucumberDockerDocker HubDynatraceElasticsearchFortifyGitGitGitlabGradleGruntJbossJenkinsJIRAJmeterJujuKibanaLogstashMavenMercurialNagiosNew RelicNexusNpmOttoPuppetReadyapiRed Hat Enterprise LinuxSaltSeleniumSlackSoapuiSplunkSubversionTerraformTravis CiTripwireVagrant

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account