DevSecOps / Cloud Security Engineer

Posted An Hour Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
170K-200K Annually
Senior level
Software
The Role
Own and operationalize cloud, CI/CD, and application security across AWS environments. Implement SAST, DAST, SCA, secrets scanning, CSPM, IAM federation, least privilege, encryption, immutable backups, and security guardrails. Establish secure release gates, eliminate cloud misconfigurations and local credentials, automate secrets rotation, support data-loss prevention, and mentor a junior cloud security engineer across distributed teams and acquired business units.
Summary Generated by Built In

Annual Compensation: $170,000 - $200,000

Position Type: Full Time, Remote

About us 

Vermont Information Processing is the leading technology provider to the beverage industry, route accounting, warehouse, delivery, and sales platforms trusted by distributors, bottlers, and over 1,600 suppliers for 50+ years. Backed by Warburg Pincus, VIP is investing in security as a first-class discipline across a growing family of companies. You will join at the moment the program is being built, with executive sponsorship, a funded roadmap, and visible board-level impact.

About the role  

You will own security of how VIP builds and runs software, the release pipeline and the cloud.  Today the ingredients exist without enforcement: SonarQube and CAST are installed but code-security checks are not yet required before release; CrowdStrike cloud security posture management is deployed but early-stage; a 15-domain cloud security framework with forty implementation runbooks is authored and live in its first environment. Your mandate is to turn all of it on and make secure the default path for our engineering teams. You will work hand-in-hand with a junior cloud security engineer on our India team and have direct executive sponsorship: this role exists because our CIO told the board that no one owns pipeline security and fixed it.


What you will own  

  • Secure release pipeline: make code-security scanning (SAST/SCA) a required, low-friction gate in CI/CD across our development teams; introduce automated application testing (DAST) and secrets scanning.  
  • Cloud security framework rollout: operationalize our 15-domain, cloud-agnostic framework and CrowdStrike CSPM across all AWS estates (VIP-core, VIP India, acquired units), misconfiguration burn-down, guardrails, and workflow integration.  
  • Cloud identity & access: centralize AWS access through Okta, eliminate local credentials, and implement least-privilege roles; define the tagging standard so every resource has an owner and classification.  
  • Secrets & data protection: stand up managed secrets with rotation (replacing env-var and ad-hoc storage), encryption-at-rest verification, and support the data-leak-prevention rollout beyond email. 
  • Resilience engineering: configure tamper-proof (immutable) backup tiers on our Rubrik platform and help define recovery-time objectives with IT.  
  • Enablement & mentorship: build paved-road patterns and developer guidance; grow our India-based junior cloud security engineer; extend the framework to newly acquired units. 

What success looks like in year one  

  • Code-security checks required on 100% of production releases, with developer-experience friction low enough that teams defend the gate.  
  • CSPM operationalized across every AWS account with critical misconfigurations at zero and a sustained burn-down of the rest.  
  • AWS access fully Okta-federated; no shared or local console credentials; tagging standard adopted.  
  • Immutable backup tier live; secrets rotation automated for priority systems.  

What you bring


  • 5+ years across DevOps/platform and security engineering, with real ownership of CI/CD systems (Jenkins, Bitbucket/Git-based pipelines) and AWS.
  • Hands-on with SAST/DAST/SCA tooling and the craft of introducing gates developers accept.  
  • Strong AWS security depth: IAM, organizations/accounts, networking, KMS, and posture management tooling.
  • Infrastructure-as-code and automation fluency (Terraform/CloudFormation, Python).
  • Collaborative style suited to distributed teams; comfortable mentoring and working across time zones.  

Nice to have

  • Azure exposure (two of our acquired units run Azure).
  • Experience with Okta-AWS federation, Rubrik or equivalent backup platforms, and container security.
  • AWS Security Specialty, CCSP, or GIAC cloud certifications. 

Compensation is based on a variety of factors including skills, experience and industry background. The range listed here represents our best faith estimate for the role. 

All full-time job offers are contingent upon passing a pre-employment drug screening and background check.


Skills Required

  • 5+ years across DevOps or platform engineering and security engineering
  • Hands-on ownership of CI/CD systems, including Jenkins and Bitbucket or Git-based pipelines
  • AWS experience with IAM, organizations/accounts, networking, KMS, and security posture management
  • Hands-on experience with SAST, DAST, and SCA tooling
  • Infrastructure-as-code and automation experience with Terraform or CloudFormation and Python
  • Experience working with distributed teams across time zones and mentoring engineers
  • Azure exposure
  • Okta-AWS federation experience
  • Rubrik or equivalent backup platform experience
  • Container security experience
  • AWS Security Specialty, CCSP, or GIAC cloud certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Colchester, Vermont
501 Employees
Year Founded: 1972

What We Do

VIP is the leading technology supplier for brewers, distributors, wineries, soda bottlers, and other companies in the beverage industry. From helping distributors improve their warehouse, delivery, and sales operations, to empowering suppliers to know where their products are and how they’re selling, VIP has the technology and expertise to help these businesses thrive

Similar Jobs

SEON Logo SEON

Account Executive

Artificial Intelligence • Cybersecurity
Remote
US
415 Employees

T-Mobile Logo T-Mobile

Account Executive

Other • Utilities
Remote
Florida, USA
89016 Employees
43K-78K Annually

MetaBIM Logo MetaBIM

Enterprise Account Executive

Software • Database • Facilities Maintenance
Remote
United States
5 Employees
20-150K Annually

ClassWallet Logo ClassWallet

Manager, Implementations

Edtech • Fintech • Payments • Social Impact • Financial Services • Big Data Analytics
Remote
United States
89 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account