Manifest is on a mission to secure the global software and AI supply chain. Our platform automates the discovery and analysis of risks across internally built and third-party software and AI systems, giving security, product, and engineering teams complete visibility into the components and dependencies that make up their technology stack. From product security and AI risk to supplier risk and compliance, we help teams trust the software and AI they build and buy.
Founded by alumni from the Department of Defense, CISA, and Palantir, Manifest is backed by leading investors including Ensemble VC, First Round Capital, Homebrew, BoxGroup, XYZ Venture Capital, AE Ventures, Leap435, and Overmatch VC. The company partners with the US Air Force, DHS, Global 2000 companies, and critical infrastructure organizations across defense, automotive, and financial services to bring transparency, resilience, and trust to modern digital systems.
About the RoleManifest is seeking an experienced Infrastructure Engineer to own the design, development, implementation, and ongoing operation of Manifest's infrastructure and build/release pipelines. You will extend and improve existing processes and systems, ensuring pipelines are fast, secure, performant, and scalable. By dogfooding Manifest's core products, you will be closely involved with Product, driving roadmap direction and helping users build and deliver software with less risk and greater security.
What You Will Do
- Own the design, development, implementation, and ongoing operation of infrastructure and build/release pipelines
- Extend and improve existing processes to ensure pipelines are fast, secure, performant, and scalable
- Deploy IaC and automation (Terraform, Ansible, Helm, Go, etc.) to support platform and customer requirements
- Operate and sustain cloud-based CI/CD pipelines using DevSecOps principles and a shift-left mindset
- Automate application deployment using container technology (Kubernetes, GitHub, and other CI/CD tools)
- Build tools and packaging to support deployment across varied environments (AWS, Azure/GCP, on-prem, air-gapped, FedRAMP)
- Integrate DevSecOps tools and services into automated pipelines throughout the customer SDLC
- Research and adopt open-source tools to build and secure the development pipeline
- Implement and improve observability across MELT (Metrics, Events, Logs, Traces), including presentation and alerting
- Safely expose public endpoints (UIs, APIs) using load balancers, CDNs, and related tools
- Collaborate closely with Product to help drive roadmap direction and improve how users build and deliver software
- Dogfood Manifest's core products as part of day-to-day work
- Assisting developers in delivering secure applications (CORS policies, API security engineering)
Required Skills
- IaC and automation tools: Terraform, Ansible, Helm, Go
- Cloud-based CI/CD pipelines with a DevSecOps and automation-first approach
- Kubernetes — deploying, operating, and troubleshooting in cloud environments
- Networking and runtime troubleshooting, including complex remote and air-gapped environments
- Building and packaging software for multiple runtime environments (cloud, on-prem, air-gapped, FedRAMP)
- Exposing secure public endpoints using load balancers, CDNs, and related tools
- Strong verbal and written communication, including technical and design documentation
Required Qualifications
- Experience routinely developing and deploying IaC and automation to support platform and customer needs
- Experience operating and sustaining cloud-based CI/CD pipelines with a shift-left and DevSecOps mindset
- Experience automating application deployments using container technology in cloud environments
- Experience building tools and packaging for varied runtime environments (cloud, on-prem, air-gapped)
- Experience integrating DevSecOps tools into automated pipelines across the SDLC
- Experience deploying and operating applications with Kubernetes in a cloud environment
- Prior experience with commercial software products (SaaS and on-prem) serving external/3rd-party customers
Desired / Bonus Skills and Experience
- Ability to deploy Kubernetes in edge environments (bare VM and bare metal)
- Packaging software for on-prem/edge using Zarf, Helm charts, Packer, virtual appliances, etc.
- Securing AWS environments, containers, and Kubernetes clusters
- Experience with US Government networks (FedRAMP, CMMC, etc.)
- SDLC security tooling — SCA, DAST, SAST, and other DevSecOps tools
- Deploying and supporting self-hosted LLMs
- Secure SDLC practices, including bug bounty programs and software vulnerability management (SVM)
Salary: $150,000 – $210,000/year + meaningful stock options. Placement within the range depends on experience and skills.
- 🔍 Help organizations gain visibility into their software supply chain and improve security
- 🌎 Fully remote (with potential for hybrid co-working)
- 🌴 Unlimited PTO (taken seriously)
- 🏥 Medical, dental, and vision insurance — 100% covered for you and your dependents
- 💵 Competitive salary and meaningful stock options
- 🏦 401(k) and retirement options
- ⚒️ Ground-floor opportunity at a well-funded, early-stage startup
- 🦄 Additional benefits to come (retirement, holiday gifts, etc.)
Skills Required
- Terraform, Ansible, Helm, and Go experience for infrastructure as code and automation
- Experience with cloud-based CI/CD pipelines using DevSecOps and automation-first practices
- Experience deploying, operating, and troubleshooting Kubernetes in cloud environments
- Networking and runtime troubleshooting experience, including remote and air-gapped environments
- Experience building and packaging software for cloud, on-premises, air-gapped, and FedRAMP environments
- Experience exposing secure public endpoints using load balancers, CDNs, and related tools
- Strong verbal and written communication, including technical and design documentation
- Experience developing and deploying infrastructure as code and automation for platform and customer needs
- Experience automating application deployments using container technology in cloud environments
- Experience integrating DevSecOps tools into automated pipelines across the software development lifecycle
- Prior experience with commercial SaaS and on-premises software products serving external customers
- Ability to deploy Kubernetes in edge environments on bare virtual machines and bare metal
- Experience packaging software for on-premises or edge environments using Zarf, Helm charts, Packer, or virtual appliances
- Experience securing AWS environments, containers, and Kubernetes clusters
- Experience with U.S. government networks and standards such as FedRAMP or CMMC
- Experience with SDLC security tooling including SCA, DAST, and SAST
- Experience deploying and supporting self-hosted LLMs
- Experience with secure SDLC practices, bug bounty programs, or software vulnerability management
What We Do
Manifest is a software supply chain company that helps organizations of all sizes with their entire SBOM management flows.

.png)
.png)






