
DevSecOps Engineer
Hover or tap a row for full statistics (EUR / month on this chart).
Salary analysis
Compared with the selected benchmark ("Market Average: DevSecOps Engineer"), this listing's salary midpoint is about 21% higher. The offer sits above the benchmark range (€11,575–€13,745). The listed pay band (€14,954–€15,658) is tighter than the benchmark, which suggests lower salary variability. This benchmark is based on 1 comparable listings.
| Market | Lower bound (25th percentile) | Median | Upper bound (75th percentile) |
|---|---|---|---|
| Market Average: DevSecOps Engineer | €11,575/per month | €12,660/per month | €13,745/per month |
Virta Health is leading a new standard of care. We are seeking a passionate DevSecOps engineer to help build and mature our application security program. You’ll implement best practices and embed security principles across the org. Responsibilities include improving security design, secure development, automation, IAM, network security, standards, vulnerability management, and security awareness. The 90 Day Plan covers onboarding, landscape learning, assessment of posture, and initial builds. Must-Haves include cloud-native security experience (Kubernetes, GCP preferred), IAM, encryption, OWASP Top 10, communication, secure coding, IaC with Terraform, Go/Python, and 5-7+ years at a high-growth startup. Virta emphasizes values like People First, Ownership, Impact, No Ego, Transparency, Evidence-based decisions, and rapid iteration. The role is remote-first with office hubs in Denver and San Francisco; some state hire restrictions apply. Salary range is $179,451 - 187,900 per year in USD. HIPAA considerations apply. Remote work with #LI-remote tag.
Job Details
Responsibilities
- As a DevSecOps Engineer, you will help secure Virta's applications and platform, directly contributing to the trust our members and partners place in us.
- You'll collaborate across teams to ensure security is a seamless part of our development lifecycle.
- Improve Security Design: Help assess our current security controls within GCP and Kubernetes, identify areas for improvement, and contribute to the maturation of our security posture from good to great.
- Champion Secure Development: Partner closely with Engineering, Product, and Platform teams to integrate security best practices early and often ("shift-left") into the software development lifecycle.
- Build and Automate: Design, implement, and manage security tooling and automation to streamline vulnerability detection, remediation, and compliance verification. Replace manual processes with efficient, automated solutions.
- Refine Access Control: Evolve our identity and access management (IAM) strategy, ensuring least-privilege access and robust auditing capabilities across our systems.
- Strengthen Network Security: Continuously improve our network security architecture, policies, and controls within our cloud environment.
- Develop Clear Standards: Establish, document, and communicate practical security policies, standards, and guidelines for engineering teams.
- Support Security Initiatives: Drive vulnerability management efforts and enhance our incident response preparedness, ensuring we are ready to handle potential threats effectively.
- Cultivate Security Awareness: Act as a security evangelist, promoting security awareness and best practices throughout the engineering organization.
Requirements
- Understanding and practical experience in securing cloud-native applications and infrastructure, particularly in Kubernetes environments. GCP experience is strongly preferred.
- Strong grasp of networking concepts, identity management (IAM), encryption, and common web application vulnerabilities (e.g., OWASP Top 10).
- Strong communication skills with the ability to clearly articulate complex security concepts to diverse audiences and influence technical direction across teams.
- Hands-on experience in application security, including secure coding practices, vulnerability management, and security testing (SAST, DAST, IAST); exposure to threat modeling is a plus.
- Proficiency in Infrastructure as Code (IaC) tools, specifically Terraform.
- Development experience with Go and/or Python.
- 5-7+ years of experience with 2+ at a high growth startup or similar environment
Skills & Technologies

| Location | Active listings |
|---|---|
| Remote - Global | 3 |
| Denver, CO | 1 |
| San Francisco, CA | 1 |
| Role type | Active listings |
|---|---|
| Front End Specialist | 1 |
| Senior Manager | 1 |
| Data Analyst | 1 |
| Role level | Active listings |
|---|---|
| Senior | 1 |
| Mid-Level | 1 |
| Executive | 1 |
Related Opportunities
Discover more opportunities that match your interests and skills