Senior DevSecOps Engineer
Phoenix, NM - USA
Department:
Job Summary
Virtuous is on a mission to inspire global generosity by helping nonprofits build better relationships with their donors. We offer a modern software platform that provides mid-sized charities with elegant tools for fundraising marketing volunteerism and online giving.
Our talented team is driven to disrupt the status quo in the nonprofit sector. We are hungry humble and committed to delivering best-in-class software solutions customer success interactions and sales experiences to the worlds leading nonprofits
We also recognize the importance of giving back and making a difference in the communities where we live and work. Thats why we practice radical generosity by volunteering at nonprofits or going the extra mile for our team and the customers we serve. We take our work seriously but we dont take ourselves too seriously. We believe that life is too short not to love what you do.
The ideal candidate for Virtuous embodies our values by:
Asking questions with a spirit of curiosity
Giving feedback freely with candor & grace welcoming it in return
Displaying a passion for philanthropy and technology
Serving with joy. Everyone is willing to make the coffee!
Celebrating the wins & milestones of others
Assuming good intent & demonstrating trust in others
Pursuing relationships with people different from themselves & creates space to be human
Find our core values & more here.
Position Summary
Virtuous is hiring a Senior DevSecOps Engineer to strengthen the security posture of our products cloud infrastructure and software delivery ecosystem.
Reporting to the Director of IT & Security youll partner with Engineering Cloud Engineering DevOps Architecture and Security teams to build security into the way we design develop deploy and operate software. Youll improve the security of our products and cloud environment by reducing security debt modernizing security practices and building secure-by-default solutions through automation and engineering.
This role is embedded within a collaborative DevOps function and is ideal for someone who enjoys solving security problems through code automation and engineering rather than manual reviews or gatekeeping. Were looking for an engineer who is naturally curious challenges conventional approaches and safely leverages AI-assisted tooling and modern engineering practices to create scalable high-impact solutions.
Responsibilities
Security Engineering & Cloud Security
Design implement and continuously improve secure Azure cloud architectures networking governance and infrastructure to support scalable secure-by-default engineering.
Strengthen cloud security posture through infrastructure hardening segmentation secure connectivity patterns RBAC/PIM Azure Policy and automated guardrails.
Improve security visibility through logging monitoring SIEM integrations detection engineering and operational security tooling.
Continuously assess and remediate cloud security risks inherited infrastructure weaknesses configuration drift and operational security gaps.
Embed security into infrastructure platforms and engineering workflows by collaborating with Cloud Engineering and DevOps teams to build secure-by-default solutions.
Application Security & DevSecOps
Identify and address security risks in application architecture authentication APIs and data flows throughout the product lifecycle.
Integrate security capabilities into CI/CD pipelines and engineering workflows including SAST DAST dependency scanning secrets management software supply-chain security and policy-based controls.
Lead threat modeling architecture reviews and secure design discussions to identify security risks early in the software development lifecycle.
Build developer-friendly security guardrails reusable patterns and automations that improve security without slowing delivery velocity.
Drive timely remediation of security findings by enabling engineering teams with practical guidance automation and secure-by-default patterns.
Security Modernization & Operational Excellence
Lead efforts to reduce security backlog cloud governance drift stale permissions infrastructure weaknesses technical debt and operational security risk.
Balance risk reduction engineering impact and business priorities when determining what to remediate standardize automate or defer.
Collaborate with Security leadership to improve incident readiness operational maturity security visibility and organizational resilience.
Help modernize inherited systems while improving container security Kubernetes security and secure cloud-native engineering practices.
Automation AI & Engineering Enablement
Leverage automation APIs scripting AI-assisted tooling and emerging technologies to improve security operations engineering productivity and organizational effectiveness.
Continuously challenge traditional approaches by identifying opportunities to automate simplify or reimagine security and engineering workflows.
Build self-service capabilities reusable tooling and scalable workflows that improve developer experience while strengthening security outcomes.
Evaluate and adopt modern engineering practices AI-assisted workflows and emerging technologies that improve security outcomes accelerate remediation and increase engineering effectiveness.
Act as a force multiplier across Security Engineering and Cloud Operations by creating systems that increase organizational leverage and effectiveness.
What Success Looks Like
Security controls are embedded into engineering workflows without creating unnecessary friction or slowing delivery velocity.
Application and cloud security posture improve through strong engineering adoption operational ownership and scalable guardrails.
Security backlog infrastructure debt and operational risk are consistently reduced through pragmatic remediation and automation.
Cloud infrastructure is secure resilient observable and governed through secure-by-default engineering practices.
Automation AI-assisted engineering and intelligent workflows measurably improve team effectiveness remediation velocity and operational scalability.
Engineering Security and Cloud teams operate as trusted partners with shared ownership of reliability security and business outcomes.
You Must Have
5 years of experience in Security Engineering Application Security Cloud Security DevSecOps or related security-focused engineering roles within cloud-native SaaS environments.
Strong experience designing securing and modernizing Azure environments including Azure networking governance RBAC/PIM Azure Policy and secure connectivity patterns.
Experience improving application security through secure SDLC practices threat modeling CI/CD security controls and engineering partnership.
Hands-on experience implementing DevSecOps capabilities such as SAST DAST dependency scanning secrets management software supply-chain security and policy automation.
Experience with Kubernetes Docker container security IaC and modern cloud-native platforms.
Hands-on experience with GitHub GitHub Actions GitHub Advanced Security (or equivalent) SIEM platforms observability tooling and cloud security technologies.
Strong automation scripting troubleshooting and cross-functional collaboration skills with a focus on scalable solutions and operational improvement.
Experience leveraging AI-assisted engineering tools (such as GitHub Copilot Claude Code or similar) and a demonstrated curiosity for applying automation and emerging technologies to improve security and engineering outcomes.
What We Offer
Market competitive pay leveraging Carta data
Employee recognition through Bonusly (birthdays anniversaries achievements etc.)
401(k) retirement plan with company matching- 50% match up to 6% of compensation after 90 days
We value our employees work-life balance and encourage taking advantage of Unlimited PTO
Supportive time off including paid volunteer days and company holidays
Employer-contributed healthcare benefits encompassing medical dental and vision coverage with plans available for dependents and choices for Health Savings Accounts (HSA) and Flexible Spending Accounts (FSA).
12 weeks primary parent leave 4 weeks secondary parent leave - full pay (adoption as well)
We pride ourselves on Community and host exciting company outings and events.
Weve recently noticed an increase in recruitment scams where individuals are impersonating recruiters to obtain personal or financial information through fraudulent interviews and job offers.
Please note that all legitimate communication from Virtuous will only come from the @ domain. If you receive a message from other domains even if they look similar (e.g. or ) they arenot legitimateand we recommend disregarding it immediately.
Required Experience:
Senior IC
About Company
Virtuous gives you the nonprofit CRM, fundraising, volunteer, and marketing tools you need to create more responsive donor experiences and grow giving.