DevSecOps Engineer
Virta Health
Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.
Got this interview? Our apps help you get the job.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
58 open devsecops roles across 39 companies are on ApplySarthi right now, most of them in Bengaluru (6), Hyderabad (2), Pune (1).
- Cybersecurity Engineer – DevSecOpsJobgether
- Associate Director - DevSecOps & Cloud EngineeringAstrazeneca · bengaluru
- Staff DevSecOps Engineerionq
- Senior DevSecOps [US Client]Pwc
- DevSecOps Engineer (AWS/Azure)Capco
What devsecops roles keep asking for: CI/CD (79%), AWS (60%), Terraform (60%), Python (47%), Kubernetes (45%), IAM (43%), Jenkins (34%), Shell scripting (34%) — counted across their open postings here.
Devsecops Engineer jobs in the United States · AWS jobs · CI/CD jobs · GCP jobs · IAM jobs
Virta Health has 2 open roles listed here.
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for devsecops roles keep coming back to CI/CD, AWS, Terraform, Python. Practise those questions before you sit with Virta Health.
Questions you are likely to be asked
- Why do you want to join Virta Health?
- What is your experience with IAM? Tell me one thing you learned the hard way.
- Walk me through a system you built. How was it designed, and what would you change now?
- Tell me about a hard bug you tracked down. How did you find the cause?
- How do you decide what to test, and what does good code review look like to you?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the DevSecOps Engineer at Virta Health interview free →Virta Health is pioneering a new standard of care for people to reclaim their lives. We are in the midst of a public health crisis: obesity rates are at an all-time high and over half of US adults have type 2 diabetes or prediabetes, and despite billions spent on new treatments, outcomes are largely worse. Virta reverses these diseases and delivers life-changing results by pairing individualized nutrition with ongoing care from a clinical support team. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives. As we rapidly scale our impact, we're seeking a passionate DevSecOps engineer to help build and mature our application security program. Working closely with our security lead, you'll implement best practices and help embed security principles across the org. If you thrive on building secure systems, automation, fostering a security-conscious culture, and making a tangible difference in protecting sensitive health information, this role is for you. # Responsibilities As a DevSecOps Engineer, you will help secure Virta's applications and platform, directly contributing to the trust our members and partners place in us. You'll collaborate across teams to ensure security is a seamless part of our development lifecycle. - **Improve Security Design:** Help assess our current security controls within GCP and Kubernetes, identify areas for improvement, and contribute to the maturation of our security posture from good to great. - **Champion Secure Development:** Partner closely with Engineering, Product, and Platform teams to integrate security best practices early and often ("shift-left") into the software development lifecycle. - **Build and Automate:** Design, implement, and manage security tooling and automation to streamline vulnerability detection, remediation, and compliance verification. Replace manual processes with efficient, automated solutions. - **Refine Access Control:** Evolve our identity and access management (IAM) strategy, ensuring least-privilege access and robust auditing capabilities across our systems. - **Strengthen Network Security:** Continuously improve our network security architecture, policies, and controls within our cloud environment. - **Develop Clear Standards:** Establish, document, and communicate practical security policies, standards, and guidelines for engineering teams. - **Support Security Initiatives:** Drive vulnerability management efforts and enhance our incident response preparedness, ensuring we are ready to handle potential threats effectively. - **Cultivate Security Awareness:** Act as a security evangelist, promoting security awareness and best practices throughout the engineering organization. # 90 Day Plan Joining a new company and stepping into a foundational role takes time. Here’s what you can expect as you get started and begin making your mark: - **Immerse Yourself:** Your initial focus will be on understanding Virta's culture, our mission, our engineering workflows, and the nuances of our cloud platform (GCP/Kubernetes). You'll connect with key engineers and stakeholders across different teams. - **Learn the Landscape:** You'll dive into our existing systems, CI/CD pipelines, and current security tooling and configurations to get a clear picture of where we stand today. - **Assess & Identify Opportunities:** Leveraging your expertise, you'll begin evaluating our current security posture, including critical areas like our IAM implementation (RBAC), data security practices, network controls, and existing security policies. You'll help identify high-impact areas for improvement. - **Start Building:** You'll quickly move into hands-on work, likely starting with foundational projects such as refining IAM roles, enhancing specific security configurations, or beginning to develop key security automation or documentation. # Must-Haves - Understanding and practical experience in securing cloud-native applications and infrastructure, particularly in Kubernetes environments. GCP experience is strongly preferred. - Strong grasp of networking concepts, identity management (IAM), encryption, and common web application vulnerabilities (e.g., OWASP Top 10). - Strong communication skills with the ability to clearly articulate complex security concepts to diverse audiences and influence technical direction across teams. - Hands-on experience in application security, including secure coding practices, vulnerability management, and security testing (SAST, DAST, IAST); exposure to threat modeling is a plus. - Proficiency in Infrastructure as Code (IaC) tools, specifically Terraform. - Development experience with Go and/or Python. - 5-7+ years of experience with 2+ at a high growth startup or similar environment # Values-driven culture Virta’s company values drive our culture, so you’ll do well if: - You put **_people first_** and take care of yourself, your peers, and our patients equally - You have a strong sense of **_ownership_** and take initiative while empowering others to do the same - You prioritize positive **_impact_** over busy work - You have **_no ego_** and understand that everyone has something to bring to the table regardless of experience - You appreciate **_transparency_** and promote trust and empowerment through open access of information - You are **_evidence-based_** and prioritize data and science over seniority or dogma - You **_take risks and rapidly iterate_** Is this role not quite what you're looking for? [_Join our Talent Community_](https://jobs.ashbyhq.com/virtahealth/form/talent-community-form) and [_follow us on Linkedin_](https://www.linkedin.com/company/virta-health) to stay connected! *Virta has a location based compensation structure. Starting pay will be based on a number of factors and commensurate with qualifications & experience. For this role, the compensation range is $179,451 - 187,900 Information about Virta’s benefits is on our Careers page at:* [*https://www.virtahealth.com/careers*](https://www.virtahealth.com/careers)*.* *As part of your duties at Virta, you may come in contact with sensitive patient information that is governed by HIPAA. Throughout your career at Virta, you will be expected to follow Virta's security and privacy procedures to ensure our patients' information remains strictly confidential. Security and privacy training will be provided.* *As a remote-first company, our team is spread across various locations with office hubs in Denver and San Francisco.* *Clinical roles: We currently **do not hire** in the following states: AK, HI, RI* *Corporate roles: We currently **do not hire** in the following states: AK, AR, DE, HI, ME, MS, NM, OK, SD, VT, WI.* *Virta uses Ashby as its applicant tracking system, which incorporates AI-powered tools (provided by OpenAI, AWS, and Google Gemini) in certain aspects of the recruiting process, including application review, candidate screening, and interview note taking; your data is not used to train AI models, and all final hiring decisions are made by Virta Health personnel. For more information, see Ashby's AI Terms at* [*https://www.ashbyhq.com/resources/terms-ai-features*](https://www.ashbyhq.com/resources/terms-ai-features) *#LI-remote*
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- IT EngineerVirta Health
- DevSecOps EngineerIBM
- DevSecOps EngineerSutherland · hyderabad
- DevSecOps EngineerProdigal · bengaluru
- DevSecOps EngineerQuantum Business Advisory USA
- DevSecOps EngineerTradeify.co
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on wellfound · posted 2026-08-27. ApplySarthi collects openings and links to application pages; the role is advertised by Virta Health, not by us.