Vanilla
Engineering
SeniorDevSecOpsEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior DevSecOps Engineer at Vanilla. Skills: DevSecOps, Cloud security, Infrastructure security, Security operations. Operate security tooling. Tune security tooling”
Industry & Context.
Root cause analysis; Troubleshooting
What They're Looking For.
Must Have
Hands-on AWS experience, Experience with infrastructure-as-code, Strong understanding of IAM, Strong understanding of network security, Strong understanding of encryption, Strong understanding of secrets management, Hands-on vulnerability management experience, Experience with threat modeling, Experience with secure code review, Experience with CI/CD security gating, Scripting and automation skills
Nice to Have
Experience operating security tooling, Familiarity with SentinelOne, Familiarity with Sublime, Familiarity with Panther, Familiarity with Cloudflare, Prior incident response experience, Prior tabletop exercise facilitation experience, Exposure to AI/ML security, Experience in fintech, Experience in wealthtech, Experience in regulated industries, Familiarity with supply chain security
What You'll Do.
Operate security tooling
Tune security tooling
Monitor security alerts
Triage security alerts
Respond to security requests
Manage vCISO relationship
Coordinate cloud security posture
Coordinate endpoint coverage
Coordinate SOC 24x7 operations
Own penetration test lifecycle
Select penetration test vendors
Scope penetration tests
Coordinate penetration tests
Report penetration tests
Scope AI red team engagements
Coordinate AI red team engagements
Run tabletop exercises
Maintain incident response playbook
Build security roadmap
Maintain security roadmap
Evolve pre-deploy security gates
Run vulnerability management
Prioritize vulnerabilities
Remediate vulnerabilities
Conduct threat modeling
Champion secure coding practices
Scope AI red team exercises
Coordinate AI red team exercises
Assess security of AI/ML pipelines
Assess security of inference endpoints
Assess security of third-party AI vendors
Implement AI output guardrails
Maintain AI output guardrails
Establish data governance practices
How You'll Work.
Team & Collaboration
Director of Engineering; vCISO; External partners; Engineering teams; Engineering leadership
Process & Methodology
Roadmap planning
Full Job Description
ABOUT US We’re a startup with big ambitions: to make estate planning modern, visual, and intelligent. Vanilla https://www.justvanilla.com/ is the first AI-powered estate advisory platform, built by advisors, planners, and attorneys to transform how wealth is transferred across generations. Our technology unifies scenario modeling, client visualization, and document creation into one seamless, digital experience. Our team brings together diverse subject matter expertise across estate planning, wealth management, and scaling SaaS startups. We’re distributed across the U.S., with a mix of fully remote and hybrid roles, and we embrace flexibility while staying closely connected. At Vanilla, you’ll join curious builders and problem-solvers who thrive on speed, autonomy, and impact. Here, you won’t just join a company, you’ll help create it. If you’re excited to tackle hard problems, move quickly, and see your work shape both an industry and a growing startup, we’d love to meet you. WORKING LOCATION This role is a remote position, you must be based out of one of the following states: Arizona, California, Colorado, Connecticut, Florida, Georgia, Idaho, Illinois, Kentucky, Maine, Massachusetts, Minnesota, New Jersey, New York, Ohio, Pennsylvania, Texas, Utah or Washington. JOB SUMMARY We’re looking for a Senior DevSecOps Engineer to own and operate our security tooling, manage key vendor relationships, and drive our application and cloud security programs forward. This is a hands-on, high-ownership role: you’ll be the day-to-day operator of our security stack, the point person for our vCISO engagement, and the engineer building the processes that keep Vanilla’s platform and infrastructure secure. You’ll also own the operational cadence of our security program: managing vendor-led pen tests, running tabletop exercises, maintaining our incident response playbook, and building a multi-quarter security roadmap. This role is ideal for a strong DevOps or infrastructure engineer w
Applying for this Senior DevSecOps Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Vanilla?
Real rants from real employees. Read before you apply.