À propos de ce poste DevSecOps / Cloud Security Engineer chez Vermont Information Processing
Annual Compensation: $170,000 - $200,000
Position Type: Full Time, Remote
About us
Vermont Information Processing is the leading technology provider to the beverage industry, route accounting, warehouse, delivery, and sales platforms trusted by distributors, bottlers, and over 1,600 suppliers for 50+ years. Backed by Warburg Pincus, VIP is investing in security as a first-class discipline across a growing family of companies. You will join at the moment the program is being built, with executive sponsorship, a funded roadmap, and visible board-level impact.
About the role
You will own security of how VIP builds and runs software, the release pipeline and the cloud. Today the ingredients exist without enforcement: SonarQube and CAST are installed but code-security checks are not yet required before release; CrowdStrike cloud security posture management is deployed but early-stage; a 15-domain cloud security framework with forty implementation runbooks is authored and live in its first environment. Your mandate is to turn all of it on and make secure the default path for our engineering teams. You will work hand-in-hand with a junior cloud security engineer on our India team and have direct executive sponsorship: this role exists because our CIO told the board that no one owns pipeline security and fixed it.
What you will own
- Secure release pipeline: make code-security scanning (SAST/SCA) a required, low-friction gate in CI/CD across our development teams; introduce automated application testing (DAST) and secrets scanning.
- Cloud security framework rollout: operationalize our 15-domain, cloud-agnostic framework and CrowdStrike CSPM across all AWS estates (VIP-core, VIP India, acquired units), misconfiguration burn-down, guardrails, and workflow integration.
- Cloud identity & access: centralize AWS access through Okta, eliminate local credentials, and implement least-privilege roles; define the tagging standard so every resource has an owner and classification.
- Secrets & data protection: stand up managed secrets with rotation (replacing env-var and ad-hoc storage), encryption-at-rest verification, and support the data-leak-prevention rollout beyond email.
- Resilience engineering: configure tamper-proof (immutable) backup tiers on our Rubrik platform and help define recovery-time objectives with IT.
- Enablement & mentorship: build paved-road patterns and developer guidance; grow our India-based junior cloud security engineer; extend the framework to newly acquired units.
What success looks like in year one
- Code-security checks required on 100% of production releases, with developer-experience friction low enough that teams defend the gate.
- CSPM operationalized across every AWS account with critical misconfigurations at zero and a sustained burn-down of the rest.
- AWS access fully Okta-federated; no shared or local console credentials; tagging standard adopted.
- Immutable backup tier live; secrets rotation automated for priority systems.
What you bring
- 5+ years across DevOps/platform and security engineering, with real ownership of CI/CD systems (Jenkins, Bitbucket/Git-based pipelines) and AWS.
- Hands-on with SAST/DAST/SCA tooling and the craft of introducing gates developers accept.
- Strong AWS security depth: IAM, organizations/accounts, networking, KMS, and posture management tooling.
- Infrastructure-as-code and automation fluency (Terraform/CloudFormation, Python).
- Collaborative style suited to distributed teams; comfortable mentoring and working across time zones.
Nice to have
- Azure exposure (two of our acquired units run Azure).
- Experience with Okta-AWS federation, Rubrik or equivalent backup platforms, and container security.
- AWS Security Specialty, CCSP, or GIAC cloud certifications.
Compensation is based on a variety of factors including skills, experience and industry background. The range listed here represents our best faith estimate for the role.
All full-time job offers are contingent upon passing a pre-employment drug screening and background check.