DevSecOps / Cloud Security Engineer

Vermont Information Processing
$180,000Remote

About The Position

Vermont Information Processing is the leading technology provider to the beverage industry, route accounting, warehouse, delivery, and sales platforms trusted by distributors, bottlers, and over 1,600 suppliers for 50+ years. Backed by Warburg Pincus, VIP is investing in security as a first-class discipline across a growing family of companies. You will join at the moment the program is being built, with executive sponsorship, a funded roadmap, and visible board-level impact. You will own security of how VIP builds and runs software, the release pipeline and the cloud. Today the ingredients exist without enforcement: SonarQube and CAST are installed but code-security checks are not yet required before release; CrowdStrike cloud security posture management is deployed but early-stage; a 15-domain cloud security framework with forty implementation runbooks is authored and live in its first environment. Your mandate is to turn all of it on and make secure the default path for our engineering teams. You will work hand-in-hand with a junior cloud security engineer on our India team and have direct executive sponsorship: this role exists because our CIO told the board that no one owns pipeline security and fixed it.

Requirements

  • 5+ years across DevOps/platform and security engineering, with real ownership of CI/CD systems (Jenkins, Bitbucket/Git-based pipelines) and AWS.
  • Hands-on with SAST/DAST/SCA tooling and the craft of introducing gates developers accept.
  • Strong AWS security depth: IAM, organizations/accounts, networking, KMS, and posture management tooling.
  • Infrastructure-as-code and automation fluency (Terraform/CloudFormation, Python).
  • Collaborative style suited to distributed teams; comfortable mentoring and working across time zones.

Nice To Haves

  • Azure exposure (two of our acquired units run Azure).
  • Experience with Okta-AWS federation, Rubrik or equivalent backup platforms, and container security.
  • AWS Security Specialty, CCSP, or GIAC cloud certifications.

Responsibilities

  • Secure release pipeline: make code-security scanning (SAST/SCA) a required, low-friction gate in CI/CD across our development teams; introduce automated application testing (DAST) and secrets scanning.
  • Cloud security framework rollout: operationalize our 15-domain, cloud-agnostic framework and CrowdStrike CSPM across all AWS estates (VIP-core, VIP India, acquired units), misconfiguration burn-down, guardrails, and workflow integration.
  • Cloud identity & access: centralize AWS access through Okta, eliminate local credentials, and implement least-privilege roles; define the tagging standard so every resource has an owner and classification.
  • Secrets & data protection: stand up managed secrets with rotation (replacing env-var and ad-hoc storage), encryption-at-rest verification, and support the data-leak-prevention rollout beyond email.
  • Resilience engineering: configure tamper-proof (immutable) backup tiers on our Rubrik platform and help define recovery-time objectives with IT.
  • Enablement & mentorship: build paved-road patterns and developer guidance; grow our India-based junior cloud security engineer; extend the framework to newly acquired units.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service