DevSecOps Engineer

Virta Health
$179,451 - $187,900Remote

About The Position

Virta Health is pioneering a new standard of care for people to reclaim their lives. We are in the midst of a public health crisis: obesity rates are at an all-time high and over half of US adults have type 2 diabetes or prediabetes, and despite billions spent on new treatments, outcomes are largely worse. Virta reverses these diseases and delivers life-changing results by pairing individualized nutrition with ongoing care from a clinical support team. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives. As we rapidly scale our impact, we're seeking a passionate DevSecOps engineer to help build and mature our application security program. Working closely with our security lead, you'll implement best practices and help embed security principles across the org. If you thrive on building secure systems, automation, fostering a security-conscious culture, and making a tangible difference in protecting sensitive health information, this role is for you.

Requirements

  • Understanding and practical experience in securing cloud-native applications and infrastructure, particularly in Kubernetes environments. GCP experience is strongly preferred.
  • Strong grasp of networking concepts, identity management (IAM), encryption, and common web application vulnerabilities (e.g., OWASP Top 10).
  • Strong communication skills with the ability to clearly articulate complex security concepts to diverse audiences and influence technical direction across teams.
  • Hands-on experience in application security, including secure coding practices, vulnerability management, and security testing (SAST, DAST, IAST); exposure to threat modeling is a plus.
  • Proficiency in Infrastructure as Code (IaC) tools, specifically Terraform.
  • Development experience with Go and/or Python.
  • 5-7+ years of experience with 2+ at a high growth startup or similar environment

Nice To Haves

  • Exposure to threat modeling is a plus.

Responsibilities

  • Help secure Virta's applications and platform, directly contributing to the trust our members and partners place in us.
  • Collaborate across teams to ensure security is a seamless part of our development lifecycle.
  • Help assess our current security controls within GCP and Kubernetes, identify areas for improvement, and contribute to the maturation of our security posture from good to great.
  • Partner closely with Engineering, Product, and Platform teams to integrate security best practices early and often ("shift-left") into the software development lifecycle.
  • Design, implement, and manage security tooling and automation to streamline vulnerability detection, remediation, and compliance verification. Replace manual processes with efficient, automated solutions.
  • Evolve our identity and access management (IAM) strategy, ensuring least-privilege access and robust auditing capabilities across our systems.
  • Continuously improve our network security architecture, policies, and controls within our cloud environment.
  • Establish, document, and communicate practical security policies, standards, and guidelines for engineering teams.
  • Drive vulnerability management efforts and enhance our incident response preparedness, ensuring we are ready to handle potential threats effectively.
  • Act as a security evangelist, promoting security awareness and best practices throughout the engineering organization.

Benefits

  • Information about Virta’s benefits is on our Careers page at: https://www.virtahealth.com/careers.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service