Senior DevSecOps Engineer
Virtuous
| Company | Virtuous |
| Category | Engineering |
| Location | Phoenix |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 28 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
ABOUT US
Virtuous is on a mission to inspire global generosity by helping nonprofits build better relationships with their donors. We offer a modern software platform that provides mid-sized charities with elegant tools for fundraising, marketing, volunteerism, and online giving.
Our talented team is driven to disrupt the status quo in the nonprofit sector. We are hungry, humble, and committed to delivering best-in-class software solutions, customer success interactions, and sales experiences to the world’s leading nonprofits
We also recognize the importance of giving back and making a difference in the communities where we live and work. That's why we practice radical generosity by volunteering at nonprofits or going the extra mile for our team and the customers we serve. We take our work seriously, but we don’t take ourselves too seriously. We believe that life is too short not to love what you do.
The ideal candidate for Virtuous embodies our values by:
- Asking questions with a spirit of curiosity
- Giving feedback freely with candor & grace, welcoming it in return
- Displaying a passion for philanthropy and technology
- Serving with joy. Everyone is willing to make the coffee!
- Celebrating the wins & milestones of others
- Assuming good intent & demonstrating trust in others
- Pursuing relationships with people different from themselves & creates space to be human
Find our core values & more here https://virtuous.org/company/about/.
Position Summary
Virtuous is hiring a Senior DevSecOps Engineer to strengthen the security posture of our products, cloud infrastructure, and software delivery ecosystem.
Reporting to the Director of IT & Security, you'll partner with Engineering, Cloud Engineering, DevOps, Architecture, and Security teams to build security into the way we design, develop, deploy, and operate software. You'll improve the security of our products and cloud environment by reducing security debt, modernizing security practices, and building secure-by-default solutions through automation and engineering.
This role is embedded within a collaborative DevOps function and is ideal for someone who enjoys solving security problems through code, automation, and engineering rather than manual reviews or gatekeeping. We're looking for an engineer who is naturally curious, challenges conventional approaches, and safely leverages AI-assisted tooling and modern engineering practices to create scalable, high-impact solutions.
Responsibilities
Security Engineering & Cloud Security
- Design, implement, and continuously improve secure Azure cloud architectures, networking, governance, and infrastructure to support scalable, secure-by-default engineering.
- Strengthen cloud security posture through infrastructure hardening, segmentation, secure connectivity patterns, RBAC/PIM, Azure Policy, and automated guardrails.
- Improve security visibility through logging, monitoring, SIEM integrations, detection engineering, and operational security tooling.
- Continuously assess and remediate cloud security risks, inherited infrastructure weaknesses, configuration drift, and operational security gaps.
- Embed security into infrastructure, platforms, and engineering workflows by collaborating with Cloud Engineering and DevOps teams to build secure-by-default solutions.
Application Security & DevSecOps
- Identify and address security risks in application architecture, authentication, APIs, and data flows throughout the product lifecycle.
- Integrate security capabilities into CI/CD pipelines and engineering workflows, including SAST, DAST, dependency scanning, secrets management, software supply-chain security, and policy-based controls.
- Lead threat modeling, architecture reviews, and secure design discussions to identify security risks early in the software development lifecycle.
- Build developer-friendly security guardrails, reusable patterns,