Prepin
Log in
VIP (Vermont Information Processing)

engineering opportunity

DevSecOps / Cloud Security Engineer

You will own the security of the software release pipeline and cloud infrastructure by implementing automated security gates and operationalizing a cloud-agnostic security framework. Additionally, you will manage cloud identity, secrets protection, and provide mentorship to the India-based cloud security team.

United StatesremoteFULL_TIME

Posted

About the role

What will you do at VIP (Vermont Information Processing)?

Annual

Compensation

180,000

Position Type: Full Time, Remote

About us

Vermont Information Processing is the leading technology provider to the beverage industry, route accounting, warehouse, delivery, and sales platforms trusted by distributors, bottlers, and over 1,600 suppliers for 50+ years. Backed by Warburg Pincus, VIP is investing in security as a first-class discipline across a growing family of companies. You will join at the moment the program is being built, with executive sponsorship, a funded roadmap, and visible board-level impact.

About the role

You will own security of how VIP builds and runs software, the release pipeline and the cloud. Today the ingredients exist without enforcement: SonarQube and CAST are installed but code-security checks are not yet required before release; CrowdStrike cloud security posture management is deployed but early-stage; a 15-domain cloud security framework with forty implementation runbooks is authored and live in its first environment.

Your mandate is to turn all of it on and make secure the default path for our engineering teams. You will work hand-in-hand with a junior cloud security engineer on our India team and have direct executive sponsorship: this role exists because our CIO told the board that no one owns pipeline security and fixed it.

What you will own

Secure release pipeline: make code-security scanning (SAST/SCA) a required, low-friction gate in CI/CD across our development teams; introduce automated application testing (DAST) and secrets scanning.

Cloud security framework rollout: operationalize our 15-domain, cloud-agnostic framework and CrowdStrike CSPM across all AWS estates (VIP-core, VIP India, acquired units), misconfiguration burn-down, guardrails, and workflow integration.

Cloud identity & access: centralize AWS access through Okta, eliminate local credentials, and implement least-privilege roles; define the tagging standard so every resource has an owner and classification.

Secrets & data protection: stand up managed secrets with rotation (replacing env-var and ad-hoc storage), encryption-at-rest verification, and support the data-leak-prevention rollout beyond email.

Resilience engineering: configure tamper-proof (immutable) backup tiers on our Rubrik platform and help define recovery-time objectives with IT.

Enablement & mentorship: build paved-road patterns and developer guidance; grow our India-based junior cloud security engineer; extend the framework to newly acquired units.

What success looks like in year one

Code-security checks required on 100% of production releases, with developer-experience friction low enough that teams defend the gate.

CSPM operationalized across every AWS account with critical misconfigurations at zero and a sustained burn-down of the rest.

AWS access fully Okta-federated; no shared or local console credentials; tagging standard adopted.

Immutable backup tier live; secrets rotation automated for priority systems.

What you bring

5+ years across DevOps/platform and security engineering, with real ownership of CI/CD systems (Jenkins, Bitbucket/Git-based pipelines) and AWS.

Hands-on with SAST/DAST/SCA tooling and the craft of introducing gates developers accept.

Strong AWS security depth: IAM, organizations/accounts, networking, KMS, and posture management tooling.

Infrastructure-as-code and automation fluency (Terraform/CloudFormation, Python).

Collaborative style suited to distributed teams; comfortable mentoring and working across time zones.

Nice to have

Azure exposure (two of our acquired units run Azure).

Experience with Okta-AWS federation, Rubrik or equivalent backup platforms, and container security.

AWS Security Specialty, CCSP, or GIAC cloud certifications.

Compensation

is based on a variety of factors including skills, experience and industry background. The range listed here represents our best faith estimate for the role.

All full-time job offers are contingent upon passing a pre-employment drug screening and background check.

Which skills does this role require?

DevSecOpsCloud SecurityCI/CDSASTDASTSCATerraformPythonIAMCrowdStrikeInfrastructure as CodeSecrets ManagementEncryptionMentorshipJenkinsBitbucketCSPMCloudFormationKMSImmutable BackupsBeverage IndustryAutomationIdentity and Access ManagementSecurity FrameworkResilience EngineeringREST APIsProduct Strategy

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.