Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior DevSecOps Engineer image - Rise Careers
Job details

Senior DevSecOps Engineer

Vistar Media is the home of out-of-home (OOH). As a global ad tech company and the world's largest digital out-of-home (DOOH) advertising marketplace, we offer technology designed to make buying and selling OOH media easier. Our goal is simple: to help the world's marketers leverage OOH's unique ability to motivate and delight. 

From strategic partnerships with major media owner networks to executing impactful campaigns with renowned global brands such as Nestlé, Porsche, Target, and Levi's, our team is filled with passionate, innovative, and collaborative problem solvers, engaging and entertaining consumers like you in the real world. Find your home in out-of-home - find your people at Vistar.

About the role:

We are seeking a Senior DevSecOps Engineer, with extensive experience in security vulnerability remediation, cloud infrastructure, and strategic planning. The ideal candidate is adept at identifying and fixing security vulnerabilities in codebases written in languages such as Python, TypeScript, Go, Java, and Scala. This role is ideal for a Software Engineer with a focus on Security, who thrives working independently and collaborating in a cross-functional environment with multiple engineering teams, leadership, and non-technical peers. This is a great opportunity to join an innovative company that prioritizes security and continuous improvement.

What you'll do:

  • Security & Vulnerability Management:

    • Conduct code reviews, static and dynamic application security testing (SAST and DAST), and penetration testing to identify vulnerabilities and recommend remediation strategies.

    • Implement automated security testing and monitoring tools to maintain a robust security posture.

  • Cloud Infrastructure:

    • Design, deploy, and manage secure cloud infrastructure solutions.

    • Integrate security best practices across cloud services and platforms.

  • Collaboration & Communication:

    • Excel in a strong, collaborative work environment while effectively managing independent tasks.

    • Provide technical guidance and mentorship to junior team members and peers.

    • Collaborate with development, operations, and product teams to plan and implement security enhancements.

  • Security Tooling & Monitoring:

    • Manage and optimize security tooling including SIEM systems, vulnerability scanning tools, and Zero Trust Architecture (ZTA) VPN solutions.

    • Leverage related services to ensure comprehensive threat detection, incident response, and secure remote access.

  • Continuous Improvement:

    • Stay updated with the latest trends, tools, and best practices in DevSecOps.

    • Drive process improvements and advocate for security-first development practices across teams.

What experience we're looking for:

  • Bachelor's Degree in a technical field (e.g. engineering, computer science, etc.), or equivalent practical experience.

  • 8+ years of professional work experience as a developer.

  • 3+ years of work experience in software development and fixing security vulnerabilities in languages such as Python, TypeScript, Go, Java, and Scala.

  • 5+ years of work experience in DevSecOps or other security-focused software development role, with a strong focus on cloud infrastructure.

  • Expertise in public cloud platforms (AWS - preferred, Azure, GCP, etc) and related security services.

  • Proficiency with security tooling including IDS, IPS, SIEM, Zero Trust Architecture (ZTA VPN), and related services.

  • Familiarity with automation tools, CI/CD pipelines, and containerization technologies.

  • Strong understanding of security protocols and technologies (TLS, HTTPS, OAuth, etc).

  • Deep understanding of security frameworks and compliance standards.

Who you are

  • Proven history of succeeding in challenging projects that have a significant impact on the organization’s overall security posture.

  • Thrive off opportunities for professional growth and career advancement in a fast-paced, technology-driven setting.

  • Enjoy a strong, collaborative work environment that values teamwork and open communication.

  • Excellent problem solving skills and attention to detail.

  • Demonstrated ability to work both independently and collaboratively in a dynamic environment.

  • Strong communication skills with the ability to communicate security risks and recommendations effectively to technical and non-technical stakeholders.

What we offer:

  • Flexible, fun start-up environment and culture

  • An approachable and accessible C-Suite.

  • Comprehensive health benefits.

  • 401k + match.

  • Quarterly Lifestyle Stipend.

  • Unlimited PTO and summer Fridays.

  • Company-wide and team specific entertainment budgets for both in-person and virtual team building.

  • A flexible hybrid work environment, with a fully stocked kitchen, weekly catered lunches, and casual attire while in office.

  • Sponsored Volunteer Events and Vistar Gives Back program.

  • An awesome and supportive bunch of people to work with and learn from.

Recruiting fraud is a serious issue facing jobseekers. Please be aware that Vistar Media would never require personal information (such as bank account information) during the interview process. Should an employee from Vistar Media reach out to you, that communication will come from an @vistarmedia.com email address. During a typical interview process, you will have several phone, video, and/or in-person interviews with multiple Vistar Media employees before a hiring decision is made. We do not require payment from applicants for training or other costs incurred, nor do we offer compensation before hiring.

If you’re ambitious, highly driven, and interested in making an impact, Vistar is the place for you. Apply to join our team… we’ll see you out there.

Vistar Media Glassdoor Company Review
4.5 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Vistar Media DE&I Review
4.3 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Vistar Media
Vistar Media CEO photo
Michael Provenzano
Approve of CEO

Average salary estimate

$122500 / YEARLY (est.)
min
max
$100000K
$145000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior DevSecOps Engineer, Vistar Media

At Vistar Media, we're on the lookout for a seasoned Senior DevSecOps Engineer to join our energetic team in Philadelphia. As a leading force in digital out-of-home advertising, our mission revolves around making the experience of buying and selling OOH media seamless for marketers. In this role, you'll become an integral part of our efforts to ensure top-notch security within our innovative products. Your day-to-day will involve conducting thorough code reviews, implementing automated security testing, and managing our secure cloud infrastructure. With your deep knowledge in languages like Python, TypeScript, Go, Java, and Scala, you'll be strategizing ways to identify and mitigate security vulnerabilities, all while mentoring junior team members and collaborating across multifaceted teams. We're not just about securing code; we also embrace ongoing improvement, keeping you at the forefront of emerging trends in DevSecOps. Joining Vistar means you're part of a culture that's agile, collaborative, and always striving for excellence. If you're someone who thrives in a fast-paced environment, values teamwork and open communication, and hopes to make a tangible impact, we'd love to hear from you! Get ready to take your career to new heights in a company that genuinely cares about its people and their growth.

Frequently Asked Questions (FAQs) for Senior DevSecOps Engineer Role at Vistar Media
What are the key responsibilities of a Senior DevSecOps Engineer at Vistar Media?

As a Senior DevSecOps Engineer at Vistar Media, you'll be responsible for conducting security assessments including code reviews, static and dynamic application security testing, and ensuring vulnerability remediation. You'll also be tasked with designing and managing secure cloud infrastructure solutions while integrating security best practices across various platforms. Collaboration is key, as you'll work closely with other engineering teams and provide mentorship to junior developers.

Join Rise to see the full answer
What qualifications do I need to apply for the Senior DevSecOps Engineer position at Vistar Media?

To qualify for the Senior DevSecOps Engineer role at Vistar Media, you should possess a Bachelor's degree in a technical field or have equivalent experience. Additionally, you should have a solid 8+ years of professional experience in development, with at least 3 years focusing on fixing security vulnerabilities. Experience with public cloud platforms, as well as proficiency in security tooling, is essential to succeed in this role.

Join Rise to see the full answer
What is the work culture like for a Senior DevSecOps Engineer at Vistar Media?

The work culture for a Senior DevSecOps Engineer at Vistar Media is vibrant and engaging. You'll be part of a flexible, start-up environment where creativity and collaboration thrive. We pride ourselves on open communication, and each team member is encouraged to share ideas and contribute to the development process. You'll find support from leadership and peers alike, creating a fantastic atmosphere for professional growth.

Join Rise to see the full answer
How does Vistar Media support continuous improvement in security practices?

At Vistar Media, supporting continuous improvement in security practices is ingrained in our approach. As a Senior DevSecOps Engineer, you'll have the opportunity to stay updated with the latest trends and technologies in DevSecOps. You will drive process improvements and advocate for security-first development practices, ensuring that security is an integral part of the development lifecycle across teams.

Join Rise to see the full answer
What tools and technologies will I work with as a Senior DevSecOps Engineer at Vistar Media?

As a Senior DevSecOps Engineer at Vistar Media, you'll work with a variety of tools and technologies focused on security and cloud infrastructure management. This includes security tooling like IDS and IPS, SIEM, and Zero Trust Architecture VPN. Additionally, you'll engage with automation tools, CI/CD pipelines, and containerization technologies, allowing you to build a robust security posture for our complex applications.

Join Rise to see the full answer
Common Interview Questions for Senior DevSecOps Engineer
Can you describe your experience with vulnerability remediation in software development?

When discussing your experience with vulnerability remediation, focus on specific instances where you identified and mitigated security risks in codebases. Use examples that demonstrate your methods for conducting code reviews or leveraging automated tools. Highlight your proficiency in programming languages like Python, TypeScript, or Go, and explain how these experiences align with Vistar Media's emphasis on security enhancement.

Join Rise to see the full answer
What is a Zero Trust Architecture, and how have you implemented it?

In your response, explain what Zero Trust Architecture involves—specifically, the principle of 'never trust, always verify.' Share your experiences implementing ZTA in past projects, detailing the challenges faced and strategies adopted. This will show your understanding of security frameworks and how they contribute to the overall security posture, which is critical for the role at Vistar Media.

Join Rise to see the full answer
How do you keep up-to-date with the latest trends in DevSecOps?

When answering this question, describe your methods for staying informed, such as following industry publications, participating in online forums, attending conferences, or completing professional courses. Emphasize your commitment to continuous learning and how this knowledge can be beneficial to your role as a Senior DevSecOps Engineer at Vistar Media.

Join Rise to see the full answer
Describe a time when you had to mentor a junior team member.

Sharing a specific instance where you successfully mentored someone will showcase your leadership abilities. Discuss how you guided them through a project or through understanding complex security concepts, and highlight any positive outcomes as a result of your mentorship. This will align well with Vistar Media's collaborative culture.

Join Rise to see the full answer
What tools do you prefer for automated security testing?

Discuss the specific tools you've used for automated security testing, like SAST or DAST tools, and share why you prefer them. Mention how you’ve integrated these tools into CI/CD pipelines to enhance security practices. Highlight your experience with Vistar’s tech stack when possible.

Join Rise to see the full answer
How have you dealt with conflicting priorities in a fast-paced environment?

Discuss your strategy for managing multiple priorities by using examples from previous positions. Mention the importance of open communication with stakeholders and how prioritizing tasks based on risk assessment has helped you navigate through challenges. This will demonstrate your fit for Vistar Media’s dynamic work culture.

Join Rise to see the full answer
What experience do you have with public cloud services?

Detail your experience with cloud services such as AWS, Azure, or GCP. Explain how you have used these platforms to enhance security and what services you leveraged to improve the security posture of applications. Connect your experience to the specific cloud strategies Vistar Media is likely employing.

Join Rise to see the full answer
What are some common security protocols you have implemented in your past projects?

Discuss security protocols you have worked with, such as TLS, HTTPS, or OAuth. Provide examples of how you implemented these protocols to secure applications, including the benefits they offered. Align this with Vistar Media's focus on maintaining a robust security infrastructure.

Join Rise to see the full answer
Can you explain a challenging project you worked on and how you handled it?

Choose a project that involved significant security challenges and discuss your role in overcoming those obstacles. Be sure to focus on the techniques you employed and the tools used to achieve a successful outcome. This will showcase problem-solving skills that are crucial for a Senior DevSecOps Engineer at Vistar Media.

Join Rise to see the full answer
What role does collaboration play in your DevSecOps approach?

Emphasize the importance of collaboration across engineering and product teams when it comes to security. Provide examples of how you worked with cross-functional teams to integrate security into workflows and how this improved not only security posture but also overall productivity, mirroring Vistar Media’s team-oriented ethos.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 14 days ago
Photo of the Rise User
McDonald's Corporation Hybrid 110 N Carpenter St, Chicago, IL 60607, USA
Posted 2 days ago
Photo of the Rise User
Lingraphica Remote 700 Alexander Park Dr, Princeton, NJ 08540, USA
Posted 17 hours ago
Posted 6 days ago
Posted 8 days ago
Photo of the Rise User
Posted 2 days ago

Vistar Media is the home of out-of-home. Out there, in the streets, ad space intersects time and place. It’s a part of life. OOH campaigns inform, entertain, attract - and they can change the course of someone’s afternoon. At Vistar Media, we fa...

35 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
March 18, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!