Senior DevSecOps Engineer
Varsity TutorsAbout the role
About Nerdy:
Nerdy (NYSE: NRDY), the parent company of Varsity Tutors, is a leading platform for live online learning, with a mission to transform the way people learn through technology. The Company’s purpose-built proprietary platform leverages technology, including Machine Learning and AI (Nerdy AI Learning Products - Press Release), to connect learners of all ages to experts, delivering superior value on both sides of the network. Nerdy’s comprehensive learning destination provides learning experiences across 3,000+ subjects and multiple formats—including one-on-one instruction, small group classes, large format group classes, on-demand study support, and adaptive self-study. Nerdy’s flagship business, Varsity Tutors, is one of the nation’s largest platforms for live online tutoring and classes. Its solutions are available directly to students and consumers, as well as through schools and other institutions. Learn more about Nerdy at https://www.nerdy.com/.
Qualifications:
The Sr DevSecOps Engineer is responsible for the supervision, implementation, and maintenance of Varsity Tutors’ cyberspace. They will plan, implement, manage, monitor and upgrade security measures to protect the organization’s data, systems and networks. They will work with 3rd party providers to carry out assessments and penetration testing. They will work with other departments within the organization to establish security protocols and processes to protect IT systems and data.
Qualifications:
- A bachelor’s degree in computer science, computer engineering or related technical field experience
- 7+ years of technology experience
- 3+ years as a Security Engineer (DevSevOps), or related experience, in a technical and remote customer-focused position
- 5+ years experience with Infrastructure as Code (IaC)
- 5+ years working with cloud providers such as AWS and GCP
- Proficient with AWS or GCP security offerings
- Experience in designing and implementing an enterprise-wide Cloud security architecture
- Proficiency with Security Information Event Management (SIEM) and vulnerability management solutions
- Knowledgeable in Shift Left Security: increasing visibility and remediation of security defects earlier in the CI/CD pipeline
- Experience implementing Policy as Code (PaC)
- Familiar with Open Policy Agent (OPA)
- Experience with Agile practices and NIST frameworks
- Familiar with SOC2, SOX and FERPA compliance
- In-depth knowledge of computer hardware, software, and networks.
- Excellent knowledge of networking technologies, particularly with OSI network layers and TCP/IP
- Ability to lead, prioritize, facilitate, organize and manage several milestones and projects efficiently
- Ability to learn quickly and keep up with technical innovation and trends in the Security field
- Experience with identity federation standards like SAML and OAuth
- Experience in documenting processes and monitoring performance metrics (OKR, KPI)
- Scripting (Bash, Python)
- Extensive experience working with different operating systems
- Exceptional interpersonal and communication skills
- Time management skills and the ability to establish reasonable and attainable deadlines for resolution.
Responsibilities:
- Conduct cyber risk assessment activities including threat modeling, vulnerability analysis and analysis of mitigation solutions
- Develop, present, lead and improve security awareness training programs for all employees
- Develop, evaluate, and analyze design constraints, trade-offs and detailed system and security design as they pertain to the cyber domain
- Coordinate with other DevOps Engineers, System Architects, and Developers to provide oversight in the development of robust solutions
- Work cross-functionally to assess risk and help deliver countermeasures that protect customers and company data
- Conduct cybersecurity tests and evaluations of hardware and/or software designs to verify and validate compliance with defined specifications and requirements
- Employ cybersecurity processes, methods, techniques and tools and assure their consistent application
- Implement appropriate assessment and authorization activities, as required
- Bake security controls into Engineering and DevOps pipelines (e.g., build automation and configuration management)
- Design and implement network-based and host-based Security tools.
- Design, implement and integrate security solutions into a centralized security an
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s