Senior DevSecOps & Network Infrastructure Engineer
Summary
Designs, hardens, and operates KWI's on-prem retail commerce platform infrastructure — VMware vSphere clusters, Linux VMs, Docker workloads, and the FortiGate network edge — while building DevSecOps into CI/CD (image scanning, secrets/PKI, vulnerability management) and owning incidents, observability, and audit support.
- Design, harden, and operate our on-prem footprint: VMware vSphere clusters, Linux virtual machines, and Docker workloads running across multiple datacenters and serving retail clients 24x7.
- Own the network edge. FortiGate policy design, NAT and VIPs, IPsec site-to-site and remote-access VPN, segmentation, IPS and UTM profiles, and disciplined change control on every rule you touch.
- Build security into the delivery pipeline. Container image and dependency scanning, SAST, secrets detection, IaC policy checks, signed artifacts, and vulnerability findings you drive to closure instead of to a spreadsheet.
- Containerize and template services with Docker and infrastructure-as-code so deployments are repeatable, declarative, and boring.
- Run the secrets and PKI plane: centralized secrets management, an internal certificate authority, automated certificate issuance and rotation, and a standing campaign to get hardcoded credentials out of the environment.
- Own incidents end to end: triage alerts, drive root-cause analysis across the application, network, database, and hypervisor layers, and write the post-incident docs that stop recurrence.
- Improve observability across the fleet. Metrics, logs, traces, dashboards, and firewall and flow telemetry, so problems are seen before customers feel them.
- Support audit, compliance, and penetration-test work: evidence collection, remediation SLAs, access reviews, and hardening baselines that hold up under scrutiny.
- Use modern AI-augmented engineering tools (Claude Code, MCP-based workflows, agentic automation) as a daily multiplier, to operate faster and extend what one engineer can deliver.
- Document and mentor. Runbooks, network diagrams, and design docs aren't an afterthought here. They're how the team scales.
- 5+ years operating production Linux/UNIX (RHEL, CentOS/Rocky, Debian/Ubuntu) in an on-prem or hybrid environment at meaningful scale.
- Hands-on enterprise firewall experience, ideally FortiGate/FortiOS: policy design, NAT and VIPs, IPsec and SSL VPN, routing, HA pairs, and the judgment to change a live rule set safely. Deep Palo Alto or Cisco ASA/Firepower experience plus a genuine willingness to go deep on Fortinet also works.
- Strong networking fundamentals: TCP/IP, VLANs and segmentation, routing, DNS, TLS, HTTP/S, and load balancing. You can read a packet capture and a certificate chain and say what is actually happening.
- Production VMware vSphere experience: clusters and hosts, datastores, resource contention, snapshots and templates, and patching without an outage.
- Docker in production: image builds and hardening, registries, compose-based or orchestrated deployment, container networking, and troubleshooting the container that will not stay up.
- Practical DevSecOps: CI/CD pipelines with security gates, vulnerability management and CVE remediation at fleet scale, secrets management, and image scanning.
- Solid DevOps fundamentals: Git, CI/CD pipelines, Ansible (or similar configuration management), Terraform/OpenTofu (or similar IaC), and Docker.
- Comfortable scripting in Bash. Python is not required, but you should have a working understanding of programming fundamentals and be able to read, modify, and write straightforward code.
- Strong troubleshooting instincts and the temperament to lead under pressure.
- Real day-to-day experience using AI-augmented engineering tools (Claude, Cursor, Copilot, MCP servers, agentic workflows), not just demos.
- Firewall and network security operations at the edge of a production e-commerce platform: rule hygiene, attack-surface reduction, and closing external pen-test findings.
- Experience with a centralized secrets manager (HashiCorp Vault, OpenBao, or comparable) and internal PKI or certificate automation.
- Experience with Datadog, Grafana, or comparable observability platforms.
- Security certifications such as Fortinet NSE 4 or higher, Security+, CISSP, or OSCP, or equivalent demonstrated depth.
- Exposure to compliance frameworks that touch retail (PCI DSS, SOC 2) and the evidence work that comes with them.
- MySQL operational experience: replication, performance tuning, backups, and recovery.
- Load balancer experience (Kemp/LoadMaster, F5, HAProxy, NGINX), including SSL offload and WAF policy.
- Multi-datacenter, disaster-recovery, or failover-testing experience.
- Retail, e-commerce, or POS-adjacent operational experience.
- Full Medical, Dental and Vision
- Annual bonus eligible
- Free gym in the building
- Generous PTO policy
- Summer Fridays....all year round
- Tuition Reimbursement
- Discount from building café
- 401(K) with a 50% company match (up to 6% of employee contribution)
- Employee Referral Program
- (1) Volunteer day each year
Our work space
Our commitment to you
Skills
- Agentic AI
- AI
- Ansible
- Automation
- Bash
- CI/CD
- Cisco
- Cissp
- Claude Code
- Datadog
- DevOps
- DevSecOps
- DNS
- Docker
- E-commerce
- Firewall
- Fortinet
- Git
- Grafana
- Infrastructure as Code
- IPsec
- Linux
- MCP
- MySQL
- Network Security
- Networking
- Nginx
- Observability
- Pci Dss
- PKI
- Python
- RHEL
- SAST
- Secrets Management
- SOC 2
- SSL
- TCP/IP
- Terraform
- TLS
- Ubuntu
- Unix
- Vault
- VLAN
- VMware
- VPN
- WAF