> Markdown version of [/jobs/ext/2718462-staff-infrastructure-security-engineer](https://www.wearedevelopers.com/jobs/ext/2718462-staff-infrastructure-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Infrastructure & Security Engineer - **Company:** Vouch, Inc. - **Location:** San Francisco, CA, United States - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software as a Service, Cloud Engineering, Code Review, Cyber Security, Continuous Integration, Data Masking, DevOps, Role-Based Access Control, Circleci, Cloud Platform System, Terraform, Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/staff-infrastructure-security-engineer-vouch-inc-8807135 ## About the Role * Deep cloud engineering experience, primarily in AWS: designing, building, and operating production infrastructure at scale. * Strong in CI/CD and delivery automation (CircleCI, Nomad, or equivalent) and infrastructure-as-code (Terraform), with ownership of a real production system's reliability. * Apply security pragmatically: isolation, least-privilege, RBAC, blast-radius containment. * A formal background in information security or cybersecurity, including having led a SOC 2 (or similar) compliance audit. * Has led at least one enterprise security-breach or data-leak incident response. * Comfortable as a hands-on technical lead and DRI: work through architecture, standards, and code review, set technical direction, and raise the bar across a team. * A bias toward simplicity and subtraction. * AI-forward: build for isolation, safe data, and non-human identity, and the infrastructure behind it. * Communicate crisply across engineering, IT/Security, Legal, and Finance. Nice To Have: * Experience operating Temporal or similar durable-workflow infrastructure in production. * Hands-on with supply-chain / dependency vulnerability scanning (Endor Labs, Snyk, or equivalent). * Compliance-as-code experience: treating controls and evidence as an engineering artifact. * Familiarity with agent / sandbox isolation patterns: dedicated accounts, scoped tokens, ephemeral environments, and data masking. * Secrets and credential management at scale (1Password, AWS SSM, or equivalent). * Experience in insurance, fintech, or another regulated domain. * A university degree in cybersecurity or a related field. ## Description * Serve as the technical DRI for the Infra & Security group: own the architecture, set the standards, and make the technical calls across infrastructure, DevOps, and security engineering. * Own the cloud platform end-to-end: infrastructure reliability, CI/CD and delivery automation, and the infrastructure-as-code beneath them. * Drive a simpler, isolated architecture through shrinking the surface area we defend and maintain: Retire legacy and unused services, consolidate SaaS and vendors, and unwind standing external dependencies. * Own infra & security incident-response: a staffed rotation with no single point of failure, severity-matched response, actionable alerting, and runbooks. * Bring identity and access under a single source of truth: human, service, machine, and agent identity. * Build the Production-agent Infrastructure that lets autonomous agents run and self-verify safely in production. * Drive and maintain our security-compliance and supply-chain scanning programs. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Serverless: Past, Present and Future](https://www.wearedevelopers.com/videos/34-serverless-past-present-and-future) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)