[All remote jobs](https://jobicy.com/jobs.md)Open role[![Veeam Software logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/f7716b71-221.jpg)](https://jobicy.com/company/veeam-software.md)Remote opportunity at[Veeam Software](https://jobicy.com/company/veeam-software.md)

# Cyber-Security Operations Analyst III, Product AppSec

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/veeam-software.md)Share28 Aug 2026Published20Listing views0Application actions27 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryThis senior Cyber-Security Operations Analyst role supports secure software delivery infrastructure and DevSecOps operations for cloud-native and AI-enabled products. The position operates CI/CD platforms, integrates application-security tooling, manages patching, and supports SIEM monitoring, detection tuning, alert triage, and incident response. It requires substantial hands-on experience across cloud platforms, infrastructure as code, Kubernetes, containers, Linux, and security testing tools such as SAST, DAST, and SCA. The role is remote within the United States and is restricted to U.S. citizens because it supports federal customers.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

4/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

4/5GuidedFull ownership

### Communication Load

4/5IndependentCollaborative

AI insightThe role combines senior-level DevOps, cloud infrastructure, application security, and SIEM operational responsibilities in a regulated environment. Success requires independently resolving production-adjacent platform issues while coordinating closely with engineering, IT, infrastructure, and security stakeholders.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$168,500US market range$120k–$190k0$209k

AI insightThe disclosed annual total target compensation range is $102,200 to $234,800 USD, varying by U.S. geographic zone; the overall offer midpoint is $168,500. This is broadly competitive for a senior U.S. DevSecOps/AppSec operations professional, for whom an estimated market range is approximately $120,000 to $190,000 USD annually depending on location, cloud-security depth, and regulated-environment experience.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[DevSecOps](https://jobicy.com/jobs?search_keywords=DevSecOps.md)[Application Security](https://jobicy.com/jobs?search_keywords=Application%20Security.md)[CI/CD](https://jobicy.com/jobs?search_keywords=CICD.md)[GitHub Actions](https://jobicy.com/jobs?search_keywords=GitHub%20Actions.md)[Azure DevOps](https://jobicy.com/jobs?search_keywords=Azure%20DevOps.md)[Kubernetes](https://jobicy.com/jobs?search_keywords=Kubernetes.md)[Terraform](https://jobicy.com/jobs?search_keywords=Terraform.md)[SIEM](https://jobicy.com/jobs?search_keywords=SIEM.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[SAST/DAST/SCA](https://jobicy.com/jobs?search_keywords=SASTDASTSCA.md)

Sample interview questionsHow have you integrated SAST, DAST, SCA, or container scanning into CI/CD pipelines without creating excessive friction for developers?I use risk-based policy gates, actionable findings, and phased enforcement. For example, I initially report on findings, tune false positives and ownership, then block builds only for defined critical vulnerabilities or policy violations while tracking remediation SLAs.

Describe your approach to operating and troubleshooting a CI/CD platform with failing build agents or degraded pipeline performance.

I begin by reviewing platform health metrics, agent logs, queue depth, recent configuration changes, and resource utilization. I isolate whether the issue is caused by agent capacity, credentials, network connectivity, dependencies, or pipeline configuration, restore service through a controlled fix, and document preventive actions such as autoscaling, patching, or improved alerting.

What is your process for onboarding a new security log source into a SIEM?

I validate log quality and transport, define a normalized schema, identify high-value detection use cases, and map ownership and retention requirements. After creating and testing alerts, I tune thresholds using baseline behavior, establish triage runbooks, and review alert quality with the incident-response team.

How would you manage patching for CI/CD infrastructure, container base images, and platform dependencies in a regulated environment?

I maintain an asset inventory, prioritize vulnerabilities by exploitability and business criticality, and test patches in lower environments before controlled production rollout. I use change records, rollback plans, maintenance windows, and evidence collection to meet compliance needs while ensuring critical exposures are remediated quickly.

How do infrastructure as code and Kubernetes practices improve the security and reliability of a DevSecOps platform?

Infrastructure as code provides version control, peer review, repeatable deployments, and policy enforcement for cloud resources. In Kubernetes, I apply least-privilege RBAC, image scanning, admission controls, secrets management, network policies, and observability to reduce configuration drift and strengthen operational resilience.

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

### #LI-REMOTE #LI-JC2

### About the Role

We’re looking for a Cyber-Security Operations Analyst to operate, monitor, and support secure software delivery infrastructure across cloud and platform engineering environments. You’ll partner with Software Engineering, Security, Infrastructure, and Platform teams to strengthen CI/CD pipelines, automate deployment workflows, and enhance operational reliability. This role sits at the intersection of development velocity and security, helping modernize workflows and implement scalable DevSecOps practices that support enterprise software, cloud-native services, and AI-enabled products.

Due to the fact that this position will deal with highly sensitive data and will support federal customers, we are only considering US citizens at this time. Security clearance is not required, but there is a slight chance it maybe requested in the future

### What You’ll Do

* Operate and maintain CI/CD pipelines, build agents, and supporting infrastructure across development, staging, and pre-production environments
* Configure and integrate application security tooling, including logging, monitoring, alerting, and dashboard management
* Support SIEM operations including log onboarding, detection tuning, alert triage, and incident response
* Manage patching of CI/CD infrastructure, build agents, container base images, and platform dependencies
* Monitor health, availability, and performance of security tools and DevSecOps platform components
* Partner with IT and Engineering teams on CI/CD toolchain support, including upgrades, capacity planning, and access management
* Collaborate with engineering teams to triage issues, document workflows, and share operational knowledge

### Technologies You’ll Work With

* CI/CD platforms: GitHub Actions, Azure DevOps, Jenkins, GitLab CI
* IaC tools: Terraform, Ansible, CloudFormation, or Pulumi
* Security tooling: Trivy, SAST, DAST, SCA, container scanning platforms
* Cloud providers: AWS, Azure, or GCP
* Containerization: Kubernetes, Docker, Helm
* Artifact management: JFrog Artifactory
* Scripting: Python, Bash, PowerShell
* SIEM and observability platforms

### What You’ll Bring

* 5+ years of experience in DevOps, Platform Engineering, SRE, or a related technical role
* 3+ years of hands-on experience with security testing tools (SAST, DAST, SCA)
* Experience designing and maintaining CI/CD pipelines using GitHub Actions, Azure DevOps, Jenkins, or similar
* Proficiency with IaC tools (Terraform, Ansible, or equivalent) and cloud environments (AWS, Azure, or GCP)
* Strong Linux administration skills and experience with Kubernetes, Docker, and Git
* Familiarity with regulated or compliance-driven environments
* Bachelor’s degree in Computer Science, Engineering, or equivalent experience

### Bonus Skills

* Experience with software supply chain security frameworks (SLSA, NIST SSDF, OWASP SCVS)
* Relevant certifications such as CDP, GCSA, CCSP, CKS, or cloud security certifications (Azure, AWS, GCP)
* Experience with agentic AI development practices
* Familiarity with TCP/IP networking, DNS, SSL/TLS, and network security fundamentals

What you’ll get

* Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
* Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
* Medical, dental, and vision coverage starting on your first day
* Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
* 401(k) retirement plan with company matching contributions
* Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
* AirVet: 24/7 virtual veterinary care at no cost
* Legal services, identity protection, and supplemental health insurance options
* Tax-advantaged spending accounts for healthcare, dependent care, and commuting
* Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning

Compensation Transparency

Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.

In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.

U.S. Geographic Zones & Compensation Ranges (TTC / OTE)

Zone 1: San Francisco Bay Area, New York City Boroughs

$140,900—$234,800 USD

Zone 2: Washington, California (excluding San Francisco Bay Area)

$129,200—$215,300 USD

Zone 3: Texas, Illinois, North Carolina, Colorado, Massachusetts, Pennsylvania, Virginia, Oregon, Nevada, Hawaii, New York (excluding NYC boroughs); Sales roles located in Georgia, Ohio, and Arizona

$117,400—$195,700 USD

Zone 4: All other US locations

$102,200—$170,300 USD

Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our [Recruiting Privacy Notice](https://www.veeam.com/legal/recruiting-privacy-notice.html), which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing.

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

Show more

[Apply now >](https://jobicy.com/jobs/151951-cyber-security-operations-analyst-iii-product-appsec.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Cision logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/e9661342-221.jpeg)
Cision  Aug 27

### [Security Engineer I, Information Technology](https://jobicy.com/jobs/151867-security-engineer-i-information-technology.md)

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As…

*
![Cision logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/e9661342-221.jpeg)
Cision  Aug 27

### [Security Analyst I, Information Technology](https://jobicy.com/jobs/151862-security-analyst-i-information-technology.md)

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As…

*
![LastPass logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13842160-221.png)
LastPass  Aug 27

### [Principal Cloud Security Engineer](https://jobicy.com/jobs/151831-principal-cloud-security-engineer.md)

About LastPassLastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and…

*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Lead Security Operations Engineer](https://jobicy.com/jobs/151792-lead-security-operations-engineer.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…

*
![Ada logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/666ef11e-221.png)
Ada  Aug 27

### [Compliance and Security Lead](https://jobicy.com/jobs/151791-compliance-and-security-lead.md)

About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service…

*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Senior Application Security Manager](https://jobicy.com/jobs/151788-senior-application-security-manager.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…

*
![GitLab logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/12/WRILS-201207055737-109952.jpg)
GitLab  Aug 27

### [Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA](https://jobicy.com/jobs/149309-senior-security-engineer-security-incident-response-team-sirt-emea.md)

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel  Aug 27

### [Security Software Engineer, IAM](https://jobicy.com/jobs/147750-security-software-engineer-iam.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….

*
![Bloomreach logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/60790cd5-221.png)
Bloomreach  Aug 26

### [Director, AI Enablement & Security](https://jobicy.com/jobs/151780-director-ai-enablement-security.md)

Bloomreach is building the world’s premier agentic platform for personalization.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire customer journey. We’re taking…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 26

### [Security Engineer, Infrastructure Security](https://jobicy.com/jobs/151778-security-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….