×
Register Here to Apply for Jobs or Post Jobs. X

Senior DevSecOps & Network Infrastructure Engineer

Job in Melville, Suffolk County, New York, 11775, USA
Listing for: KWI
Full Time position
Listed on 2026-09-14
Job specializations:
  • IT/Tech
    Cybersecurity, SRE/Site Reliability, Network Engineer, Cloud Computing: Infrastructure & Operations
Salary/Wage Range or Industry Benchmark: 165000 - 175000 USD Yearly USD 165000.00 175000.00 YEAR
Job Description & How to Apply Below

Department: Systems Ops

Employment Type: Full Time

Location: Melville, NY

Reporting To: VP of Infrastructure & Operations

Compensation: $165,000 - $175,000 / year

Description

About KWI

KWI builds the unified commerce platform that powers some of the world's most recognized specialty and luxury retail brands. Behind every transaction, every clienteling interaction, and every store opening is an infrastructure team that keeps the lights on and is continuously raising the bar on how modern, and how secure, that platform runs. This is a role on that team.

The opportunity

If innovation lives in your DNA and AI is already part of how you think, build, and operate, you're going to love what we're doing 'll join a small, senior team with a real mandate to design, build, secure, and run the systems that power retail s is hands-on, on-prem infrastructure work: our own hypervisors, our own network edge, our own containers, and our own pipelines.

We move fast, we automate aggressively, and we expect security to be built into the platform rather than bolted onto it. Your fingerprints will be on the platform every day.

The impact you'll make
  • Design, harden, and operate our on-prem footprint: VMware vSphere clusters, Linux virtual machines, and Docker workloads running across multiple datacenters and serving retail clients 24x7.
  • Own the network edge. Forti Gate policy design, NAT and VIPs, IPsec site-to-site and remote-access VPN, segmentation, IPS and UTM profiles, and disciplined change control on every rule you touch.
  • Build security into the delivery pipeline. Container image and dependency scanning, SAST, secrets detection, IaC policy checks, signed artifacts, and vulnerability findings you drive to closure instead of to a spreadsheet.
  • Containerize and template services with Docker and infrastructure-as-code so deployments are repeatable, declarative, and boring.
  • Run the secrets and PKI plane: centralized secrets management, an internal certificate authority, automated certificate issuance and rotation, and a standing campaign to get hardcoded credentials out of the environment.
  • Own incidents end to end: triage alerts, drive root-cause analysis across the application, network, database, and hypervisor layers, and write the post-incident docs that stop recurrence.
  • Improve observability across the fleet. Metrics, logs, traces, dashboards, and firewall and flow telemetry, so problems are seen before customers feel them.
  • Support audit, compliance, and penetration-test work: evidence collection, remediation SLAs, access reviews, and hardening baselines that hold up under scrutiny.
  • Use modern AI-augmented engineering tools (Claude Code, MCP-based workflows, agentic automation) as a daily multiplier, to operate faster and extend what one engineer can deliver.
  • Document and mentor. Runbooks, network diagrams, and design docs aren't an afterthought here. They're how the team scales.
What you will bring

Required

  • 5+ years operating production Linux/UNIX (RHEL, CentOS/Rocky, Debian/Ubuntu) in an on-prem or hybrid environment at meaningful scale.
  • Hands-on enterprise firewall experience, ideally Forti Gate/FortiOS: policy design, NAT and VIPs, IPsec and SSL VPN, routing, HA pairs, and the judgment to change a live rule set safely. Deep Palo Alto or Cisco ASA/Firepower experience plus a genuine willingness to go deep on Fortinet also works.
  • Strong networking fundamentals: TCP/IP, VLANs and segmentation, routing, DNS, TLS, HTTP/S, and load balancing. You can read a packet capture and a certificate chain and say what is actually happening.
  • Production VMware vSphere experience: clusters and hosts, data stores, resource contention, snapshots and templates, and patching without an outage.
  • Docker in production: image builds and hardening, registries, compose-based or orchestrated deployment, container networking, and troubleshooting the container that will not stay up.
  • Practical Dev Sec Ops : CI/CD pipelines with security gates, vulnerability management and CVE remediation at fleet scale, secrets management, and image scanning.
  • Solid Dev Ops fundamentals:
    Git, CI/CD pipelines, Ansible (or similar configuration management), Terraform/Open Tofu (or similar IaC), and Docker.
  • Comfortable scripting in Bash. Python is not required, but you should have a working understanding of programming fundamentals and be able to read, modify, and write straightforward code.
  • Strong troubleshooting instincts and the temperament to lead under pressure.

Key skills (we'll weigh heavily)

  • Real day-to-day…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary