OperationsRemote·Full-time·Senior
DevOps / Release & Security Engineer
Own the release supply chain — multi-arch builds, signing, SBOM, and CI.
About the role
Purple8 ships as a hardened Docker image and a compiled pip wheel. This role owns the entire release supply chain — reproducible multi-arch builds, artifact signing and SBOMs, CI, and deployment — so shipping stays fast and trustworthy as the team grows. (Today the founder does this; it does not scale.)
What you’ll own
- Own Docker / Nuitka multi-arch builds and the compiled-wheel pipeline.
- Stand up signing (cosign), SBOMs, and dependency scanning.
- Own CI and deployment (fly.io / containers) with fast, safe rollbacks.
- Partner on the SOC vertical and security-by-default posture.
What we’re looking for
- Strong CI/CD and container build experience (multi-arch, caching, reproducibility).
- Supply-chain security: signing, SBOM, provenance.
- Comfort owning production deploys and incident response.
Nice to have
- Nuitka / Cython compiled-artifact packaging.
- Kubernetes and cloud KMS integrations.
Interested?
Send a short note and anything that shows how you work — code, writing, or a project you're proud of.
Apply for this role