Skip to main content
← All roles
OperationsRemote·Full-time·Senior

DevOps / Release & Security Engineer

Own the release supply chain — multi-arch builds, signing, SBOM, and CI.

About the role

Purple8 ships as a hardened Docker image and a compiled pip wheel. This role owns the entire release supply chain — reproducible multi-arch builds, artifact signing and SBOMs, CI, and deployment — so shipping stays fast and trustworthy as the team grows. (Today the founder does this; it does not scale.)

What you’ll own

  • Own Docker / Nuitka multi-arch builds and the compiled-wheel pipeline.
  • Stand up signing (cosign), SBOMs, and dependency scanning.
  • Own CI and deployment (fly.io / containers) with fast, safe rollbacks.
  • Partner on the SOC vertical and security-by-default posture.

What we’re looking for

  • Strong CI/CD and container build experience (multi-arch, caching, reproducibility).
  • Supply-chain security: signing, SBOM, provenance.
  • Comfort owning production deploys and incident response.

Nice to have

  • Nuitka / Cython compiled-artifact packaging.
  • Kubernetes and cloud KMS integrations.

Interested?

Send a short note and anything that shows how you work — code, writing, or a project you're proud of.

Apply for this role