--- title: 'Sr. DevSecOps Engineer (US) at Craft Machine Inc' canonical: 'https://feeny.ai/job/sr-devsecops-engineer-us-craft-machine-inc-united-states-p3dxh5v0he9q' type: 'job' last_seen: '2026-09-09' --- # Sr. DevSecOps Engineer (US) at Craft Machine Inc - **Company:** Craft Machine Inc - **Location:** United States - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-07-17 - **Last confirmed live:** 2026-09-09 - **Apply:** https://jobs.ashbyhq.com/craft.co/9c0bcae2-0ee4-40a8-98ca-f92bc8b77e88 ## Job description ## ABOUT CRAFT: Craft is the leader in supplier risk intelligence, enabling enterprises to discover, evaluate, and continuously monitor their suppliers at scale. Our AI research and monitoring agents deliver real, actionable intelligence, by operating on top of our unique, proprietary data platform - this helps our customers make better, more informed decisions for their business, faster and strategically secure critical supply chains from risk. Our customers include Fortune 500 companies, government agencies, and global service platforms. We’ve developed distribution partnerships with some of the largest integrators and software platforms globally. We are a post-Series B high-growth technology company backed by top-tier investors in Silicon Valley and Europe, headquartered in San Francisco with hubs in Seattle and Warsaw. We support remote and hybrid work, with team members across North America and Europe. We are looking for innovative and driven people passionate about building the future of Enterprise Intelligence to join our growing team! ## ABOUT THE ROLE: Craft is growing — and we’re looking for a senior engineer to contribute to one of our most strategically important initiatives: establishing a FedRAMP-authorized cloud environment by defining a secure boundary and hardening our existing cloud platform. This is an initiative with direct impact on Craft’s ability to serve the 40+ federal government agencies we already work with, and to unlock new opportunities across the public sector. You’ll own and lead the implementation of security controls, compliance automation, and secure architecture patterns required to achieve and maintain FedRAMP authorization at both Class C and Class D impact levels, with alignment to DoW IL2 and IL5 requirements. Working cross-functionally with infrastructure, engineering, and security, you’ll translate NIST 800-53 Rev. 5 requirements into scalable, auditable technical controls across our platform. This role reports to and partners closely with Jose M., our Manager of DevSecOps. You’ll contribute to our authorization readiness efforts day-to-day — driving the ATO timeline, shaping the program’s architecture, and upleveling team expertise in FedRAMP and NIST controls. If you want to contribute something consequential at a company that already has a sponsor and active federal relationships, this is it. ## WHAT YOU'LL DO: - Design and implement AWS architecture that meets FedRAMP Class C and Class D requirements. - Translate NIST 800-53 Rev. 5 controls into concrete, auditable, and continuously enforced technical implementations — not just documentation. - Build and maintain compliance automation tooling to continuously validate control adherence across the environment, reducing manual audit burden. - Develop and manage secure CI/CD pipelines with integrated security gates, secrets management, and deployment controls appropriate for authorized environments. - Contribute to development and maintenance of System Security Plans (SSPs), control implementation statements, and audit evidence packages. - Perform threat modeling, risk assessments, and security architecture reviews across the platform. - Manage POA&M remediation under 30/30/90/180-day SLAs, driving fixes across engineering teams. ## WHO YOU ARE: Required - 5+ years hands-on DevSecOps experience, building and operating security controls in production cloud environments. - Deep hands-on AWS expertise: IAM design, VPC and boundary protection, KMS, security groups, and cloud posture management. - You have strong working knowledge of NIST 800-53 Rev. 5 controls and how to implement them technically, not just document them. - Familiarity working inside an authorized boundary (FedRAMP, DoD IL, SOC 2, or ISO 27001). Comfort with continuous monitoring, POA&M workflows, and evidence collection. - You write advanced Terraform — modules, policy enforcement, and infrastructure that’s auditable by design. - You’ve built or hardened CI/CD pipelines for secure, compliant deployments — integrating security scanning, secrets management, and access controls. Nice to Haves - Direct experience contributing to a FedRAMP Moderate ATO or DoW IL2/IL4 authorization inside an MSP boundary (Knox, Second Front Game Warden, Platform One, or similar). - AWS GovCloud partition experience, including cross-partition IAM, service catalog gaps, and FIPS endpoint enforcement. - SOC 2 Type II experience, particularly in environments where mapped or extended to support FedRAMP or NIST frameworks. - Experience securing data platforms such as Databricks, including data isolation and access control patterns. - Familiarity with AI and LLM security concepts: prompt injection risks, model data isolation, inference boundary controls. - Experience working in a startup or lean DevSecOps environment where you’ve had to build programs pragmatically with limited resources. ## WHAT WE OFFER: - Competitive salary starting at $170,000 USD/ year. This starting number can be increased based on levels of expertise, location, cost of living, taxes, market experience, etc. - Equity at a well-funded, fast-growing startup - Unlimited vacation time so you can take what you need, when you need it - 99% covered Health + Dental + Vision insurance for employees and dependents - 401K through Empower with options to invest how you want it ## A NOTE TO CANDIDATES: We are an equal opportunity employer who values and encourages diversity, equity and belonging at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, caste, or disability status. Don’t meet every requirement? Studies have shown that women, communities of color and historically underrepresented talent are less likely to apply to jobs unless they meet every single qualification. At Craft, we are dedicated to building a diverse, inclusive and authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we strongly encourage you to apply. You may be just the right candidate for this or other roles! ## About Craft Machine Inc ## Company Overview - **One-liner**: Craft provides an AI-powered supplier intelligence and risk management platform that helps global enterprises build more secure, resilient, and sustainable supply chains. - **Entity Type**: Private (Series B; last known funding round in 2022) - **Headquarters**: San Francisco, California, USA - **Founded**: 2019 - **Founders**: Ilya Levtov (CEO) ## Core Business - **Primary industry/industries**: Supply Chain Management, Supplier Risk Management, Procurement Intelligence - **Target customers**: Large global enterprises, Fortune 500 companies, U.S. Federal Government agencies, Aerospace & Defense primes, and other organizations with complex supply chains (B2B, Enterprise) - **Mission or purpose statement**: "To make global supply chains more secure" by orchestrating intelligence for procurement and supply chain professionals, enabling faster, smarter decisions and more confident operations. The broader mission also includes fostering "responsible and sustainable global supply chains, driving ethical practices, reducing environmental impact, and creating a brighter, more resilient global economy for all." ## Products & Services For each major offering: - **Supplier Intelligence Platform (Data Fabric)**: A unified, AI-integrated system of intelligence that aggregates, normalizes, and enriches supplier data from 250k+ supplier attributes and real-time news from 20+ data pipelines into one centralized, trusted foundation. - **Continuous Monitoring & Risk Management**: Automatically detects, investigates, and prioritizes emerging risks (e.g., financial, geopolitical, sustainability, regulatory) so teams can respond faster. Claims a **90% reduction in time to deliver due diligence**. - **Sourcing Diligence**: Evaluates prospective suppliers and informs RFP/RFQ decisions using verified third-party data. - **Supplier Qualification**: Accelerates onboarding and qualification by replacing manual surveys with automatically sourced intelligence and evidence. Claims **87% faster supplier onboarding**. - **Relationship Management**: Equips teams with on-demand intelligence to know their suppliers, enforce governance, and make day-to-day decisions. - **Network Graph**: Maps supplier hierarchies, dependencies, and relationships. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed (Private company) - **Key Metric**: Total Funding (Private) — Raised a **$100M Series B** in January 2022, led by SoftBank Vision Fund 2, with participation from prior investors including Y Combinator, Bloomberg Beta, and Goldcrest Capital. Total funding is estimated at over $130M. - **Notable Investors/Partners**: SoftBank Vision Fund 2, Y Combinator, Bloomberg Beta, Goldcrest Capital. Customers include Defense Primes, Fortune 500 Enterprises, and the U.S. Federal Government. - **Growth Signals**: Winner of FIMA Startup "Dragon's Den"; recognized in "Top 10 Procurement Tech Investments of 2021" and "Top 10 Supply Chain Management Solutions". The company serves mission-critical sectors like Aerospace & Defense and the U.S. Federal Government. ## Competitive Advantages - **Comprehensive Data Fabric**: A proprietary, AI-driven engine that ingests, normalizes, and resolves data from over 20 pipelines and 250k+ supplier attributes, creating a single source of truth. - **Agentic AI**: Uses "agentic intelligence" to autonomously fetch, refresh, normalize, and resolve supplier records across disparate sources, reducing manual work. - **Network Graph Technology**: Maps complex supplier hierarchies and dependencies that traditional tools miss, providing a 360-degree view of risk. - **Trusted by High-Stakes Customers**: Serves Defense primes and the U.S. Federal Government, indicating a high bar for security, compliance, and reliability. - **Speed & Efficiency**: Quantified results (90% faster due diligence, 87% faster onboarding) demonstrate clear ROI over manual or legacy processes. ## Strategic Focus - **Deepening AI & Automation**: Further integrating agentic intelligence to automate data gathering and risk detection. - **Expanding Industry Verticals**: Building on strength in Aerospace & Defense and Government to serve more sectors (e.g., healthcare, manufacturing, energy). - **Sustainability & Resilience**: Aligning product development with the mission to create more ethical and sustainable global supply chains. - **Growth & Hiring**: Actively expanding teams in San Francisco, London, Austin, and Seattle, with a focus on engineering, product, and data science roles. ## Why Work Here - **Culture**: Described as "a diverse and passionate team of experts – from technologists to data scientists and supply chain professionals" that infuses a "warm, fun, and collaborative spirit" into serious work. Values include innovation, collaboration, humility, and accountability. - **Remote/Hybrid Policy**: Hybrid company with offices in four major cities (San Francisco, London, Austin, Seattle) and remote employees worldwide. The San Francisco office is centrally located near Montgomery Street BART. The Austin and Seattle hubs are growing but do not yet have permanent offices; teams there gather for regular events. - **Benefits & Perks**: Unlimited PTO, 99% benefits coverage, 401k plan, parental leave, flexible work hours. - **Engineering & Innovation Focus**: The platform is built on cutting-edge AI, data engineering, and graph technology, offering challenging technical work on a mission-critical problem. The company has been recognized with multiple industry awards. ## Sources 1. [Craft.co Homepage](https://global.craft.co/) 2. [Craft.co About Us](https://global.craft.co/about-us/) 3. [Craft.co Culture & Careers](https://global.craft.co/careers/) 4. [Craft.co Career Openings](https://global.craft.co/careers/career-openings/) 5. [Craft Machine Inc Jobs on Ashby](https://jobs.ashbyhq.com/craft.co/) 6. [TechCrunch - Craft raises $100M Series B (2022)](https://techcrunch.com/2022/01/27/craft-raises-100m-series-b-to-help-companies-manage-supply-chain-risk/) 7. [Crunchbase - Craft Machine Inc](https://www.crunchbase.com/organization/craft-machine-inc) ## Other roles at Craft Machine Inc - [Sr. Data Platform Engineer (US)](https://feeny.ai/job/sr-data-platform-engineer-us-craft-machine-inc-united-states-j7etd9tj1r0y) — United States