DevOps & Security Engineer at Studyfetch
Beverly Hills, CA
$170,000–$270,000from the description
Jul 5, 2026
Beverly Hills, CA
Jul 21, 2026
What this job asks for AI summary
A security and DevOps engineering role at an AI-powered learning platform, focused on owning the full security posture of cloud and Kubernetes infrastructure, CI/CD pipelines, compliance programs (SOC 2, with a path toward FedRAMP), and incident response. The position also involves securing a new GPU and colocation facility buildout. It suits engineers with hands-on production security and operations experience who work well with significant autonomy.
Senior level · 5+ years · San Francisco-Oakland-Berkeley, CA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 40 people in the San Francisco-Oakland-Berkeley, CA area plausibly meet what this posting asks for (information security analysts). range 25–60
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $165,879 (middle half $117,529–$206,125). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
This role is a genuine hybrid of security engineering and DevOps/SRE; 15-1212 (Information Security Analysts) was chosen as primary because security posture, compliance (SOC 2, FedRAMP roadmap), and hardening are explicitly the first-listed and most-emphasized ownership areas. 15-1244 is the runner-up given the substantial infrastructure operations and CI/CD ownership.
Location is not explicitly stated in the posting, but the role is described as in-person and the company (StudyFetch) is headquartered in San Francisco, CA — CBSA assigned accordingly.
The 'stack you'll work in' section is framed as 'you don't need every item below, but you should be deep in most' — specific named tools (GCP, Cloudflare, Vercel, GKE, Helm, Jenkins, Pulumi/Terraform, GitOps, VPC, PostgreSQL, MongoDB, GPU/model-serving) are listed there and treated as preferred rather than hard gates. The hard gates (IAM, secrets management, network security, Kubernetes security, SOC 2, CI/CD, infrastructure-as-code) are drawn from the explicit 'What we're looking for' requirements section.
Pulumi is listed first in the IaC requirement ('Pulumi or Terraform'); Terraform is captured as an alternative.
Jenkins is listed first in the CI/CD requirement ('Jenkins or similar'); common substitutes are captured as alternatives.
FedRAMP is described as a future roadmap framework ('awareness of frameworks like FedRAMP'), not a current hard requirement — listed as preferred.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secrets management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.