h2o.ai logo

Devops Engineer

h2o.ai

Colombo, Colombo, Sri LankaRemoteJobNo compensation foundPosted 1mo agoSeen in employer's feed 6 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Colombo, Colombo, Sri LankaRemote
Work Authorization
Not specified

Job overview

h2o.ai is hiring a Devops Engineer. H2O.ai seeks a DevOps Engineer to join its Cloud Platform team in Colombo, focusing on scaling vulnerability management and security compliance across containerized platforms for regulated enterprises, supporting FedRAMP, SOC2, and banking requirements while collaborating with engineering teams.

Key focus areas include Own and lead analysis and triage of vulnerability scan results, Work directly with engineering teams to evaluate remediation options, and Remediate vulnerabilities hands‑on by upgrading dependencies and rebuilding images.

Successful candidates bring 2-4 Years Application Security Experience, 2-4 Years DevSecOps Experience, and 3+ Years Software Engineering Experience. Important skills include Vulnerability Management, Security Compliance, Security Findings Triage, Security Findings Analysis, Dependency Upgrading, and Container Image Rebuilding. Preferred (not required): FedRAMP, SOC 2, ISO 27001, and Banking Regulations.

Skills & qualifications

RequiredNice to have

Skills

Vulnerability ManagementSecurity ComplianceSecurity Findings TriageSecurity Findings AnalysisDependency UpgradingContainer Image RebuildingPatchingSecurity Tooling DevelopmentCross-Functional CoordinationVulnerability RemediationFedRAMP Continuous MonitoringPOA&M ManagementCompliance ReportingAutomation InfrastructureRisk AssessmentContainer Image Security ControlsKubernetes Security PoliciesSecurity DocumentationRunbooksCompliance ArtifactsSecurity Incident ResponseCustomer EscalationsPythonJavaScriptGoRubyJavaReading CodeWriting CodeDebugging CodeDeploying CodeNpmPipMavenBundlerGitHub ActionsGitLab CIJenkinsCircleCIGit BranchingPull RequestsCode ReviewTesting MindsetCVE AssessmentVulnerability Findings AnalysisSecurity Scanning ToolsKubernetes Security ConceptsCommunicationDependency ManagementCI/CDGitBranchingContainer SecurityVulnerability AnalysisStrong Follow-ThroughDetail-OrientedCustomer-Focused ApproachSelf-MotivatedWorking in Remote-First EnvironmentFedRAMPSOC 2ISO 27001Banking Regulations

Qualifications

2-4 Years Application Security Experience2-4 Years DevSecOps Experience3+ Years Software Engineering Experience

Full job description

Founded in 2012, H2O.ai is on a mission to democratize AI. As the world’s leading agentic AI company, H2O.ai converges Generative and Predictive AI to help enterprises and public sector agencies develop purpose-built GenAI applications on their private data. With a focus on Sovereign AI—secure, compliant, and infrastructure-flexible deployments—H2O.ai delivers solutions that align with the highest standards of data privacy and control.

Our open-source technology is trusted by over 20,000 organizations worldwide, including more than half of the Fortune 500. H2O.ai powers AI transformation for companies like AT&T, Commonwealth Bank of Australia, Chipotle, Workday, Progressive Insurance, and NIH.

H2O.ai partners include NVIDIA, Dell Technologies, Deloitte, Ernst & Young (EY), Snowflake, AWS, Google Cloud Platform (GCP), VAST Data and MinIO. H2O.ai’s AI for Good program supports nonprofit groups, foundations, and communities in advancing education, healthcare, and environmental conservation. With a vibrant community of 2 million data scientists worldwide, H2O.ai aims to co-create valuable AI applications for all users.

H2O.ai has raised 256 million from investors, including Commonwealth Bank, NVIDIA, Goldman Sachs, Wells Fargo, Capital One, Nexus Ventures and New York Life.

About This Opportunity

H2O.ai is seeking a DevOps Engineer to join our Cloud Platform team and help scale our vulnerability management and security compliance operations. As H2O.ai serves highly regulated enterprises including major financial institutions and government agencies, maintaining robust security posture across our cloud platform is critical to customer success.

You'll manage vulnerability scanning and assessment across our containerized platform, lead triage and analysis of security findings, and work closely with engineering teams to coordinate fixes — and remediate vulnerabilities hands-on yourself, upgrading dependencies, rebuilding container images, and shipping patches. Your work will support compliance requirements for FedRAMP, SOC2, and banking regulations by ensuring timely vulnerability remediation. This role combines hands-on vulnerability remediation, security tooling development, vulnerability analysis, and cross-functional coordination to centralize vulnerability management expertise, allowing engineering teams to focus on their core product work.

This is an opportunity to build expertise in enterprise security operations while working with cutting-edge cloud-native technologies and making a direct impact on how large Fortune 500 companies and government agencies deploy AI securely.

This position is based in Sri Lanka.

What You Will Do

  • Own and lead analysis and triage of vulnerability scan results from multiple security tools, investigating findings to understand actual risk and exploitability in context

  • Work directly with engineering teams to understand remediation options, evaluate fix approaches, and coordinate timely resolution of security issues

  • Remediate vulnerabilities hands-on: upgrade dependencies, rebuild container images with patched components, and contribute fixes directly to product codebases

  • Test fixes thoroughly and verify remediation by re-scanning before and after deployment

  • Route vulnerabilities to component owners and actively track remediation progress, following up to ensure completion within required timeframes

  • Support FedRAMP continuous monitoring processes, including monthly POA&M management and compliance reporting

  • Engage with customer security teams to address vulnerability findings, reconcile scan results, and support deployment approvals

  • Maintain and extend our vulnerability management tooling and automation infrastructure

  • Build automations and processes that eliminate manual work and support continuous security improvement across the platform

  • Assess risk levels and communicate security findings to technical and non-technical stakeholders

  • Support container image security controls and Kubernetes security policies across customer environments

  • Contribute to security documentation, runbooks, and compliance artifacts for customer audits

  • Participate in security incident response and customer escalations as needed

What We Are Looking For

  • 2-4 years of experience in application security, product security, or DevSecOps roles

  • 3+ years of software engineering experience

  • Strong coding skills in at least 2 languages (Python, JavaScript, Go, Ruby, Java, etc.)

  • Comfortable reading, writing, debugging, and deploying code

  • Experience with dependency management (npm, pip, maven, bundler, etc.)

  • CI/CD experience (GitHub Actions, GitLab CI, Jenkins, CircleCI, etc.)

  • Git proficiency (branching, PRs, code review)

  • Testing mindset (write and run tests to validate fixes)

  • Strong understanding of container security, vulnerability management, and CVE assessment

  • Ability to analyze vulnerability findings deeply - understanding exploit paths, affected components, and contextual risk

  • Hands-on experience with security scanning tools

  • Familiarity with Kubernetes security concepts and best practices

  • Experience with compliance frameworks (FedRAMP, SOC2, ISO 27001, or banking regulations) preferred

  • Excellent written and verbal communication skills for cross-functional coordination with engineering teams

  • Strong follow-through and ability to drive remediation efforts across multiple teams

  • Detail-oriented mindset with ability to manage multiple priorities and deadlines

  • Customer-focused approach with ability to translate technical security findings into business context

  • Self-motivated and able to work effectively in a remote-first environment

Why H2O.ai?

  • Market leader in total rewards

  • Remote-friendly culture

  • Flexible working environment

  • Be part of a world-class team

  • Career growth

Sounds exciting? Let’s talk! We’re looking for smart, curious engineers who are ready to take on the challenge! Apply now and help us shape the future of enterprise AI software.

H2O.ai is committed to creating a diverse and inclusive culture. All qualified applicants will receive consideration for employment without regard to their race, ethnicity, religion, gender, sexual orientation, age, disability status or any other legally protected basis.

H2O.ai is an innovative AI cloud platform company, leading the mission to democratize AI for everyone. Thousands of organizations from all over the world have used our cutting-edge technology across a variety of industries. We’ve made it easy for people at all levels to generate breakthrough solutions to complex business problems and advance the discovery of new ideas and revenue streams. We push the boundaries of what is possible with artificial intelligence.

H2O.ai employs the world’s top Kaggle Grandmasters, the community of best-in-the-world machine learning practitioners and data scientists. A strong AI for Good ethos and responsible AI drive the company’s purpose.

Please visit www.H2O.ai to learn more.

#LI-Hybrid

For information about how H2O.ai collects, uses, and protects your personal information during the recruitment process, please review our Candidate Privacy Notice.

Powered by JazzHR

You've read the whole posting — now see how you match it.