
DevSecOps Engineer
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in United States.
• Safeguard the confidentiality, integrity, and availability of Claritas Rx's AWS-hosted SaaS platform that processes sensitive patient and commercial data.
• Oversee daily security engineering tasks, encompassing infrastructure hardening, vulnerability management, security-event response, and integration of security within the SDLC.
• Adjust and manage alerts from AWS GuardDuty, Security Hub, CloudTrail, and associated tools.
• Investigate, contain, remediate, and document security incidents; facilitate post-incident reviews and implement corrective actions.
• Enhance detection capabilities, log-analysis pipelines, alert rules, and correlation logic to minimize MTTD and MTTR.
• Engage in the security-event on-call rotation while maintaining escalation paths and runbooks.
• Design, implement, and uphold AWS security controls, such as IAM, SCPs, KMS, VPC security, WAF, and network segmentation.
• Assess AWS configurations utilizing AWS Config, Inspector, Macie, and third-party tools; address and track findings.
• Collaborate with SRE on secure AWS CDK infrastructure-as-code templates and ensure they are version-controlled, auditable, and reproducible.
• Evaluate changes in AWS services and architecture for security implications and provide guidance to engineering teams.
• Implement security-focused observability patterns.
• Assist in vulnerability lifecycle activities, including asset discovery, scanning, prioritization, remediation tracking, and reporting.
• Integrate SAST, DAST, dependency scanning, and container image scanning into GitHub Actions CI/CD pipelines.
• Research emerging threats, CVEs, and attacker techniques, translating findings into defensive enhancements.
• Support HIPAA, SOC 2 Type II, and HITRUST initiatives through evidence collection, control testing, and gap remediation.
• Ensure that PHI handling, encryption, access control, data classification, and audit logging comply with regulatory standards.
• Manage and test encryption, key management, secrets rotation via AWS Secrets Manager, and DLP controls.
• Facilitate external audits by preparing evidence, responding to auditors, and tracking findings through remediation.
• Develop and maintain security policies, standards, and procedures.
• Administer AWS IAM roles, policies, permission boundaries, and identity access lifecycles.
• Enhance MFA, SSO, authentication, authorization, and privileged access management.
• Work alongside SRE and Software Engineering to ensure production readiness, architecture, and deployment security.
• Deliver practical, risk-informed security guidance to engineering teams.
• Communicate security risks and program status to both technical and non-technical stakeholders, including leadership.
• Report to the Sr. Manager, Site Reliability.
• A minimum of 4 years of experience in information security engineering, cloud security, or a closely related field with hands-on technical ownership.
• Strong practical expertise in AWS security, including IAM, KMS, VPC security, CloudTrail, GuardDuty, Security Hub, Config, and WAF.
• Experience in managing a vulnerability management program across both infrastructure and application layers.
• Proven ability to respond to and investigate security incidents in cloud environments from triage to containment, root cause analysis, and corrective action.
• Familiarity with integrating SAST, DAST, dependency scanning, and container scanning into CI/CD pipelines and developer workflows.
• Working knowledge of HIPAA, SOC 2, and/or HITRUST technical-control requirements.
• Proficiency in scripting languages such as Python, Bash, or equivalent.
• Excellent written and verbal communication skills.
• Collaborative, team-oriented approach with the ability to influence others without direct authority.
• Capability to work independently in a fast-paced, high-growth startup environment.
• Primarily remote position with occasional travel requirements.
• Preferred: Experience in healthcare technology or digital health with HIPAA-regulated PHI.
• Preferred: Familiarity with threat modeling methodologies such as STRIDE or PASTA.
• Preferred: Knowledge of penetration testing concepts and third-party security assessments.
• Preferred: Experience in privileged access management and secrets management at scale.
• Preferred: Familiarity with TypeScript, NestJS, PostgreSQL, and React.
• Preferred: Experience with AI tools, including Claude.
• Preferred: Relevant certifications such as AWS Security Specialty, CISSP, CISM, CEH, OSCP, or CompTIA Security+.
• Preferred: A B.S. in Computer Science, Information Security, or a related field, or equivalent practical experience.
• Flexible and collaborative work environment.
• Unlimited PTO.
• Stock options.
• Access to a growing set of tools and technology.
• Accelerated professional development through shared learning and collaboration.
• A respectful and enjoyable work atmosphere.
• Employee empowerment through effective use of technology and tools.
• Regional town hall gatherings approximately every other month for employees within reasonable driving distance.
• Competitive benefits package.
• Company-provided onboarding equipment; no purchases required.
HubSpot
InfluxData
LocalStack
Amigo Tech
Get handpicked remote jobs straight to your inbox weekly.