1 час назад
DevSecOps Professional (AWS)
130 000 - 160 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
DevSecOps Professional (AWS): Protecting and hardening an AWS-hosted SaaS platform that processes sensitive patient and commercial data with an accent on cloud security, vulnerability management, incident response, and regulatory compliance. Focus on designing IAM, KMS, VPC, WAF, and monitoring controls, integrating security scanning into CI/CD, and maintaining HIPAA, SOC 2 Type II, and HITRUST requirements.
Location: Remote within the United States; occasional travel is required.
Salary: $130,000–$160,000 per year, plus benefits and stock options.
Company
is a digital health company using AI, predictive modeling, real-world data, analytics, and CRM capabilities to improve treatment access and adherence for patients with rare and specialty diseases.
What you will do
- Monitor the AWS platform using GuardDuty, Security Hub, CloudTrail, and related security tooling.
- Investigate, contain, remediate, and document security incidents while improving detection, alerting, and response processes.
- Design and maintain AWS security controls across IAM, SCPs, KMS, VPCs, WAF, network segmentation, secrets, and data protection.
- Review cloud configurations, remediate vulnerabilities, and evaluate security implications of new AWS services and architectural changes.
- Integrate SAST, DAST, dependency, and container scanning into GitHub Actions CI/CD pipelines.
- Support HIPAA, SOC 2 Type II, and HITRUST compliance through control testing, evidence collection, audits, and remediation.
Requirements
- 4+ years of experience in information security engineering, cloud security, or a closely related discipline.
- Hands-on AWS security experience with IAM, KMS, VPC security, CloudTrail, GuardDuty, Security Hub, Config, and WAF.
- Experience operating vulnerability management programs and responding to cloud security incidents.
- Experience integrating security tooling into CI/CD pipelines and developer workflows.
- Working knowledge of HIPAA, SOC 2, and/or HITRUST technical controls.
- Proficiency in Python, Bash, or an equivalent scripting language, with strong communication and collaboration skills.
Nice to have
- Healthcare technology or digital health experience involving HIPAA-regulated PHI.
- Threat modeling, penetration testing, third-party security assessment, PAM, or secrets management experience.
- Experience with TypeScript, NestJS, PostgreSQL, React, or the broader application stack.
- Experience using AI tools for threat hunting, security documentation, or compliance evidence workflows.
- Relevant security certifications or a related degree.
Culture & Benefits
- Flexible, collaborative, fast-paced, and results-driven work environment.
- Unlimited PTO, stock options, and a competitive benefits package.
- Opportunities for shared learning, collaboration, professional development, and employee empowerment.
- Regional in-person town halls approximately every other month for employees within reasonable driving distance.
- Participation in an on-call rotation for security events.
Hiring process
- Submit a resume and cover letter.
- Expect multiple video interviews; offers are not made after a single call or form.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Senior Security Operations Engineer (Cybersecurity)
136 000 - 155 000$
7 часов назад
Senior Cloud Security Engineer (AWS)
140 000 - 165 000$
3 дня назад
Cloud Security Engineer (Oracle)
100 000 - 150 000$
4 дня назад
DevSecOps Engineer / Security Solutions Lead (FinTech)
5 дней назад
DevSecOps Engineer (GCP/Kubernetes)
179 451 - 187 900$
5 дней назад
Security Engineer
160 000 - 185 000$