Trial Library logo
Trial LibraryPosted 1 week ago

DevSecOps / Cloud Engineer

HybridSan Francisco, California, United States

Full TimeStartup

Job Summary

Manage Terraform codebases, multi-account AWS landing zones, and security tooling including Security Hub, GuardDuty, and Config. Own the vulnerability lifecycle, secure GitHub Actions pipelines with least-privilege OIDC, and enforce SOC 2 and HIPAA controls through compliance-as-code. Lead disaster recovery testing, IAM governance, and Bedrock AI workload security alongside the Dev Team. Produce evidence for audits, coordinate penetration tests, and partner with application engineers on Lambda and Aurora PostgreSQL workloads. Maintain observability dashboards and cost visibility while ensuring blast-radius-safe deployments in regulated environments.

Required Qualifications

  • 5+ years in DevSecOps, security, platform, or infrastructure engineering, operating production systems you were accountable for
  • Demonstrated security ownership: you have run vulnerability management, remediated real findings, and participated in incident response - not just deployed tooling
  • Deep Terraform proficiency: module hierarchies, multi-environment state, drift and refactors, critical plan review
  • Hands-on AFT and Control Tower experience - you have vended accounts through AFT and customized the pipeline, not adjacent familiarity
  • Broad AWS depth: IAM, Organizations, VPC, Lambda, RDS/Aurora, S3, KMS, CloudTrail, Config, Security Hub, GuardDuty, Secrets Manager
  • GitHub Actions as a daily environment, including pipeline hardening and secrets management
  • SOC 2 Type II and HIPAA experience in a real PHI-handling environment - you have owned controls, produced evidence, and sat in front of an auditor
  • Change and release discipline: you think about blast radius before you apply, have owned deployment and rollback strategies in production, and move quickly inside regulated-environment constraints rather than treating them as obstacles
  • Hands-on, autonomous, and clear: you write code daily, take ambiguous problems to documented decisions, and can explain security tradeoffs to non-security people
  • You use AI coding and automation tools as a daily part of how you work, and you actively explore how they change infrastructure and security practices
  • Genuine interest in improving clinical trial access and health equity

Desired Qualifications

  • Compliance automation platforms (Drata, Vanta) including evidence automation
  • CloudFormation/CDK/Serverless-to-Terraform migration experience
  • GitHub EMU, SCIM, and SAML SSO administration
  • Aurora PostgreSQL operations and schema migration coordination
  • Python or TypeScript for automation
  • HITRUST, NIST 800-53, or CSA STAR exposure
  • Securing LLM workloads

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce