FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

DevSecOps Engineer
Claritas RxDevSecOps Engineer securing Claritas Rx’s AWS-hosted digital health SaaS platform for rare-disease treatment access. Managing cloud controls, incident response, vulnerability programs, and healthcare compliance.
Posted 8/23/2026full-timeRemote • 🇺🇸 United StatesMid-LevelSenior💰 $130,000 - $160,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in AWS security, including IAM, KMS, and VPC security, while effectively managing vulnerability programs and responding to security incidents. Proficient in integrating security practices into CI/CD pipelines and ensuring compliance with HIPAA and SOC 2 requirements.
Highest-signal resume keywords
AWS Security ExpertiseVulnerability Management ProgramIncident Response and InvestigationCI/CD Security IntegrationHIPAA and SOC 2 Compliance
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
AWS IAMAWS KMSAWS VPC SecurityAWS CloudTrailAWS GuardDutyAWS Security HubSAST IntegrationDAST IntegrationPython ScriptingBash Scripting
Soft Skills
Strong Communication SkillsCollaborative MindsetAbility to Influence
Tools & Technologies
AWS ConfigAWS InspectorAWS MacieGitHub ActionsAWS Secrets Manager
Certifications & Qualifications
AWS Security SpecialtyCISSPCISMCEHOSCPCompTIA Security+
Industry Keywords
HIPAASOC 2HITRUSTPHI HandlingThreat ModelingPenetration Testing
Tech Stack
Tools & technologiesAWSCloudPostgresPythonReactSDLCTypeScript
About the role
Key responsibilities & impact- Protect the confidentiality, integrity, and availability of Claritas Rx's AWS-hosted SaaS platform processing sensitive patient and commercial data
- Own day-to-day security engineering, including infrastructure hardening, vulnerability management, security-event response, and SDLC security integration
- Tune and triage alerts from AWS GuardDuty, Security Hub, CloudTrail, and related tools
- Investigate, contain, remediate, and document security incidents; lead post-incident reviews and corrective actions
- Improve detection capabilities, log-analysis pipelines, alert rules, and correlation logic to reduce MTTD and MTTR
- Participate in the security-event on-call rotation and maintain escalation paths and runbooks
- Design, implement, and maintain AWS security controls, including IAM, SCPs, KMS, VPC security, WAF, and network segmentation
- Review AWS configurations using AWS Config, Inspector, Macie, and third-party tooling; remediate and track findings
- Partner with SRE on secure AWS CDK infrastructure-as-code templates and version-controlled, auditable, reproducible controls
- Evaluate AWS services and architecture changes for security implications and advise engineering teams
- Implement security-focused observability patterns
- Support vulnerability lifecycle activities including asset discovery, scanning, prioritization, remediation tracking, and reporting
- Integrate SAST, DAST, dependency scanning, and container image scanning into GitHub Actions CI/CD pipelines
- Research emerging threats, CVEs, and attacker techniques and translate findings into defensive improvements
- Support HIPAA, SOC 2 Type II, and HITRUST programs through evidence collection, control testing, and gap remediation
- Ensure PHI handling, encryption, access control, data classification, and audit logging meet regulatory requirements
- Maintain and test encryption, key management, secrets rotation via AWS Secrets Manager, and DLP controls
- Support external audits by preparing evidence, responding to auditors, and tracking findings through remediation
- Develop and maintain security policies, standards, and procedures
- Administer AWS IAM roles, policies, permission boundaries, and identity access lifecycles
- Improve MFA, SSO, authentication, authorization, and privileged access management
- Collaborate with SRE and Software Engineering on production readiness, architecture, and deployment security
- Provide practical, risk-informed security guidance to engineering teams
- Communicate security risks and program status to technical and non-technical stakeholders, including leadership
- Report to the Sr. Manager, Site Reliability
Requirements
What you’ll need- 4+ years of experience in information security engineering, cloud security, or a closely related discipline with hands-on technical ownership
- Solid practical AWS security expertise, including IAM, KMS, VPC security, CloudTrail, GuardDuty, Security Hub, Config, and WAF
- Experience operating a vulnerability management program across infrastructure and application layers
- Demonstrated ability to respond to and investigate cloud-environment security incidents from triage through containment, root cause analysis, and corrective action
- Familiarity integrating SAST, DAST, dependency scanning, and container scanning into CI/CD pipelines and developer workflows
- Working knowledge of HIPAA, SOC 2, and/or HITRUST technical-control requirements
- Scripting proficiency in Python, Bash, or equivalent
- Strong written and verbal communication skills
- Collaborative, team-oriented mindset and ability to influence without direct authority
- Ability to operate independently in a fast-paced, high-growth startup environment
- Primarily remote work with occasional travel requirements
- Preferred: healthcare technology or digital health experience with HIPAA-regulated PHI
- Preferred: threat modeling methodologies such as STRIDE or PASTA
- Preferred: penetration testing concepts and third-party security assessments
- Preferred: privileged access management and secrets management at scale
- Preferred: TypeScript, NestJS, PostgreSQL, and React
- Preferred: AI tools, including Claude
- Preferred: relevant certifications such as AWS Security Specialty, CISSP, CISM, CEH, OSCP, or CompTIA Security+
- Preferred: B.S. in Computer Science, Information Security, or a related discipline, or equivalent practical experience
Benefits
Comp & perks- Flexible, collaborative work environment
- Unlimited PTO
- Stock options
- Growing set of tools and technology
- Accelerated professional development through shared learning and collaboration
- Respectful and fun work environment
- Employee empowerment through effective use of technology and tools
- Regional town hall gatherings approximately every other month for employees within reasonable driving distance
- Competitive benefits package
- Company-provided onboarding equipment; no purchases required