Salary
💰 $115,000 - $135,000 per year
Tech Stack
AWSCloudDockerEC2GrafanaHAProxyKubernetesPrometheusSDLCTerraformVault
About the role
- Maintain and improve our security posture by implementing and monitoring necessary security controls
- Design, implement, and maintain CI/CD pipelines using GitLab CI/CD
- Develop and manage AWS infrastructure using Infrastructure as Code (Terraform)
- Automate deployment, monitoring, and management processes to reduce manual intervention
- Manage and mitigate supply chain risks by monitoring third-party components and dependencies (e.g., Snyk)
- Implement and maintain monitoring and observability solutions (DataDog, Prometheus, Grafana) to ensure system health and performance
- Partner with development and product teams to integrate security throughout the SDLC
- Own incident response processes, including detection, triage, and resolution of security events
- Serve as the security champion within the organization, driving a culture of security awareness
- Research and evaluate new tools and processes to continuously improve security and operational efficiency
- Collaborate with engineering, product, and operations teams; report to VP of Engineering
Requirements
- 3+ years of experience in DevOps, SecOps, or related roles
- Bachelor's degree in Computer Science, Engineering, or related field (or equivalent experience)
- Expertise with AWS services (EC2, S3, RDS, Lambda, VPC) and security best practices
- Experience with Infrastructure as Code (Terraform)
- Familiarity with containerization and orchestration (Docker; Kubernetes or Nomad a plus)
- Proficiency with CI/CD pipelines (GitLab preferred)
- Hands-on experience with monitoring, logging, and alerting tools (DataDog, Prometheus, Grafana)
- Experience with security scanning tools (Snyk, Dependabot, or similar)
- Strong knowledge of security principles, identity and access management, and compliance frameworks (SOC 2)
- Experience with secrets management and access control systems (e.g., Vault, AWS IAM)
- Strong troubleshooting and problem-solving skills
- Excellent communication skills and ability to work cross-functionally
- Proactive, curious, and able to work independently as a security leader
- A Huge Plus: Experience with FreeIPA or other enterprise identity management solutions
- A Huge Plus: Experience with HAProxy or other load-balancing technologies
- A Huge Plus: Familiarity with SOC 2 and HIPAA compliance requirements
- A Huge Plus: Background in healthcare or pharmacy SaaS environments
- Must reside in one of the following U.S. states to be considered: California, Colorado, Florida, Georgia, Illinois, Louisiana, Maryland, Nevada, New Hampshire, New Jersey, New York, North Carolina, Ohio, Pennsylvania, Rhode Island, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin
- Must be authorized to work in the United States; employer participates in E-Verify and will conduct background checks