Summary
What you’ll impact
The Senior DevOps & Security Engineer at the organization is a hands‑on technical role focused on building, operating, securing, automating, and improving cloud infrastructure and software delivery environments. Reporting to the Director of IT, DevOps & Security, the engineer works across Engineering, Data, and other teams to ensure secure, reliable, and well‑monitored systems, with an emphasis on cloud security, compliance, and production reliability.
Responsibilities
What you'll do
- The Senior DevOps & Security Engineer is a hands‑on technical role responsible for building, operating, securing, automating, and improving our cloud infrastructure and software delivery environments.
- Translate security and compliance requirements into practical technical controls and directly support HIPAA, SOC 2, and related activities
- Build, maintain, secure, and improve AWS infrastructure, Kubernetes/EKS environments, identity and access controls (IAM), networking, databases, storage, logging, monitoring, and SIEM integrations
- Develop and maintain Terraform, secure CI/CD pipelines, deployment tooling, and related automation
- Manage vulnerability scanning, security telemetry, incident response support, and application/infrastructure hardening
- Partner with Engineering, Data, and other internal teams to automate workflows, connect systems, and reduce manual work
- Build scripts, integrations, internal tools, and API-based automations across technical and business systems
- Maintain clear technical documentation, architecture diagrams, and infrastructure security standards
- Research and evaluate new tools, security practices, and infrastructure approaches to determine how they can be applied effectively in our environment
- Participate in on-call or escalation coverage as operational needs evolve. Our production environment is generally stable and relatively low‑traffic, so after‑hours work tends to focus more on planned maintenance, upgrades, and proactive security improvements than on responding to outages
Requirements
What you’ll bring
- 4+ years of experience in cloud security engineering, DevOps, cloud infrastructure, SRE, or a related field
- Strong understanding of cloud security, IAM, networking, vulnerability management, observability, and incident response
- Hands‑on experience supporting or implementing security controls in regulated environments (e.g., HIPAA, SOC 2)
- Hands‑on experience with SentinelOne (or similar EDR/endpoint security platforms), AWS, Terraform, Kubernetes, and securing CI/CD pipelines
- Ability to write scripts (Python, Bash, etc.) and work with APIs, integrations, and security automation
- Excellent written and verbal communication skills, with a proven ability to produce clear technical writing, architecture documentation, and cross‑functional collaboration
- Ability to work independently, research unfamiliar problems, and take projects from problem definition through implementation
- Experience in healthcare, healthtech, financial services, or another highly regulated sector
- Familiarity with tools such as Datadog, SentinelOne, Argo CD, GitHub Actions, or Google Workspace administration
- Direct experience with SIEM setup, detection engineering, or penetration testing remediation
- Background in disaster recovery planning and backup restoration testing