Role Overview
We are looking for an experienced Cloud / DevSecOps & Security Engineer to build and maintain secure, scalable cloud infrastructure for healthcare applications. The role combines cloud engineering, infrastructure-as-code, CI/CD, containerization, security engineering, monitoring and secure remote-access architecture.
Responsibilities
- Design, implement and maintain cloud infrastructure on AWS or Azure.
- Implement infrastructure-as-code using Terraform and/or CloudFormation.
- Build and maintain CI/CD pipelines.
- Manage containerized application environments and orchestration.
- Implement healthcare security controls aligned with the HIPAA Security Rule.
- Apply principles from the NIST Cybersecurity Framework / NIST SP 800-53.
- Implement encryption in transit and at rest, Role-based access control, Least-privilege access, Centralized audit logging, and Key management.
- Design and maintain secure remote-access architecture using VDI / zero-trust principles.
- Ensure PHI is not stored on offshore or personal endpoints.
- Implement monitoring, security detection and incident-response capabilities.
- Support security documentation, audits and compliance requirements.
- Collaborate with development and AI/ML teams to integrate security into the software development lifecycle.
Requirements
- 3+ years of cloud engineering experience with AWS or Azure.
- Strong DevOps experience.
- Hands-on experience with Terraform and/or CloudFormation.
- Experience implementing CI/CD pipelines.
- Experience with containers and container orchestration.
- Strong understanding of cloud security.
- Experience implementing encryption, RBAC, audit logging and key management.
- Knowledge of HIPAA Security Rule safeguards.
- Familiarity with NIST CSF / NIST SP 800-53.
- Experience with secure remote-access architecture.
- Knowledge of monitoring, security detection and incident response.
Preferred Skills
- Healthcare cloud compliance experience.
- Experience preparing applications for athenahealth Marketplace security review.
- SOC 2 control implementation experience.
- NIST control implementation experience.
- Experience working in regulated environments.
Skills
- AWS
- Terraform
- CI/CD
- Azure
- CloudFormation