DevSecOps Engineer

Claritas Rx β€” United States Β· Posted ~2 hours ago

Full-time

Skills

DevOps Cloud infrastructure Security engineering CI/CD Cloud Security tools

πŸ”“ Log in to save this job, tailor your resume & track your apply process β€” 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A DevSecOps position focused on building secure, scalable infrastructure and supporting technology platforms that use advanced data and automation capabilities.

Highlights

Join a mission-driven technology team building secure digital solutions with modern engineering practices and advanced analytics.

Description

Who We Are Claritas Rx uses AI and predictive modeling to help rare disease and specialty brands remove the barriers that keep patients from accessing and staying on the treatments they need. By uniting the most complete view of the patient journey with purpose-built technologies, we predict and resolve access challenges before they disrupt care, combining advanced analytics, real-world data, AI, and CRM capabilities to increase start and refill rates, reduce abandonment, and improve brand performance. Our mission is to ensure patients with chronic, life-threatening diseases receive the support that enables the greatest benefit from their therapy. Simply put, our promise is progress for every patient journey. This is the opportunity to help shape a first-in-industry digital health solution alongside a team of mission-driven professionals. We were named one of Inc.'s Best Workplaces in 2025 and recognized on the Inc. 5000 list for two consecutive years (2025 and 2026), and our team genuinely respects and supports each other. We thrive on being fast-paced, innovative, and results-driven, and our employees enjoy a flexible, collaborative work environment, unlimited PTO, stock options, and a growing set of tools and technology to drive innovation for our customers. The Position We are seeking a skilled and hands-on DevSecOps professional to join our Engineering team. Reporting to the Sr. Manager, Site Reliability, you will be a key individual contributor responsible for protecting the confidentiality, integrity, and availability of Claritas Rx's AWS-hosted SaaS platform β€” a system that processes sensitive patient and commercial data for some of the world's leading biopharmaceutical companies. In this role, you will own day-to-day security engineering work: hardening infrastructure, managing vulnerability programs, responding to security events, and embedding security practices into the software development lifecycle. You will work closely with Software Engineering, SRE, and external compliance partners to ensure our platform maintains the rigorous compliance posture our customers and regulators require β€” including HIPAA, SOC 2 Type II, and HITRUST. This is a high-impact individual contributor role suited to an engineer who thrives at the intersection of security and cloud infrastructure, takes ownership of outcomes, and brings a builder's mindset to security problems. The role is primarily remote with occasional travel requirements. Key Accountabilities Security Monitoring & Incident Response Own security monitoring across the platform: tune and triage alerts from AWS GuardDuty, Security Hub, CloudTrail, and related tooling to distinguish signal from noise and surface actionable threatsServe as a primary responder for security incidents β€” investigate, contain, and remediate threats; document findings; and drive post-incident reviews with clear corrective actionsMaintain and continuously improve detection capabilities, including log analysis pipelines, alert rules, and correlation logic, to reduce mean time to detect (MTTD) and mean time to respond (MTTR)Participate in on-call rotation for security events, with appropriate escalation paths and runbooks in place Cloud Security Engineering Design, implement, and maintain security controls across the AWS environment β€” including IAM policies, SCPs, KMS key management, VPC security, WAF rulesets, and network segmentationConduct regular reviews of cloud configurations using AWS Config, Inspector, Macie, and third-party tooling; remediate findings and track resolution to closurePartner with the SRE team to ensure infrastructure-as-code (AWS CDK) templates follow security best practices and that security controls are version-controlled, auditable, and reproducibleEvaluate new AWS services and architectural changes for security implications, providing clear guidance to engineering teams before and during adoptionImplement security focused observability patterns to detect threats as they emerge Vulnerability Management Support the vulnerability management lifecycle: asset discovery, scanning (infrastructure and application), risk-based prioritization, remediation tracking, and reportingCoordinate with Software Engineering to integrate SAST, DAST, dependency scanning, and container image scanning into CI/CD pipelines (GitHub Actions), ensuring vulnerabilities are caught early in the SDLCTrack and communicate vulnerability metrics to engineering and leadership, balancing remediation urgency against engineering capacityResearch emerging threats, CVEs, and attacker techniques relevant to our technology stack and cloud environment; translate findings into actionable defensive improvements Compliance & Data Protection Support the maintenance and continuous improvement of Claritas Rx's HIPAA, SOC 2 Type II, and HITRUST compliance programs β€” including evidence collection, control testing, and gap remediationEnsure PHI handling practices β€” at rest, in transit, and in processing β€” meet regulatory requirements; identify and close gaps in data classification, encryption, access control, and audit loggingMaintain and test data protection controls including encryption key management, secrets rotation (via AWS Secrets Manager), and DLP measuresSupport external audits and assessments: prepare evidence packages, respond to auditor inquiries, and track audit findings through remediationContribute to the development and maintenance of security policies, standards, and procedures Identity & Access Management Administer and continuously refine AWS IAM roles, policies, and permission boundaries, applying least-privilege principles across all environmentsManage access lifecycle processes: provisioning, periodic access reviews, and de-provisioning for human and machine identitiesEvaluate and improve authentication and authorization controls β€” including MFA enforcement, SSO integration, and privileged access management Cross-Functional Partnership Collaborate with SRE and Software Engineering to embed security requirements into production readiness reviews, architecture decisions, and deployment processesServe as a trusted security resource for engineering teams β€” providing practical, risk-informed guidance rather than purely compliance-driven mandatesCommunicate security risks and program status clearly to both technical peers and non-technical stakeholders, including leadership Our Stack Cloud: AWS (ECS, EC2, Aurora RDS, DynamoDB, Lambda, S3, SQS, EventBridge, Cognito, Secrets Manager, CloudFront, WAF)Infrastructure as Code: AWS CDK (primary); familiarity with Terraform/OpenTofu a plusCI/CD: GitHub ActionsApplication Platform: NestJS/TypeScript (backend), React/TypeScript (frontend), PostgreSQL, Turborepo, pnpmData Platform: AWS Glue, Lake Formation, PySpark, Kinesis (data streaming), Python-based ELT pipelinesObservability & Monitoring: CloudWatch (logs, metrics, alarms, dashboards), Sentry, OpenFeature (feature flags), TableauLanguages in Use Across Engineering: TypeScript, Python, SQL; Golang familiarity a plusWork Management: JiraCompliance: HIPAA, SOC 2 Type II, HITRUST Who You Are Required Skills: 4+ years of experience in information security engineering, cloud security, or a closely related discipline with hands-on technical ownershipSolid, practical AWS security expertise β€” you understand IAM, KMS, VPC security, CloudTrail, GuardDuty, Security Hub, Config, and WAF at a working level, not just conceptuallyExperience operating a vulnerability management program: scanning, prioritization, tracking, and reporting across infrastructure and application layersDemonstrated ability to respond to and investigate security incidents in a cloud environment β€” from initial triage through containment, root cause analysis, and corrective actionFamiliarity with integrating security tooling (SAST, DAST, dependency scanning, container scanning) into CI/CD pipelines and developer workflowsWorking knowledge of HIPAA, SOC 2, and/or HITRUST requirements as they apply to technical controls β€” you understand what compliance requires and how to implement it in an engineering contextScripting proficiency in Python, Bash, or equivalent for automating security tasks, log analysis, and tooling integrationsStrong written and verbal communication skills β€” you can explain security risk and technical trade-offs clearly to both engineering peers and non-technical stakeholdersCollaborative, team-oriented mindset with the ability to influence security outcomes without direct authorityComfort operating independently in a fast-paced, high-growth startup environment where priorities shift and initiative is expected Preferred Skills: Experience in a healthcare technology or digital health environment with direct exposure to HIPAA-regulated PHI and the controls required to protect itHands-on experience with threat modeling methodologies (e.g., STRIDE, PASTA) applied to cloud-native application architecturesFamiliarity with penetration testing concepts and experience participating in or coordinating third-party security assessmentsExperience with privileged access management (PAM) tooling and secrets management at scaleExposure to the Claritas Rx application stack: TypeScript, NestJS, PostgreSQL, ReactExperience leveraging AI tools (including Claude) to accelerate threat hunting, automate security documentation, or streamline compliance evidence workflowsRelevant certifications such as AWS Security Specialty, CISSP, CISM, CEH, OSCP, CompTIA Security+, or equivalentB.S. in Computer Science, Information Security, or a related discipline, or equivalent practical experience Join Us We are seeking to add new expertise and perspective to our strong team of experienced professionals. We aspire to a culture of accelerated professional development through: shared learning and collaboration; a respectful and fun work environment; and employee empowerment through the effective use of technology and tools. We are a highly collaborative team and prioritize opportunities to connect in person. For employees within a reasonable driving distance of each other, we host regional town hall gatherings approximately every other month. These sessions give our teams a chance to come together, share updates, and strengthen relationships beyond day-to-day work. In addition to our great environment, we offer a competitive salary of $130,000 to $160,000 and benefits package and the opportunity to make a significant impact on a first-in-industry digital health solution. Please send a cover letter along with your resume when applying to the position of interest. Claritas Rx embraces diversity, equality, and transparency. We are committed to building a team that comprises a variety of backgrounds, perspectives, and talents. We believe the more inclusive we are, the better we are. Join us and discover what it feels like to be part of an environment that rewards ingenuity, risk taking and smart work. It's time to fall in love with what you do! At Claritas Rx, protecting our candidates is a top priority. If you're applying for a role with us, please note: β€’All legitimate opportunities are posted first on ClaritasRx.com. Check there before trusting external listings. β€’ We believe in meaningful interviews: offers never come after just one phone call or form. Expect multiple video calls to get to know you. β€’ We never ask for fees or payments of any kind during the hiring process. β€’ Our People Operations Team will handle your onboarding, and all equipment comes directly from usβ€”no purchases required. Learn more about how to spot recruitment scams and protect yourself - FBI warning: https://bit.ly/4aDF5wU Claritas Rx is committed to transparency, integrity, and a safe hiring experience for every candidate. Learn more https://www.claritasrx.com/about/careers/