Summary
✨ AI‑Generated
A DevSecOps engineering opportunity supporting a digital healthcare platform that handles sensitive patient information. The role sits at the intersection of cloud infrastructure, software development, cybersecurity, and highly regulated healthcare technology.
Highlights
Opportunity to work with cloud infrastructure, data-driven software development, and security-sensitive healthcare technology while contributing to a mission-driven digital healthcare platform.
Description
Greetings!
We are Olmait, a dynamic team of technology enthusiasts specializing in data science, cloud infrastructures, and data-driven software development.
Based in Israel and Georgia, we collaborate with forward-thinking startups across industries such as healthcare, cybersecurity, and e-commerce.
Our exceptional development team offers a rewarding work environment and significant opportunities for career growth.
A mission-driven Israeli health-tech company is building a smart, digital, and affordable healthcare platform in the US.
The company combines medical services and health insurance within a digital-first experience, making healthcare more accessible, efficient, and easier for members to manage.
Through its platform, members can access virtual medical care, receive prescriptions and referrals, manage lab results, and take greater control of their health — all within a secure digital environment.
Operating in healthcare means working with highly sensitive patient information and maintaining strict standards for security, privacy, reliability, and compliance.
As the platform continues to scale, security must be embedded throughout the infrastructure and software development lifecycle while allowing engineering and product teams to move quickly.
We are currently looking for a DevSecOps Engineer to help build and strengthen the security foundations of the platform, integrating security into cloud infrastructure, CI/CD processes, and development workflows while protecting patient data and supporting a fast-moving engineering organization.
Key Responsibilities:
Design, implement, and maintain robust security practices across our CI/CD pipelines, ensuring security is built-in from the start.Collaborate with engineering teams to integrate security measures into application development and cloud infrastructure, supporting a DevSecOps culture.Work in a GCP cloud environment to enhance security across various platforms, ensuring compliance with best practices and regulatory requirements.Develop and automate security tools and processes for continuous monitoring, vulnerability scanning, incident response, and risk management.Implement infrastructure-as-code (IaC) practices to automate provisioning, security, and monitoring tasks across our infrastructure.Stay up to date with emerging security threats, vulnerabilities, and compliance standards to keep our environments secure.Provide guidance and mentorship to development teams on security best practices and assist in threat modelling.Collaborate with cross-functional teams to drive the adoption of secure coding practices and create a strong security culture across the organization.Help improve our cloud security posture, including identity and access management, network security, and incident detection.
Requirements:
3+ years' experience in a DevSecOps or similar role, with a strong background in security and operationsHands-on experience with GCP cloud platforms (or equivalent) and familiarity with IaC frameworks like Terraform/Helm and such.Strong experience with containerized deployments and orchestration tools like Kubernetes and HelmStrong knowledge of security frameworks and methodologies (NIST, OWASP, CIS) and understanding of security best practices in a cloud-native environment.Experience with CI/CD pipelines and integrating security into these workflows using tools like GitHub ActionsProficiency in scripting and automation using languages like Python, Bash, NodeStrong problem-solving skills and the ability to work in a fast-paced, high-growth startup environmentExcellent communication skills, with the ability to explain complex security topics to technical and non-technical stakeholders
Nice to have
Prior experience in healthcare, health tech, or another regulated industry (fintech, insurance).Experience supporting a HIPAA, SOC 2, or HITRUST audit as a technical contributor.Familiarity with healthcare data standards and integration patterns (HL7, FHIR) from a security perspective.Experience with compliance automation or evidence-collection platforms.