AppSec and DevSecOps Lead

Posted 2 Hours Ago
Be an Early Applicant
Waltham, MA, USA
Hybrid
163K-173K Annually
Senior level
Healthtech • Information Technology • Security • Software • Cybersecurity
Empowering secure digital identities for healthcare and beyond.
The Role
Lead application security and DevSecOps strategy across cloud, on-premises, hybrid, and traditional product environments. Embed security controls into software development and CI/CD, establish secure-by-default standards, automate policy and infrastructure security, protect software supply chains, and address application, cloud, identity, API, AI, and endpoint risks. Partner across engineering, product, operations, SecOps, and GRC to prioritize vulnerabilities, support incident response, maintain compliance evidence, and drive measurable security adoption.
Summary Generated by Built In

Ready to join a team that’s all in? At Imprivata, we deliver unified access and security management programs that eliminate friction, empowering healthcare and mission-critical organizations to work smarter, faster, and more securely.

We believe work can be more than a job or task—it’s a collective spirit; the type that emboldens creativity, embraces challenge, and fosters excitement. We are constantly raising the bar on what’s possible, owning the outcome of our triumphs and trials, staying nimble amidst change, and cultivating an environment where we win together. Here, your ideas matter, your differences are celebrated, and your work drives real results—for your career, your teammates, and our customers.

When you join Imprivata, you embark on a shared journey of ambition and growth. We’re committed to building an inclusive workplace where everyone feels valued and supported. If you’re looking for a place to match your passion with purpose—and where every day you can make an impact—you’ll find it here.

We are seeking an AppSec and DevSecOps Lead to join our team. This is a hybrid opportunity based out of our Waltham, MA office.

Job Summary

Imprivata is seeking an AppSec and DevSecOps Lead to operationalize DevSecOps across its product lines, engineering teams, and infrastructure. This role will embed security throughout the software and infrastructure lifecycle—from design and coding through testing, deployment, operations, and retirement.

The successful candidate will support cloud-native and traditional products deployed in customer-managed, on-premises, virtualized, and hybrid environments. The role combines hands-on engineering with organizational leadership to build secure automation, establish practical standards, and make secure delivery repeatable.

The position will support Imprivata’s identity, authentication, access, patient identity, remote support, analytics, and integration solutions across cloud services, endpoints, medical and shared-use devices, APIs, virtual environments, legacy systems, and customer-managed deployments.

Duties and Responsibilities

  • Execute Imprivata’s DevSecOps strategy across products, cloud, data centers, and traditional software, partnering with Engineering, Product, Platform, Quality, DevOps, SecOps, and GRC to drive adoption and clarify ownership. 
  • Establish security-by-design, secure-by-default, policy-as-code, reusable standards, reference architectures, and minimum security requirements. 
  • Embed SAST, DAST, SCA, secrets, container, IaC, API, and license scanning into CI/CD, with measurable, risk-based security gates tailored to products and deployment models. 
  • Secure Git workflows, build systems, runners, identities, repositories, signing systems, credentials, release artifacts, SBOMs, provenance, and other software supply-chain controls. 
  • Apply secure-by-default controls to cloud, networks, identity, platforms, containers, databases, APIs, serverless services, and service communications. 
  • Use infrastructure-as-code, policy-as-code, and automation to address drift, excessive privileges, exposed services, and insecure network paths, while partnering on secrets, encryption, segmentation, logging, monitoring, resilience, testing, and remediation. 
  • Address security for authentication, authorization, privileged access, sessions, tenant isolation, APIs, federation, mobile, endpoints, healthcare data, new services, acquisitions, and major releases. 
  • Secure agentic AI and MCP servers, clients, code, and workflows through threat modeling, least privilege, authentication, authorization, tool validation, secure APIs, prompt-injection protection, data-loss prevention, sandboxing, isolation, monitoring, and human approval. 
  • Operationalize findings from code, dependency, container, cloud, penetration testing, bug reports, and other tools by improving ownership, prioritization, remediation, exceptions, reporting, and monitoring with SecOps. 
  • Support response to compromised credentials, malicious code, exposed secrets, supply-chain attacks, unauthorized deployments, and cloud compromise, including exercises and post-incident reviews. 
  • Support NIST SSDF, NIST CSF, CIS Controls, OWASP, ISO 27001, SOC 2, and healthcare requirements; maintain control evidence; and use metrics, incidents, audits, assessments, and engineering feedback to drive continuous improvement. 
  • Other duties as assigned and required. 

Required Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience. 
  • Seven or more years in DevOps, cloud, software, application, or infrastructure security, including three or more years of hands-on DevSecOps or security engineering experience. 
  • Experience integrating security into CI/CD and development workflows across cloud-native and traditional environments. 
  • Proficiency with AWS, Azure, or Google Cloud; infrastructure as code; containers; Kubernetes; Git; and CI/CD platforms such as GitHub Actions, GitLab, or Jenkins. 
  • Experience with SAST, DAST, SCA, secrets detection, container security, IaC security, vulnerability management, and software supply-chain controls such as SBOMs, SLSA, Sigstore, artifact signing, or provenance. 
  • Strong scripting or programming skills in Python, Go, JavaScript, Java, Bash, or comparable languages. 
  • Working knowledge of IAM, least privilege, authentication, authorization, encryption, certificates, logging, secure network design, and policy-as-code. 
  • Experience securing SaaS, on-premises, hybrid, virtualized, customer-managed, mobile, endpoint, API, microservice, serverless, or service-mesh environments. 
  • Experience securing products in healthcare, financial services, government, or other regulated industries, including identity, privileged-access, authentication, or zero-trust solutions. 
  • Experience integrating security tools with Jira, ServiceNow, GitHub, GitLab, SIEM, CNAPP, vulnerability-management, or GRC platforms. 
  • Familiarity with STRIDE, PASTA, attack trees, or other threat-modeling methods, and relevant certifications such as CISSP, CCSP, CSSLP, AWS, Azure, Google Cloud, or Kubernetes security certifications. 
  • Ability to explain technical risk to technical and nontechnical stakeholders, influence teams, and drive adoption without relying solely on authority. 

This position offers a total compensation range of $163,000.00 to $173,000.00 (inclusive of base salary and variable compensation, such as bonuses and incentives). In addition, more information about Imprivata’s benefit offerings can be found here. This range represents the high and low end of Imprivata’s compensation range for this position. Actual compensation will vary and may be above or below the range based on various factors, such as a candidate’s location, skills, experience, and qualifications.

At Imprivata, we have a top-notch work environment, developmental opportunities, a competitive total rewards package, and the desire to have fun. If you have the skills and qualifications as we have described above, we want to hear from you!

Imprivata provides equal employment opportunities, regardless of race, religion, age, sex, national origin, disability status, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

#LI-Hybrid #LI-ML1

Skills Required

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience
  • Seven or more years of experience in DevOps, cloud, software, application, or infrastructure security
  • Three or more years of hands-on DevSecOps or security engineering experience
  • Experience integrating security into CI/CD and development workflows across cloud-native and traditional environments
  • Proficiency with AWS, Azure, or Google Cloud
  • Experience with infrastructure as code, containers, Kubernetes, Git, and CI/CD platforms such as GitHub Actions, GitLab, or Jenkins
  • Experience with SAST, DAST, SCA, secrets detection, container security, IaC security, vulnerability management, and software supply-chain controls
  • Strong scripting or programming skills in Python, Go, JavaScript, Java, Bash, or comparable languages
  • Working knowledge of IAM, least privilege, authentication, authorization, encryption, certificates, logging, secure network design, and policy-as-code
  • Experience securing SaaS, on-premises, hybrid, virtualized, customer-managed, mobile, endpoint, API, microservice, serverless, or service-mesh environments
  • Experience securing products in healthcare, financial services, government, or other regulated industries
  • Experience integrating security tools with Jira, ServiceNow, GitHub, GitLab, SIEM, CNAPP, vulnerability-management, or GRC platforms
  • Familiarity with STRIDE, PASTA, attack trees, or other threat-modeling methods
  • Relevant certifications such as CISSP, CCSP, CSSLP, AWS, Azure, Google Cloud, or Kubernetes security certifications
  • Ability to explain technical risk to technical and nontechnical stakeholders, influence teams, and drive adoption without relying solely on authority

What the Team is Saying

Chris
Rebecca
Jacob
Kelliann
Luke
Imprivata
Cindy Zhou

Imprivata Compensation & Benefits Highlights

  • Healthcare Strength — Medical coverage includes company funding of half the deductible via HSA/HRA alongside medical, dental, and vision options; feedback suggests healthcare is one of the stronger aspects of the package.
  • Leave & Time Off Breadth — A flexible time-off policy is promoted rather than a fixed vacation bank, and feedback suggests this flexibility supports work-life balance in many teams.
  • Parental & Family Support — Paid parental leave and caregiver resources via Care.com, plus dependent and domestic-partner coverage, indicate a family-oriented set of benefits that goes beyond basic insurance.

Imprivata Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Waltham, MA
1,372 Employees
Year Founded: 2002

What We Do

For more than two decades, Imprivata has been redefining how life- and mission-critical industries secure and manage digital identities. We empower healthcare and enterprise organizations to enable fast, compliant, and secure access to technology—allowing clinicians and staff to stay focused on what matters most: patient care and operational excellence. Our digital identity platform is purpose-built for complex environments where every second counts and security can never take a back seat. From authentication and access management to device, application, and identity governance, Imprivata provides a unified approach that balances usability with protection. Trusted by the world’s leading healthcare systems and enterprises in over 45 countries, we deliver solutions that improve efficiency, safeguard data, and drive digital transformation. At Imprivata, our commitment goes beyond technology—we partner closely with our customers to ensure their success, every step of the way.

Why Work With Us

At Imprivata, every voice matters. We’re a global team driven by innovation, compassion, and collaboration. Together, we live our values—Raise the Bar, Own the Outcome, Stay Nimble, and Win Together—while making a real impact on healthcare, technology, and the communities we serve.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Imprivata Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Imprivata offers a flexible hybrid work model with three in-office days and two remote. Collaboration is key, and schedules are coordinated with managers to balance flexibility and connection.

Typical time on-site: 3 days a week
HQWaltham, MA
Costa Rica
Benelux
Austin, TX
Germany
Australia
St. Petersburg, FL
European Headquarters
Learn more

Similar Jobs

Imprivata Logo Imprivata

Regional Sales Manager

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
1372 Employees
210K-320K Annually

Imprivata Logo Imprivata

Sr. Manager, DevSecOps and Application Security

Healthtech • Information Technology • Security • Software • Cybersecurity
Hybrid
3 Locations
1372 Employees
184K-228K Annually

Imprivata Logo Imprivata

Senior Project Manager

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
1372 Employees
141K-153K Annually

Imprivata Logo Imprivata

Visual Design Intern (20-25 hours per week)

Healthtech • Information Technology • Security • Software • Cybersecurity
Hybrid
Waltham, MA, USA
1372 Employees
24-25 Hourly

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account