DevSecOps Engineer

Posted Yesterday
Hiring Remotely in United States
Remote
130K-160K Annually
Mid level
Healthtech • Information Technology • Pharmaceutical
The Role
Own cloud security engineering for an AWS-hosted SaaS platform processing sensitive healthcare data. Responsibilities include security monitoring, incident response, vulnerability management, IAM, infrastructure hardening, secure CI/CD integration, compliance support, data protection, audit evidence, and threat detection. The role partners with SRE and Software Engineering to embed security into architecture and development practices, while participating in security on-call rotations and occasional travel.
Summary Generated by Built In
Who We Are

Claritas Rx uses AI and predictive modeling to help rare disease and specialty brands remove the barriers that keep patients from accessing and staying on the treatments they need. By uniting the most complete view of the patient journey with purpose-built technologies, we predict and resolve access challenges before they disrupt care, combining advanced analytics, real-world data, AI, and CRM capabilities to increase start and refill rates, reduce abandonment, and improve brand performance. Our mission is to ensure patients with chronic, life-threatening diseases receive the support that enables the greatest benefit from their therapy. Simply put, our promise is progress for every patient journey.

This is the opportunity to help shape a first-in-industry digital health solution alongside a team of mission-driven professionals. We were named one of Inc.'s Best Workplaces in 2025 and recognized on the Inc. 5000 list for two consecutive years (2025 and 2026), and our team genuinely respects and supports each other. We thrive on being fast-paced, innovative, and results-driven, and our employees enjoy a flexible, collaborative work environment, unlimited PTO, stock options, and a growing set of tools and technology to drive innovation for our customers.

The Position

We are seeking a skilled and hands-on DevSecOps professional to join our Engineering team. Reporting to the Sr. Manager, Site Reliability, you will be a key individual contributor responsible for protecting the confidentiality, integrity, and availability of Claritas Rx's AWS-hosted SaaS platform — a system that processes sensitive patient and commercial data for some of the world's leading biopharmaceutical companies.

In this role, you will own day-to-day security engineering work: hardening infrastructure, managing vulnerability programs, responding to security events, and embedding security practices into the software development lifecycle. You will work closely with Software Engineering, SRE, and external compliance partners to ensure our platform maintains the rigorous compliance posture our customers and regulators require — including HIPAA, SOC 2 Type II, and HITRUST.

This is a high-impact individual contributor role suited to an engineer who thrives at the intersection of security and cloud infrastructure, takes ownership of outcomes, and brings a builder's mindset to security problems. The role is primarily remote with occasional travel requirements.

Key Accountabilities

Security Monitoring & Incident Response

  • Own security monitoring across the platform: tune and triage alerts from AWS GuardDuty, Security Hub, CloudTrail, and related tooling to distinguish signal from noise and surface actionable threats.
  • Serve as a primary responder for security incidents — investigate, contain, and remediate threats; document findings; and drive post-incident reviews with clear corrective actions.
  • Maintain and continuously improve detection capabilities, including log analysis pipelines, alert rules, and correlation logic, to reduce mean time to detect (MTTD) and mean time to respond (MTTR).
  • Participate in on-call rotation for security events, with appropriate escalation paths and runbooks in place.

Cloud Security Engineering

  • Design, implement, and maintain security controls across the AWS environment — including IAM policies, SCPs, KMS key management, VPC security, WAF rulesets, and network segmentation.
  • Conduct regular reviews of cloud configurations using AWS Config, Inspector, Macie, and third-party tooling; remediate findings and track resolution to closure.
  • Partner with the SRE team to ensure infrastructure-as-code (AWS CDK) templates follow security best practices and that security controls are version-controlled, auditable, and reproducible.
  • Evaluate new AWS services and architectural changes for security implications, providing clear guidance to engineering teams before and during adoption.
  • Implement security focused observability patterns to detect threats as they emerge.

Vulnerability Management

  • Support the vulnerability management lifecycle: asset discovery, scanning (infrastructure and application), risk-based prioritization, remediation tracking, and reporting.
  • Coordinate with Software Engineering to integrate SAST, DAST, dependency scanning, and container image scanning into CI/CD pipelines (GitHub Actions), ensuring vulnerabilities are caught early in the SDLC.
  • Track and communicate vulnerability metrics to engineering and leadership, balancing remediation urgency against engineering capacity.
  • Research emerging threats, CVEs, and attacker techniques relevant to our technology stack and cloud environment; translate findings into actionable defensive improvements.

Compliance & Data Protection

  • Support the maintenance and continuous improvement of Claritas Rx's HIPAA, SOC 2 Type II, and HITRUST compliance programs — including evidence collection, control testing, and gap remediation.
  • Ensure PHI handling practices — at rest, in transit, and in processing — meet regulatory requirements; identify and close gaps in data classification, encryption, access control, and audit logging.
  • Maintain and test data protection controls including encryption key management, secrets rotation (via AWS Secrets Manager), and DLP measures.
  • Support external audits and assessments: prepare evidence packages, respond to auditor inquiries, and track audit findings through remediation.
  • Contribute to the development and maintenance of security policies, standards, and procedures.

Identity & Access Management

  • Administer and continuously refine AWS IAM roles, policies, and permission boundaries, applying least-privilege principles across all environments.
  • Manage access lifecycle processes: provisioning, periodic access reviews, and de-provisioning for human and machine identities.
  • Evaluate and improve authentication and authorization controls — including MFA enforcement, SSO integration, and privileged access management.

Cross-Functional Partnership

  • Collaborate with SRE and Software Engineering to embed security requirements into production readiness reviews, architecture decisions, and deployment processes.
  • Serve as a trusted security resource for engineering teams — providing practical, risk-informed guidance rather than purely compliance-driven mandates.
  • Communicate security risks and program status clearly to both technical peers and non-technical stakeholders, including leadership.

Our Stack
  • Cloud: AWS (ECS, EC2, Aurora RDS, DynamoDB, Lambda, S3, SQS, EventBridge, Cognito, Secrets Manager, CloudFront, WAF)
  • Infrastructure as Code: AWS CDK (primary); familiarity with Terraform/OpenTofu a plus
  • CI/CD: GitHub Actions
  • Application Platform: NestJS/TypeScript (backend), React/TypeScript (frontend), PostgreSQL, Turborepo, pnpm
  • Data Platform: AWS Glue, Lake Formation, PySpark, Kinesis (data streaming), Python-based ELT pipelines
  • Observability & Monitoring: CloudWatch (logs, metrics, alarms, dashboards), Sentry, OpenFeature (feature flags), Tableau
  • Languages in Use Across Engineering: TypeScript, Python, SQL; Golang familiarity a plus
  • Work Management: Jira
  • Compliance: HIPAA, SOC 2 Type II, HITRUST
Who You Are

Required Skills:

  • 4+ years of experience in information security engineering, cloud security, or a closely related discipline with hands-on technical ownership.
  • Solid, practical AWS security expertise — you understand IAM, KMS, VPC security, CloudTrail, GuardDuty, Security Hub, Config, and WAF at a working level, not just conceptually.
  • Experience operating a vulnerability management program: scanning, prioritization, tracking, and reporting across infrastructure and application layers.
  • Demonstrated ability to respond to and investigate security incidents in a cloud environment — from initial triage through containment, root cause analysis, and corrective action.
  • Familiarity with integrating security tooling (SAST, DAST, dependency scanning, container scanning) into CI/CD pipelines and developer workflows.
  • Working knowledge of HIPAA, SOC 2, and/or HITRUST requirements as they apply to technical controls — you understand what compliance requires and how to implement it in an engineering context.
  • Scripting proficiency in Python, Bash, or equivalent for automating security tasks, log analysis, and tooling integrations.
  • Strong written and verbal communication skills — you can explain security risk and technical trade-offs clearly to both engineering peers and non-technical stakeholders.
  • Collaborative, team-oriented mindset with the ability to influence security outcomes without direct authority.
  • Comfort operating independently in a fast-paced, high-growth startup environment where priorities shift and initiative is expected.

Preferred Skills:

  • Experience in a healthcare technology or digital health environment with direct exposure to HIPAA-regulated PHI and the controls required to protect it.
  • Hands-on experience with threat modeling methodologies (e.g., STRIDE, PASTA) applied to cloud-native application architectures.
  • Familiarity with penetration testing concepts and experience participating in or coordinating third-party security assessments.
  • Experience with privileged access management (PAM) tooling and secrets management at scale.
  • Exposure to the Claritas Rx application stack: TypeScript, NestJS, PostgreSQL, React.
  • Experience leveraging AI tools (including Claude) to accelerate threat hunting, automate security documentation, or streamline compliance evidence workflows.
  • Relevant certifications such as AWS Security Specialty, CISSP, CISM, CEH, OSCP, CompTIA Security+, or equivalent.
  • B.S. in Computer Science, Information Security, or a related discipline, or equivalent practical experience.
Join Us

We are seeking to add new expertise and perspective to our strong team of experienced professionals.  We aspire to a culture of accelerated professional development through: shared learning and collaboration; a respectful and fun work environment; and employee empowerment through the effective use of technology and tools. 
We are a highly collaborative team and prioritize opportunities to connect in person. For employees within a reasonable driving distance of each other, we host regional town hall gatherings approximately every other month. These sessions give our teams a chance to come together, share updates, and strengthen relationships beyond day-to-day work.

In addition to our great environment, we offer a competitive salary of $130,000 to $160,000 and benefits package and the opportunity to make a significant impact on a first-in-industry digital health solution.  Please send a cover letter along with your resume when applying to the position of interest.  Claritas Rx embraces diversity, equality, and transparency.  We are committed to building a team that comprises a variety of backgrounds, perspectives, and talents.  We believe the more inclusive we are, the better we are.

Join us and discover what it feels like to be part of an environment that rewards ingenuity, risk taking and smart work. It's time to fall in love with what you do!

At Claritas Rx, protecting our candidates is a top priority. If you're applying for a role with us, please note:

•All legitimate opportunities are posted first on ClaritasRx.com. Check there before trusting external listings.

• We believe in meaningful interviews: offers never come after just one phone call or form. Expect multiple video calls to get to know you.

• We never ask for fees or payments of any kind during the hiring process.

• Our People Operations Team will handle your onboarding, and all equipment comes directly from us—no purchases required.

Learn more about how to spot recruitment scams and protect yourself - FBI warning: https://bit.ly/4aDF5wU

Claritas Rx is committed to transparency, integrity, and a safe hiring experience for every candidate. Learn more 

https://www.claritasrx.com/about/careers/

Skills Required

  • 4+ years of experience in information security engineering, cloud security, or a closely related discipline
  • Hands-on AWS security expertise, including IAM, KMS, VPC security, CloudTrail, GuardDuty, Security Hub, Config, and WAF
  • Experience operating a vulnerability management program across infrastructure and application layers
  • Experience responding to and investigating cloud security incidents from triage through remediation
  • Experience integrating SAST, DAST, dependency scanning, and container scanning into CI/CD pipelines
  • Working knowledge of HIPAA, SOC 2, and/or HITRUST technical control requirements
  • Scripting proficiency in Python, Bash, or equivalent
  • Strong written and verbal communication skills
  • Collaborative mindset and ability to influence security outcomes without direct authority
  • Ability to operate independently in a fast-paced startup environment
  • Experience in healthcare technology or digital health with HIPAA-regulated PHI
  • Experience with threat modeling methodologies such as STRIDE or PASTA
  • Familiarity with penetration testing and third-party security assessments
  • Experience with privileged access management and secrets management at scale
  • Exposure to TypeScript, NestJS, PostgreSQL, and React
  • Experience using AI tools such as Claude for threat hunting or compliance workflows
  • Relevant certifications such as AWS Security Specialty, CISSP, CISM, CEH, OSCP, or CompTIA Security+
  • Bachelor's degree in Computer Science, Information Security, or a related discipline, or equivalent practical experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: South San Francisco, CA
62 Employees
Year Founded: 2011

What We Do

Claritas Rx is a digital health venture that brings clarity to the challenges of specialty biopharmaceutical products in the marketplace. In today’s highly complex specialty networks, our mission is to illuminate the patient experience beyond the clinical trial. Claritas Rx leverages a proprietary technology platform and deep manufacturer expertise to automate and integrate channel, commercial, and clinical data and help biopharmaceutical companies generate actionable business insights. Our work uncovers the real-world variables impacting patient access, duration of therapy, and other metrics key to commercial success, making a real impact on patient healthcare.

Similar Jobs

Remote or Hybrid
USA
589 Employees

SailPoint Logo SailPoint

Devsecops Engineer

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
121K-204K Annually
Remote
USA
31 Employees

Tria Federal Logo Tria Federal

Devsecops Engineer

Artificial Intelligence • Information Technology • Machine Learning • Software • Analytics • Consulting • Financial Services
Remote
United States
1372 Employees

Similar Companies Hiring

OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account