Responsibilities:
- Own the security posture of Vida’s cloud infrastructure, implementing best practices for regulated environments (HIPAA, HITRUST).
- Manage and enhance infrastructure-as-code (Terraform) for GCP, ensuring configurations adhere to least privilege and zero trust principles.
- Implement and maintain monitoring, logging and alerting frameworks across production systems using tools like Datadog, Prometheus and GCP Cloud Logging.
- Oversee vulnerability management, including patching, dependency scanning and automated remediation workflows.
- Partner with engineering teams to embed security controls within CI/CD pipelines (GitHub Actions or similar), aligning with secure software development lifecycle (SSDLC) practices.
- Conduct threat modeling and risk assessments for new services and architecture changes.
- Manage and optimize container security in Kubernetes (GKE), including image scanning, runtime protection and secrets management.
- Collaborate with compliance teams on audit evidence automation and support for security certifications (HITRUST, SOC 2, etc.).
- Lead incident response and postmortem analysis for security-related events.
- Mentor Engineers on secure development and deployment practices, fostering a culture of security by design.
Qualifications:
- Bachelor’s Degree in Computer Science, Engineering or related field- or equivalent practical experience.
- 6+ years of experience in DevOps, Cloud Infrastructure or Security Engineering roles, including production support.
- Strong hands-on expertise with GCP is required; familiarity with other clouds is additive,
- Deep experience managing infrastructure via Terraform or similar IaC tools.
- Demonstrated knowledge of container orchestration and Kubernetes security best practices.
- Experience securing CI/CD pipelines using tools like GitHub Actions, Jenkins or GitLab CI.
- Strong familiarity with application and dependency scanning tools (e.g., Snyk, Trivy, Dependabot).
- Proficiency in Python, Go or Bash scripting for automation and tooling.
- Experience implementing Zero Trust, network segmentation and service identity-based access controls.
- Hands-on knowledge of monitoring and observability platforms (e.g., Datadog, Prometheus, Grafana).Understanding of security compliance frameworks (HIPAA, HITRUST, NIST 800-53).
Preferred:
- Experience in GCP-native security services (Cloud Armor, SCC, IAM Analyzer, Cloud KMS).
- Familiarity with automated compliance and policy-as-code (e.g., OPA, Conftest, Checkov)
- .Exposure to incident detection and response tools, including Cloud IDS and SIEM platforms.
- Background in healthcare or other regulated data environments.
Top Skills
What We Do
Vida is a virtual care company that combines a human-centric approach with technology to address chronic and co-occurring physical and behavioral health conditions. We provide personalized chronic condition management combined with health coaching and therapy through a mobile and online platform that supports individuals in managing and significantly improving conditions such as diabetes, hypertension, obesity, depression, anxiety, etc. Our platform integrates deeply individual expert care with machine learning and remote monitoring to deliver lasting behavior change, health outcomes and cost savings. Vida is in the business of enabling self-insured employers, health plans and providers to take better care of their employees and members. We are trusted by Fortune 1000 companies, major national payers, and large providers to activate, engage, and empower their employees to live their healthiest lives. Based in San Francisco, CA, Vida is backed by investors including Khosla Ventures, StartX, Aspect Ventures, Canvas, Workday, and Nokia.









