Job Purpose
The Senior DevSecOps Engineer will be responsible for building and operating secure, scalable, automated, and cost-efficient cloud environments while embedding security throughout the software and infrastructure delivery lifecycle. The Senior DevSecOps Engineer will collaborate closely with Development and IT teams to establish engineering standards, improve automation, strengthen security controls, and support enterprise workloads across AWS and Azure.
Duties & Responsibilities
- Design, deploy, secure, and manage enterprise cloud infrastructure across AWS and Azure, including compute, networking, storage, identity, containers, and PaaS services
- Develop and maintain Infrastructure-as-Code (IaC) using Terraform to enable standardized, repeatable, and automated cloud deployments
- Design, build, and maintain CI/CD pipelines using GitHub Actions, Azure DevOps, Jenkins, or similar platforms
- Embed security controls into CI/CD pipelines, including SAST, DAST, dependency scanning, secrets detection, container scanning, and Infrastructure-as-Code security scanning
- Implement and maintain AWS and Azure cloud governance, including IAM/RBAC, policies, tagging standards, account/subscription structures, and security guardrails
- Implement cloud security best practices using services such as AWS IAM, Security Hub, GuardDuty, Inspector, KMS, AWS Config, Microsoft Defender for Cloud, Entra ID, Azure Policy, and Key Vault
- Design and support containerized environments using EKS, ECS, ECR, and container security best practices
- Implement centralized monitoring, logging, alerting, and observability using AWS CloudWatch, CloudTrail, Azure Monitor, Log Analytics, Microsoft Sentinel, and related platforms
- Identify and remediate cloud security vulnerabilities, configuration risks, and compliance findings in partnership with Security and Engineering teams
- Support workload migration, modernization, and cloud-native architecture initiatives across AWS and Azure
- Implement cloud cost optimization and FinOps practices, including right-sizing, commitments/reservations, resource lifecycle management, and cost allocation
- Develop automation using Python, PowerShell, Bash, AWS CLI, and Azure CLI
- Troubleshoot complex infrastructure, deployment, security, networking, and application connectivity issues
- Develop and maintain architecture diagrams, technical documentation, runbooks, standards, and operational playbooks
- Mentor engineers and promote DevSecOps, automation, security, and cloud engineering best practices
- Ensure cloud environments align with applicable regulatory and industry standards, including HIPAA, HITRUST, SOC 2, and PCI-DSS
- Other duties as assigned
- Use, protect and disclose patients’ protected health information (PHI) only in accordance with Health Insurance Portability and Accountability Act (HIPAA) standards
- Understand and comply with Information Security and HIPAA policies and procedures at all times
- Limit viewing of PHI to the absolute minimum as necessary to perform assigned duties
Qualifications
- Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field, or equivalent professional experience
- 7+ years of IT/engineering experience, including significant hands-on experience with cloud infrastructure and DevSecOps
- Cloud certifications such as AWS Certified DevOps/SA– Professional, AWS Certified DevOps/SA – Associate, AWS Certified Security – Specialty, Microsoft Azure Associate and/or Expert-level certifications, and/or Terraform Associate Certifications required
- Strong hands-on expertise with AWS and Microsoft Azure
- Strong understanding of AWS services, including EC2, VPC, IAM, S3, RDS, Lambda, ECS/EKS, ECR, CloudWatch, CloudTrail, Route 53, ELB/ALB, and AWS Organizations
- Strong understanding of Azure services, including VMs, VNets, NSGs, Azure Firewall, Application Gateway, Storage, Entra ID, App Services, and Azure Monitor
- Advanced hands-on experience with Terraform and Infrastructure-as-Code (IaC)
- Strong experience designing and managing CI/CD pipelines using GitHub Actions, Azure DevOps, Jenkins, or equivalent technologies
- Hands-on experience integrating security testing and controls into CI/CD pipelines.
- Strong understanding of IAM, RBAC, secrets management, encryption, network security, vulnerability management, and least-privilege principles
- Experience with Docker and container orchestration platforms such as ECS/EKS
- Proficiency with scripting and automation using Python, PowerShell, Bash, AWS CLI, and/or Azure CLI
- Strong understanding of cloud networking, including VPC/VNet, subnets, routing, DNS, VPN, load balancing, firewalls, private connectivity, and hybrid networking
- Experience implementing monitoring, logging, alerting, and security observability solutions
- Experience designing or operating enterprise AWS Organizations and Azure Landing Zones.
- Experience with cloud security posture management (CSPM), vulnerability management, and SIEM platforms.
- Knowledge of FinOps frameworks and cloud financial governance.
- Experience supporting hybrid and multi-cloud architectures.
- Experience working within regulated or security-sensitive environments, preferably with HIPAA, HITRUST, SOC 2, or PCI-DSS requirements.
- Familiarity with Jira, Confluence, ServiceNow, or similar enterprise platforms.
- Proficiency in Microsoft Office Suite
- Strong interpersonal skills, ability to communicate well at all levels of the organization
- Strong problem solving and creative skills and the ability to exercise sound judgment and make decisions based on accurate and timely analyses
- High level of integrity and dependability with a strong sense of urgency and results oriented
- Excellent written and verbal communication skills required
Working Conditions
- May be required to work outside of normal business hours
- Must possess a smart-phone or electronic device capable of downloading applications, for multifactor authentication and security purposes
- Physical Demands: While performing the duties of this job, the employee is occasionally required to move around the work area; Sit; perform manual tasks; operate tools and other office equipment such as computer, computer peripherals and telephones; extend arms; kneel; talk and hear
- Mental Demands: The employee must be able to follow directions, collaborate with others, and handle stress
- Work Environment: The noise level in the work environment is usually minimal
Med-Metrix will not discriminate against any employee or applicant for employment because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, genetic information (including family medical history), political affiliation, military service, veteran status, other non-merit based factors, or any other characteristic protected by federal, state or local law.