Principal Platform Engineer
Summary
Principal Platform Engineer to own and mature AWS infrastructure, CI/CD, and compliance for a healthcare platform serving care teams and residents, using AWS CDK, ECS, and GitHub Actions.
Impruvon builds software and connected hardware that transforms how care teams manage medications for vulnerable populations. Our platform replaces manual, error-prone workflows with real-time, guided systems that improve safety, reduce risk, and simplify compliance across residential care settings.
We support providers across 20+ states, including intellectual and developmental disabilities (IDD) providers, assisted living operators, and behavioral health programs. Our platform includes a full electronic Medication Administration Record (eMAR) and administrative dashboard, smart connected MedBoxes that control and track medication access, emergency kits for urgent situations, and tools that help residents build independence with self-medication. Our solution has been proven to reduce medication errors by approximately 48%, directly impacting the safety of individuals in care facilities.
We are a high-growth, mission-driven startup solving complex, high-impact problems where reliability, usability, and security matter.
About the Role
We support providers across 20+ states, including intellectual and developmental disabilities (IDD) providers, assisted living operators, and behavioral health programs. Our platform includes a full electronic Medication Administration Record (eMAR) and administrative dashboard, smart connected MedBoxes that control and track medication access, emergency kits for urgent situations, and tools that help residents build independence with self-medication. Our solution has been proven to reduce medication errors by approximately 48%, directly impacting the safety of individuals in care facilities.
We are a high-growth, mission-driven startup solving complex, high-impact problems where reliability, usability, and security matter.
About the Role
We are hiring a Principal Platform Engineer to take ownership of our existing platform infrastructure. Today, our engineering leadership manages AWS, DevOps, and compliance. You will be the primary technical lead for this domain. We are looking for someone who can mature our practices, optimize our workflows, and scale our infrastructure. While you will partner with engineering leadership on strategy, you will be the primary authority on technical implementation. We seek a self-starter who thrives when given a high-level outcome and the freedom to define the technical path to get there.
You will own our AWS footprint end-to-end: a multi-account AWS Organizations setup (currently 3 accounts), our Infrastructure-as-Code repo (AWS CDK), CI/CD (GitHub Actions), containerization and orchestration (ECS, considering EKS), and our developer environment tooling (docker compose, devcontainers, mise). You will be responsible for elevating our security and compliance posture - HIPAA, SOC 2 Type II, and likely upcoming work toward StateRAMP or FedRAMP.
Most of this foundation already exists. This is not a "build it from zero" role - it's a "take a working but under-resourced platform and bring it to the next level" role. We are looking for an experienced engineer who can quickly assess our environment, identify opportunities for improvement, and drive solutions with a high degree of agency. If you thrive in high-growth, mission-driven environments and are eager to tackle complex engineering challenges while maintaining a high technical bar, this role is for you.
- Own and evolve our AWS environment across a multi-account AWS Organization structure, including account boundaries, service control policies, cross-account IAM, and cost and security governance.
- Extend and maintain our Infrastructure-as-Code repo (AWS CDK), treating infrastructure changes with the same rigor as application code - reviewed, tested, and versioned.
- Own and improve CI/CD pipelines in GitHub Actions, pushing toward faster, safer, more automated deployments across applications.
- Own our containerization strategy (Docker) and container orchestration platform (currently ECS, potentially moving to EKS) - image standards, base image and dependency security, and day-to-day orchestration operations.
- Maintain and improve our devcontainer setup so engineers get consistent reproducible local development environments.
- Lead the technical work to elevate our compliance and security posture - maintaining and evolving controls for HIPAA and SOC 2 Type II, and leading the technical requirements for StateRAMP/FedRAMP readiness.
- Lead infrastructure-focused security work: secrets management, network security, vulnerability management, and incident response readiness.
- Partner with engineering leadership to evolve our platform strategy and formalize our infrastructure practices as we scale.
- Proactively identify risk in our infrastructure and compliance posture - cost, security, reliability, audit gaps - and drive fixes to completion without being asked.
- Elevate our engineering culture by setting high standards, mentoring other engineers, and simplifying processes to help the team move faster as we scale.
- Prioritize pragmatic simplicity, ensuring we build only what is necessary to validate assumptions and deliver value, while resisting complexity that hinders agility.
- Ensure the reliability and performance of our critical systems by taking ownership of production issues and implementing sustainable fixes.
Requirements
- AWS Infrastructure Ownership: 7+ years of experience owning production AWS infrastructure, including direct, hands-on experience with multi-account AWS Organizations (SCPs, consolidated billing, cross-account IAM).
- Infrastructure as Code: Deep hands-on experience with AWS CDK, or comparable IaC tooling (Terraform, Pulumi) with a demonstrated ability to ramp quickly. You treat infrastructure as software: code review, testing, version control.
- CI/CD: Proven experience designing, operating, and improving CI/CD pipelines; direct experience with GitHub Actions strongly preferred.
- Containerization & Orchestration: Strong production experience with containers and a container orchestration platform (ECS or EKS/Kubernetes).
- Security & Compliance: Direct experience operating infrastructure under HIPAA and/or SOC 2 Type II.
- Autonomy: A track record of owning ambiguous, high-stakes infrastructure and security problems end-to-end with minimal supervision in fast-paced startup environments where requirements evolve. You will be responsible for maturing and evolving our playbook.
- Communication: Excellent written and verbal communication skills. In a remote-first company, your ability to communicate asynchronously and document infrastructure decisions and compliance controls clearly enough for both engineers and auditors to follow is critical.
- Technical Leverage: Demonstrated ability to write tools or infrastructure patterns that amplify the productivity of the rest of the engineering team, rather than just solving problems for yourself.
Nice to Have
- AWS Certified Solutions Architect - Professional
- AWS Certified Security - Specialty
- AWS Certified Generative AI Developer - Professional
- Experience in healthcare, fintech, or another highly regulated industry.
- Experience with StateRAMP or FedRAMP.
- Familiarity with Ruby on Rails, React, and Flutter (useful for cross-team collaboration).
- Experience with IoT or hardware-connected systems.
What Success Looks Like
- First 30 Days: Audit the current infrastructure to identify top technical debt and compliance risks. Ship your first impactful changes to production while establishing strong working relationships with the engineering team.
- First 60 Days: Take primary ownership of our AWS environment. Begin driving our infrastructure roadmap forward by proactively implementing improvements.
- First 90 Days: Operate with full autonomy as the technical authority for the platform. Propose and begin implementing a roadmap for one major initiative (e.g., EKS migration) without needing guidance on implementation details.
At Impruvon, we know our people are our greatest asset. We provide a benefits package designed to support your well-being and growth, including:
- Competitive compensation aligned with experience
- 100% company-paid medical coverage (base plan)
- Dental & vision available
- 401(k) retirement plan
- Company-paid life, AD&D, STD & LTD insurance
- Lifestyle Spending Account (wellness, personal use, and company swag)
- Flexible PTO + company holidays
- Flexible, remote-friendly work environment
- Mission-driven work with real impact on vulnerable populations
Why Join Us
Working at Impruvon means being part of a mission-driven, passionate, and collaborative team. Every role contributes to improving lives and reducing risks in care settings across the country. Your expertise will help ensure we can continue to innovate, grow, and deliver on our promise of safer, smarter care.