Senior DevSecOps Engineer

Job Purpose
The DevSecOps Engineer will work closely with Development and IT teams to build and maintain secure, scalable, reliable, and automated cloud environments across AWS and Azure.

Duties & Responsibilities

Build, deploy, manage, and troubleshoot cloud infrastructure across AWS and Azure
Develop and maintain Infrastructure-as-Code (IaC) using Terraform
Build and maintain CI/CD pipelines using GitHub Actions, Jenkins, or similar platforms
Integrate security into CI/CD pipelines, including vulnerability scanning, secrets detection, dependency scanning, and container/IaC security checks
Manage AWS services including EC2, VPC, IAM, S3, RDS, Lambda, ECS/EKS, ECR, CloudWatch, CloudTrail, Route 53, and load balancers
Support Azure services including VMs, VNets, NSGs, Storage, Entra ID, App Services, Azure Monitor, and related cloud services
Implement and maintain cloud security controls, including IAM/RBAC, least privilege, encryption, secrets management, network security, and security policies
Support containerized applications using Docker, ECS, EKS, and ECR
Monitor cloud environments and troubleshoot infrastructure, networking, deployment, performance, and application connectivity issues
Support cloud security services such as AWS Security Hub, GuardDuty, Inspector, AWS Config, Microsoft Defender for Cloud, and Azure Policy
Automate operational tasks using Python, PowerShell, Bash, AWS CLI, and Azure CLI
Support vulnerability remediation and resolution of cloud security and compliance findings
Maintain technical documentation, deployment procedures, runbooks, and operational standards
Work with development teams to improve deployment automation, reliability, security, and operational efficiency
Support cloud cost optimization and resource right-sizing initiatives
Follow security and compliance requirements, including HIPAA, HITRUST, SOC 2, and PCI-DSS, where applicable
Other duties as assigned
Use, protect and disclose patients’ protected health information (PHI) only in accordance with Health Insurance Portability and Accountability Act (HIPAA) standards

Understand and comply with Information Security and HIPAA policies and procedures at all times
Limit viewing of PHI to the absolute minimum as necessary to perform assigned duties

Qualifications

Bachelor's degree in Computer Science, Information Technology, Engineering, or equivalent professional experience
4+ years of hands-on DevOps, DevSecOps, Cloud Engineering, or Infrastructure Engineering experience
AWS and/or Azure certifications are preferred, including: AWS Certified DevOps/SA Engineer – Associate or Professional, Microsoft Azure Associate or Expert-level certifications and/or Terraform Associate Certifications
Hands-on experience with AWS and Microsoft Azure
Strong working knowledge of core AWS services, including EC2, VPC, IAM, S3, Lambda, ECS/EKS, ECR, CloudWatch, and CloudTrail
Working knowledge of Azure infrastructure, networking, identity, security, and monitoring services
Strong hands-on experience with Terraform and Infrastructure-as-Code (IaC)
Experience building and maintaining CI/CD pipelines using GitHub Actions, Azure DevOps, Jenkins, or equivalent tools
Experience with Docker and container orchestration platforms such as ECS/EKS.
Understanding of DevSecOps practices and experience integrating security controls into deployment pipelines
Strong understanding of IAM/RBAC, secrets management, encryption, vulnerability management, network security, and least-privilege principles
Experience with cloud networking, including VPC/VNet, subnets, routing, DNS, VPN, security groups/NSGs, load balancing, and firewalls
Experience with cloud monitoring, logging, alerting, and troubleshooting
Scripting and automation experience using Python, PowerShell, Bash, AWS CLI, and/or Azure CLI
Ability to troubleshoot cloud infrastructure, deployment, security, and networking issues independently
Proficiency in Microsoft Office Suite

Strong interpersonal skills, ability to communicate well at all levels of the organization
Strong problem solving and creative skills and the ability to exercise sound judgment and make decisions based on accurate and timely analyses
High level of integrity and dependability with a strong sense of urgency and results oriented
Excellent written and verbal communication skills required

Working Conditions

Ability to work outside of normal business hours as needed
Must possess a smart-phone or electronic device capable of downloading applications, for multifactor authentication and security purposes
Physical Demands: While performing the duties of this job, the employee is occasionally required to move around the work area; Sit; perform manual tasks; operate tools and other office equipment such as computer, computer peripherals and telephones; extend arms; kneel; talk and hear
Mental Demands: The employee must be able to follow directions, collaborate with others, and handle stress
Work Environment: The noise level in the work environment is usually minimal

Med-Metrix will not discriminate against any employee or applicant for employment because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, genetic information (including family medical history), political affiliation, military service, veteran status, other non-merit based factors, or any other characteristic protected by federal, state or local law.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available