Senior DevSecOps Engineer

Job PurposeThe Senior DevSecOps Engineer will be responsible for building and operating secure, scalable, automated, and cost-efficient cloud environments while embedding security throughout the software and infrastructure delivery lifecycle. The Senior DevSecOps Engineer will collaborate closely with Development and IT teams to establish engineering standards, improve automation, strengthen security controls, and support enterprise workloads across AWS and Azure.

Duties & Responsibilities

Design, deploy, secure, and manage enterprise cloud infrastructure across AWS and Azure, including compute, networking, storage, identity, containers, and PaaS services
Develop and maintain Infrastructure-as-Code (IaC) using Terraform to enable standardized, repeatable, and automated cloud deployments
Design, build, and maintain CI/CD pipelines using GitHub Actions, Azure DevOps, Jenkins, or similar platforms
Embed security controls into CI/CD pipelines, including SAST, DAST, dependency scanning, secrets detection, container scanning, and Infrastructure-as-Code security scanning
Implement and maintain AWS and Azure cloud governance, including IAM/RBAC, policies, tagging standards, account/subscription structures, and security guardrails
Implement cloud security best practices using services such as AWS IAM, Security Hub, GuardDuty, Inspector, KMS, AWS Config, Microsoft Defender for Cloud, Entra ID, Azure Policy, and Key Vault
Design and support containerized environments using EKS, ECS, ECR, and container security best practices
Implement centralized monitoring, logging, alerting, and observability using AWS CloudWatch, CloudTrail, Azure Monitor, Log Analytics, Microsoft Sentinel, and related platforms
Identify and remediate cloud security vulnerabilities, configuration risks, and compliance findings in partnership with Security and Engineering teams
Support workload migration, modernization, and cloud-native architecture initiatives across AWS and Azure
Implement cloud cost optimization and FinOps practices, including right-sizing, commitments/reservations, resource lifecycle management, and cost allocation
Develop automation using Python, PowerShell, Bash, AWS CLI, and Azure CLI
Troubleshoot complex infrastructure, deployment, security, networking, and application connectivity issues
Develop and maintain architecture diagrams, technical documentation, runbooks, standards, and operational playbooks
Mentor engineers and promote DevSecOps, automation, security, and cloud engineering best practices
Ensure cloud environments align with applicable regulatory and industry standards, including HIPAA, HITRUST, SOC 2, and PCI-DSS
Other duties as assigned
Use, protect and disclose patients’ protected health information (PHI) only in accordance with Health Insurance Portability and Accountability Act (HIPAA) standards
Understand and comply with Information Security and HIPAA policies and procedures at all times
Limit viewing of PHI to the absolute minimum as necessary to perform assigned duties

Qualifications

Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field, or equivalent professional experience
7+ years of IT/engineering experience, including significant hands-on experience with cloud infrastructure and DevSecOps
Cloud certifications such as AWS Certified DevOps/SA– Professional, AWS Certified DevOps/SA – Associate, AWS Certified Security – Specialty, Microsoft Azure Associate and/or Expert-level certifications, and/or Terraform Associate Certifications required
Strong hands-on expertise with AWS and Microsoft Azure
Strong understanding of AWS services, including EC2, VPC, IAM, S3, RDS, Lambda, ECS/EKS, ECR, CloudWatch, CloudTrail, Route 53, ELB/ALB, and AWS Organizations
Strong understanding of Azure services, including VMs, VNets, NSGs, Azure Firewall, Application Gateway, Storage, Entra ID, App Services, and Azure Monitor
Advanced hands-on experience with Terraform and Infrastructure-as-Code (IaC)
Strong experience designing and managing CI/CD pipelines using GitHub Actions, Azure DevOps, Jenkins, or equivalent technologies
Hands-on experience integrating security testing and controls into CI/CD pipelines.
Strong understanding of IAM, RBAC, secrets management, encryption, network security, vulnerability management, and least-privilege principles
Experience with Docker and container orchestration platforms such as ECS/EKS
Proficiency with scripting and automation using Python, PowerShell, Bash, AWS CLI, and/or Azure CLI
Strong understanding of cloud networking, including VPC/VNet, subnets, routing, DNS, VPN, load balancing, firewalls, private connectivity, and hybrid networking
Experience implementing monitoring, logging, alerting, and security observability solutions
Experience designing or operating enterprise AWS Organizations and Azure Landing Zones.
Experience with cloud security posture management (CSPM), vulnerability management, and SIEM platforms.
Knowledge of FinOps frameworks and cloud financial governance.
Experience supporting hybrid and multi-cloud architectures.
Experience working within regulated or security-sensitive environments, preferably with HIPAA, HITRUST, SOC 2, or PCI-DSS requirements.
Familiarity with Jira, Confluence, ServiceNow, or similar enterprise platforms.
Proficiency in Microsoft Office Suite
Strong interpersonal skills, ability to communicate well at all levels of the organization
Strong problem solving and creative skills and the ability to exercise sound judgment and make decisions based on accurate and timely analyses
High level of integrity and dependability with a strong sense of urgency and results oriented
Excellent written and verbal communication skills required

Working Conditions

May be required to work outside of normal business hours
Must possess a smart-phone or electronic device capable of downloading applications, for multifactor authentication and security purposes
Physical Demands: While performing the duties of this job, the employee is occasionally required to move around the work area; Sit; perform manual tasks; operate tools and other office equipment such as computer, computer peripherals and telephones; extend arms; kneel; talk and hear
Mental Demands: The employee must be able to follow directions, collaborate with others, and handle stress
Work Environment: The noise level in the work environment is usually minimal

Med-Metrix will not discriminate against any employee or applicant for employment because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, genetic information (including family medical history), political affiliation, military service, veteran status, other non-merit based factors, or any other characteristic protected by federal, state or local law.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available