Rewrite
## About the Role
Most startups burn cash to find a market, at Symmetric, we've spent the last few years winning it. We've been profitable from Year 1, remain employee-owned and doubled in 2025 with line of sight to repeat that growth in 2026.
Our product is the data engine behind the world's most sophisticated healthcare systems — 17 of the Gartner Top 25 supply chains already rely on Symmetric. We provide cutting-edge solutions that streamline procurement, item master data management, and improve efficiency across healthcare systems.
We have a fully remote team that's making a big impact on the healthcare supply chain by working closely with enterprises (health systems, hospitals, consulting firms, etc.), regulatory agencies and industry groups.
## Role Overview
We are seeking a Senior Software Engineer, DevSecOps to own the systems, infrastructure, and practices that keep Symmetric's platform secure, reliable, and easy to ship to. You will oversee our DevOps and security functions — building and maintaining CI/CD pipelines in GitLab, deploying and operating AWS infrastructure for internal and external services, configuring vulnerability and license scanning, and serving as the technical point person for SOC 2 compliance and customer security assessments.
This is a high-impact individual contributor role for someone who enjoys working at the intersection of engineering, operations, and security — reducing toil for the rest of the engineering team, hardening the platform our customers depend on, and building durable controls that scale with the business.
## Key Responsibilities
### CI/CD & Developer Experience
- Build and maintain GitLab CI/CD pipelines that deliver fast, reliable, and secure build, test, and deploy workflows across our services.
- Improve developer experience by reducing pipeline friction, shortening feedback loops, and automating the repetitive work that slows engineers down.
- Establish patterns and reusable components so new services get secure, production-ready pipelines by default.
### Infrastructure & Cloud Operations
- Deploy, operate, and evolve AWS infrastructure for both internal tooling and customer-facing services.
- Own infrastructure-as-code (Terraform, CloudFormation, CDK, or similar) so environments are reproducible, reviewable, and auditable.
- Drive reliability through monitoring, alerting, incident response, and capacity planning — partnering with engineering teams to keep services healthy.
- Manage cost, performance, and scalability trade-offs as our customer base and data volumes grow.
### Security & Vulnerability Management
- Configure and operate vulnerability scanning and software license scanning across our code, containers, and dependencies.
- Triage findings, drive remediation with engineering teams, and build guardrails that prevent classes of issues from recurring.
- Harden our AWS footprint, secrets management, identity, and access patterns — baking security into how we build and deploy.
### Compliance & Customer Assurance
- Serve as the technical point person for SOC 2 compliance — owning evidence collection, control implementation, and audit readiness in partnership with leadership and external auditors.
- Lead responses to customer security assessments, questionnaires, and due diligence requests from enterprise healthcare customers.
- Translate compliance requirements into practical engineering controls, documentation, and automated checks rather than one-off manual work.
### Collaboration & Leadership
- Partner with Engineering, Product, Implementation, and Customer Success to align DevSecOps investments with product roadmap and customer commitments.
- Mentor engineers on secure development, operational excellence, and infrastructure best practices.
- Provide independent code review for infrastructure and security changes, ensuring no critical system changes ship without peer review. Participate in architectural discussions and technical planning sessions.
## Qualifications
### Required
- 5+ years of experience as a software, DevOps, SRE, or security engineer, with meaningful time spent owning CI/CD, cloud infrastructure, and production operations.
- Hands-on experience building and maintaining CI/CD pipelines (GitLab CI strongly preferred; GitHub Actions, Jenkins, CircleCI, or similar also considered).
- Strong AWS experience — deploying and operating services across common building blocks (VPC, IAM, ECS/EKS, Lambda, RDS, S3, CloudWatch).
- Proficiency with infrastructure-as-code (Terraform, CloudFormation, CDK, or similar) and modern configuration management practices.
- Strong scripting and automation skills (Python, Bash, or similar) for glue code, tooling, and operational automation.
- Working knowledge of application and cloud security fundamentals — vulnerability management, secrets handling, identity, network controls, and secure SDLC.
- Strong communication skills with the ability to collaborate effectively across technical and non-technical teams, including customers and auditors.
### Preferred
- Direct experience supporting a SOC 2 audit — evidence gathering, control design, and working with external auditors.
- Experience responding to enterprise customer security assessments and questionnaires.
- Experience configuring vulnerability and license scanning tooling (GitLab security scanners, Snyk, Trivy, Dependabot, SonarQube, or similar).
- Experience with containerization (Docker) and orchestration (ECS, EKS, or Kubernetes).
- Experience with observability tooling (CloudWatch, Datadog, Grafana, Prometheus, or similar).
- Experience in healthcare IT, regulated environments (HIPAA, HITRUST), or enterprise SaaS.
- Bachelor's degree in Computer Science, Engineering, or a related technical field.
## What Success Looks Like
- 30 days: Solid understanding of our CI/CD pipelines, AWS footprint, security tooling, and current SOC 2 posture; built relationships with cross-functional partners in Engineer
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.