Staff DevSecOps Engineer (Health 100)
Core
Leading technical implementation, migration, automation, and standardization of DevSecOps practices across the Health 100 portfolio to strengthen release readiness and enable secure-by-default delivery.
Role type
Staff DevSecOps Security Engineer (IC)
Builds
Scalable engineering solutions for security tooling, CI/CD pipelines, and mobile application security across the Health 100 portfolio.
Domain
Healthcare technology, Cloud Security, DevSecOps
Deliverable
production ML models | product features | infrastructure
Required skills
DevSecOps strategy implementation, CI/CD pipeline security controls, container and Kubernetes security, cloud security (AWS/Azure/GCP), mobile application security testing, vulnerability management, software supply chain security (SBOM), Infrastructure-as-Code, Security-as-Code, scripting/programming (Python/Java/Go/Shell), metrics-driven risk communication.
Preferred skills
Portfolio-based initiative experience, hands-on experience with Snyk/Checkmarx/Gitleaks/SBOM tooling.
Technologies
AWS, Azure, GCP, Docker, Kubernetes, Snyk, Checkmarx, Gitleaks, Python, Java, JavaScript, Go, Shell, PowerShell
Responsibilities
Lead security tool migrations (e.g., Checkmarx to Snyk) and standardize configurations; Design and automate CI/CD security controls and secret detection workflows; Drive remediation of critical vulnerabilities and manage SLA compliance; Engineer controls for public cloud, container, and IaC environments; Assess and remediate mobile application security risks for iOS and Android; Mentor engineers and establish reusable security patterns.
Seniority
Senior, hands-on IC with cross-functional influence