Job Closed
This listing is no longer active.
OpenLoop Health is a healthcare technology startup whose services are used by companies that provide telehealth delivery across all 50 states. In past hiring, t
Staff Security Engineer – DevOps Integrations
Location
United States
Posted
82 days ago
Salary
0
Seniority
Lead
Job Description
Staff Security Engineer – DevOps Integrations
OpenLoop Health
• Build relationships with developers and stakeholders to incorporate security principles into engineering design and deployments. • Supervise validation in security controls and testing across projects, using SAST, DAST, IAST and RASP tools, documenting any security findings, outlining remediation options and overseeing mitigation. • Oversee implementation of defensive practices and countermeasures across infrastructure and applications. • Draft and uphold CI/CD security strategy and practices in tandem with other technical team leads. • Lead continuous product and application security reviews, focused on secure development practices, threat modeling, vulnerability management, architecture and application security design. • Ensure security principles and validations are consistently implemented throughout the CI/CD pipeline by embedding robust, security-focused practices into all automation processes. • Attend and participate in product meetings addressing security requirements for new and existing products. • Build services and tools to enable developers and engineers to use security components successfully. • Simplify automation that applies security inter-workings with CI/CD pipelines. • Support the ability to “shift left” and incorporate security early on and throughout the development lifecycle. • Communicate vulnerability results to both technical and non-technical stakeholders, focused on risk tolerance and threat to the business, in order to gain support through influential messaging. • Leverage vulnerability database sources to understand the weakness, probability and remediation options supplied by vendors. • Join forces and provision security principles in architecture, infrastructure and code. • Regularly research and learn new tactics, techniques and procedures (TTPs). • Partner with teams to define key performance indicators (KPIs) and metrics across business units. • Ensure regulatory compliance (e.g., PCI, HIPAA, HITRUST, NIST CSF) through effective security controls and processes. • Other duties as assigned.
Job Requirements
- Bachelor's degree in computer science (preferred), information assurance, MIS or related field, or equivalent.
- 7+ years of security and systems administration-related experience, to include 3+ years of related cloud and security engineering experience
- Experience with operations and security across Amazon Web Services (AWS) and/or Google Cloud Platform (GCP).
- Experience with agile workflows, including Scrum and Kanban.
- Understanding of containers (e.g., Docker) and container orchestration (e.g., Docker Swarm, Kubernetes).
- Proficient in securing Windows and *nix operating systems, endpoint applications, networking protocols and devices.
- Understanding of OWASP, CVSS, the MITRE ATT&CK framework and (SLDC).
- Knowledge of Payment Card Industry (PCI), Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), National Institute of Standards (NIST) or International Standards Organization (ISO) requirements.
- Experience in healthcare or digital health is a plus.
Benefits
- Health insurance
- Flexible work arrangements
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
• Build and maintain CI/CD pipelines • Automate deployments and infrastructure (e.g., Terraform, Ansible) • Operate and monitor containerized applications (Docker, Kubernetes) • Provide technical support and assistance to customers • Ensure stability, security, and scalability
• Design and architect scalable, high-performance applications using the Meanstack framework. • Implement DevOps practices for continuous integration and continuous deployment (CI/CD). • Collaborate with cross-functional teams to define, design, and ship new features. • Provide technical leadership and mentoring to development teams. • Ensure the architectural integrity and quality of applications throughout the development lifecycle. • Conduct code reviews and ensure adherence to best practices in coding standards and practices. • Identify, troubleshoot, and resolve application performance issues. • Stay up-to-date with emerging technologies and industry trends to enhance architectural practices.
Senior Site Reliability Engineer
MLabs LTDFounded in 2018, MLabs is a private software engineering consultancy specializing in Haskell and Rust development with a focus on blockchain, artificial intelli
Role Description We are hiring on behalf of our client, a high-growth software company supporting the development of a premier open-source, EVM-compatible public ledger built for global enterprise and Web3 use cases. They are currently hiring a Senior Site Reliability Engineer for their "greenfield" enterprise-focused team. This team is building a private and consortium distributed ledger platform designed specifically for sectors with high security and privacy requirements, such as financial services, healthcare, and supply chain. This is a hands-on, high-impact role where you will own the design, deployment, and reliability of mission-critical, multi-region infrastructure. This is not a traditional support role; they are looking for an engineer who has operated real systems at scale and is eager to take end-to-end ownership of architecture and operational standards from the ground up. Key Responsibilities - Systems Architecture: Design and operate highly available, multi-region distributed systems with rigorous recovery strategies (RTO/RPO). - Infrastructure as Code: Own large-scale IaC using Terraform, developing reusable modules and multi-account patterns with policy guardrails. - Kubernetes Orchestration: Scale production environments (EKS, GKE, or AKS) utilizing GitOps (ArgoCD), Helm, and strict network policies. - CI/CD Leadership: Build secure pipelines supporting blue/green and canary deployments, artifact signing (SBOM), and automated rollback strategies. - SRE Advocacy: Define and improve SLOs, error budgets, and observability metrics to drive measurable reductions in MTTR. - Collaboration: Partner with the Head of SRE and VP of Engineering to translate complex business requirements into reliable, secure platform services. Qualifications - 7+ years of experience in SRE, Platform Engineering, or Infrastructure Engineering operating production distributed systems. - Multi-Cloud Mastery: Deep expertise in AWS or GCP, with experience running multi-region production environments and disaster recovery testing. - Containerization: Hands-on experience with Kubernetes at scale, including GitOps workflows and production-grade security controls. - Security Mindset: Strong background in Zero Trust principles, secrets management (Vault), and compliance frameworks (SOC 2, HIPAA, or NIST). - Tooling: Extensive experience with Terraform-first infrastructure in large-scale, real-world environments. Nice to Have - Experience with distributed ledger technology (DLT) or blockchain systems, particularly private/consortium deployments. - Familiarity with EVM-based systems and smart contract tooling (Solidity, Hardhat). - Experience operating active-active, globally distributed architectures. - Background in supporting financial services or other highly regulated industries. Benefits - Competitive base salary with Performance Bonuses. - Equity and Token participation. - 401k and comprehensive health insurance (for US-based employees). - The opportunity to build a "greenfield" platform from scratch within a stable, venture-backed organization. - Work on infrastructure that powers the world’s leading organizations across multiple sectors.
Senior Site Reliability Engineer
MLabs LTDFounded in 2018, MLabs is a private software engineering consultancy specializing in Haskell and Rust development with a focus on blockchain, artificial intelli
Senior Site Reliability Engineer (Enterprise Platform) Location: Remote - US - Open to Europe if happy to overlap with EST Compensation: Competitive We are hiring on behalf of our client, a high-growth software company supporting the development of a premier open-source, EVM-compatible public ledger built for global enterprise and Web3 use cases. They are currently hiring a Senior Site Reliability Engineer for their "greenfield" enterprise-focused team. This team is building a private and consortium distributed ledger platform designed specifically for sectors with high security and privacy requirements, such as financial services, healthcare, and supply chain. This is a hands-on, high-impact role where you will own the design, deployment, and reliability of mission-critical, multi-region infrastructure. This is not a traditional support role; they are looking for an engineer who has operated real systems at scale and is eager to take end-to-end ownership of architecture and operational standards from the ground up. Key Responsibilities: - Systems Architecture: Design and operate highly available, multi-region distributed systems with rigorous recovery strategies (RTO/RPO). - Infrastructure as Code: Own large-scale IaC using Terraform, developing reusable modules and multi-account patterns with policy guardrails. - Kubernetes Orchestration: Scale production environments (EKS, GKE, or AKS) utilizing GitOps (ArgoCD), Helm, and strict network policies. - CI/CD Leadership: Build secure pipelines supporting blue/green and canary deployments, artifact signing (SBOM), and automated rollback strategies. - SRE Advocacy: Define and improve SLOs, error budgets, and observability metrics to drive measurable reductions in MTTR. - Collaboration: Partner with the Head of SRE and VP of Engineering to translate complex business requirements into reliable, secure platform services.


