Job Closed

This listing is no longer active.

Zenara Health logo
Zenara Health

The digital platform that brings together clients, referring clinicians, and health/fitness providers

DevOps & Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 1-10Since 2023H1B No SponsorCompany SiteLinkedIn

Location

India

Posted

95 days ago

Salary

₹2,200K - ₹3,500K / year

Seniority

Mid Level

Job Description

DevOps & Security Engineer

Zenara Health

Role Description This position serves as the company's foremost line of defense. You will operate under the assumption that systems are constantly under threat, crafting infrastructure that is resilient, auditable, and inherently secure. You will be the most risk-aware individual in the startup — and that’s exactly what we require. While others concentrate on feature rollout, you will prioritize the security of patient data, regulatory compliance, and system integrity. If your understanding of DevOps is limited to "I occasionally execute kubectl apply," this position is likely not for you. This role is not suited for those who prioritize speed over safety or view security as an afterthought to be addressed later. At Zenara, safeguarding patient data and maintaining system integrity takes precedence over rapid deployment. You will be responsible for Zenara’s infrastructure, security posture, and compliance engineering — everything from the ground up. This includes: - CI/CD pipelines - HIPAA-compliant deployment automation - Monitoring and alerting systems - Cybersecurity measures and threat defense - Access controls - Audit logging Your role will go beyond mere maintenance. You will also develop infrastructure for our AI platform, encompassing model serving, scaling AI workloads, and supporting production AI pipelines. You will have a dual mandate: ensure the stability and security of the platform while also building the necessary infrastructure for AI at scale. This represents a unique opportunity for greenfield infrastructure engineering within a healthcare AI company with genuine compliance obligations and real users. You will devise systems from fundamental principles, make architectural choices, establish best practices to guide us through growth and compliance audits, and serve as the ultimate security gatekeeper. What You Will Own - Cybersecurity & Threat Defense: Manage threat modeling, reduce attack surfaces, oversee intrusion detection, handle vulnerability management, and plan incident responses. You will be the final reviewer for infrastructure and security risks. - CI/CD and Deployment Automation: Design and implement CI/CD pipelines for all Zenara products, establishing deployment automation, managing environments, and setting quality thresholds. - Security Posture and HIPAA Compliance: Develop and uphold a HIPAA-compliant security posture across all Zenara systems, implementing access controls, managing secrets, maintaining audit logs, and enforcing encryption standards. - Monitoring, Alerting, and Incident Response: Create monitoring and alerting capabilities to proactively identify issues, establish incident response protocols, and lead the on-call rotation. - AI Infrastructure Support: Address AI infrastructure needs, including model serving and autoscaling for AI workloads. - Cloud Infrastructure Management: Oversee cloud infrastructure (AWS/Azure), focusing on cost optimization, reliability, disaster recovery, and capacity planning. - SOC 2 Readiness: Spearhead SOC 2 Type II preparedness, implementing necessary controls and liaising with auditors. - Security Incident Response: Establish procedures, conduct regular security evaluations, and respond to incidents as they arise. Your First 90 Days - Week 1-2: Fully immerse yourself in the current infrastructure, deployment processes, and security posture. Identify significant security vulnerabilities and critical gaps. - Month 1: Set up basic monitoring and alerting systems. Outline the CI/CD roadmap and begin documenting existing systems and security protocols. - Month 2-3: Develop CI/CD pipelines for high-priority services with security gates and implement secrets management and access controls. - Ongoing: Take on full ownership of infrastructure and security, delivering reliable and secure systems. Qualifications - 5-10 years of experience in DevOps, SRE, or Platform Engineering. - A strong security mindset: detail-focused and able to express concerns when risks are too high. - Familiarity with HIPAA, SOC 2, or healthcare compliance frameworks. - Proficient in AWS or Azure with infrastructure-as-code (Terraform, Pulumi, or CloudFormation). - CI/CD pipeline design and implementation experience. - Experience in container orchestration (Kubernetes, ECS, or equivalent). - Skills in cybersecurity: threat modeling, vulnerability assessment, intrusion detection, and incident response. - Strong English communication skills. - Experience in startup or high-growth environments. Strongly Preferred - Experience in supporting ML/AI infrastructure. - Security expertise in healthcare SaaS. - Background in penetration testing or security audits. - Prior experience with SOC 2 or HITRUST certification processes. - Knowledge of observability and monitoring tools. Nice to Have - Understanding of FHIR/HL7 healthcare data standards. - Production experience with Kubernetes. - Acquainted with multi-tenant SaaS security strategies. - Exposure to mental health or behavioral health sectors. - Experience with cloud infrastructure cost optimization. - Relevant security certifications (CISSP, CEH, or equivalent). Schedule - Evening IST hours with 4–8 hours of daily overlap with US Pacific (9am–5pm PT). - Salary between ₹22–35 LPA, based on skills and responsibilities. - Fully remote work options available throughout India. - Provision for equipment allowance. - Acknowledgment of culturally significant local holidays (India). - Flexible paid leave options. - Direct and regular communication with the CEO. - Opportunity to build infrastructure and security practices from the ground up.

Job Requirements

  • 5-10 years of experience in DevOps, SRE, or Platform Engineering.
  • A strong security mindset: detail-focused and able to express concerns when risks are too high.
  • Familiarity with HIPAA, SOC 2, or healthcare compliance frameworks.
  • Proficient in AWS or Azure with infrastructure-as-code (Terraform, Pulumi, or CloudFormation).
  • CI/CD pipeline design and implementation experience.
  • Experience in container orchestration (Kubernetes, ECS, or equivalent).
  • Skills in cybersecurity: threat modeling, vulnerability assessment, intrusion detection, and incident response.
  • Strong English communication skills.
  • Experience in startup or high-growth environments.
  • Strongly Preferred
  • Experience in supporting ML/AI infrastructure.
  • Security expertise in healthcare SaaS.
  • Background in penetration testing or security audits.
  • Prior experience with SOC 2 or HITRUST certification processes.
  • Knowledge of observability and monitoring tools.
  • Nice to Have
  • Understanding of FHIR/HL7 healthcare data standards.
  • Production experience with Kubernetes.
  • Acquainted with multi-tenant SaaS security strategies.
  • Exposure to mental health or behavioral health sectors.
  • Experience with cloud infrastructure cost optimization.
  • Relevant security certifications (CISSP, CEH, or equivalent).
  • Schedule
  • Evening IST hours with 4–8 hours of daily overlap with US Pacific (9am–5pm PT).
  • Salary between ₹22–35 LPA, based on skills and responsibilities.
  • Fully remote work options available throughout India.
  • Provision for equipment allowance.
  • Acknowledgment of culturally significant local holidays (India).
  • Flexible paid leave options.
  • Direct and regular communication with the CEO.
  • Opportunity to build infrastructure and security practices from the ground up.

Related Categories

Related Job Pages

More Security Engineer Jobs

Zelh logo

In Transit Security Specialist

Zelh

Simplifying Staffing Solutions #IT #Outsourcing #Consulting

Full TimeRemoteTeam 201-500Since 2017H1B No Sponsor

• Protects the integrity of cargo being shipped by rigorously applying DeSpir’s in Transit Security Processes* • Proactively creates solutions to process breakdowns as they occur while communicating updates to the customer* • Communicates and coordinates within all business units to ensure the integrity of shipments • Carries out all necessary data entry and confirmation of key milestones of the In Transit Security process. (Departure, arrival, PODs, etc.) while utilizing Mcleod and other systems • Monitors In Transit Security through multiple systems to ensure quick response to customer requests • Assures that all paperwork including, but not limited to temperature downloads, pictures, and POD are downloaded to the load documents and the customer to finish the load for billing* • Risk management with an extensive focus on security best practices and protocols • Handling escalations of suspicious activity regarding customer freight • Responsible for updating customer portals based on customer requirements

Serbia
Job Closed
Semrush logo

Enterprise Security Engineer – Enterprise Security Team

Semrush

Your competitors' favorite marketing platform used by 10,000,000 marketers

Full TimeRemoteTeam 1,001-5,000Since 2008H1B Sponsor

• Develop and maintain internal security policies and guidelines, including policies related to data protection, BYOD, and network security. • Keep security documentation up to date and ensure it reflects current processes and controls. • Monitor security-related processes across the company and help ensure that security practices are followed in daily operations. • Apply security best practices in day-to-day work and support teams in implementing secure configurations and solutions. • Participate in improving security processes both within the team and across other departments. • Approve and manage access to internal information systems in accordance with established security policies. • Provide guidance to colleagues on security-related topics and the secure use of internal systems. • Work closely with the IT Support team on security-related matters, helping identify more secure solutions and advising on system configurations.

Poland
Job Closed
OtherRemoteTeam 201-500

The Information Security Governance, Risk, and Compliance (GRC) Manager provides tactical leadership and operational oversight for key components of the company’s enterprise GRC program. This role is responsible for the day-to-day management of GRC analysts, driving compliance initiatives, managing the integrated risk assessment lifecycle, and ensuring control effectiveness. The Manager will serve as a key point of contact for internal business units and external auditors, directly supporting the strategic directives set by program leadership. The position requires a proven ability to lead teams, implement policy, and translate complex security and compliance requirements into clear business actions. What You Will Work On - Manage and mentor a team of GRC Security Analysts, providing clear direction and facilitating continuous professional development. - Oversee and execute the security risk assessment process, including identifying, analyzing, and documenting emerging and ongoing risks across the organization and its third parties. - Lead efforts to document, enforce, and communicate security policies and control frameworks that are aligned with key regulations and standards (e.g., NIST, ISO, GDPR, GLBA). - Develop, implement, and maintain security policies and controls specifically for the safe and ethical deployment and use of artificial intelligence (AI) systems. - Act as the primary operational liaison for internal and external audits, coordinating the collection of evidence, tracking the resolution of findings, and ensuring sustained audit readiness. - Provide direct support to the third-party risk management program, ensuring rigorous security review of vendors and business partners to mitigate external risk. - Facilitate IT compliance activities, focusing on the operational effectiveness of technical and general IT controls. - Collaborate with business units and technical teams to ensure adequate security controls are available and implemented during the onboarding of new solutions and systems. - Define and track qualitative and quantitative metrics to measure the success and maturity of the security program, reporting regularly to program leadership. - Support incident response and disaster recovery efforts, ensuring GRC documentation and controls are properly applied to corporate resiliency programs. - Ensure the protection of critical data is maintained through established data classification, data loss prevention (DLP), and records retention requirements. - Manage information security training requirements for the organization, to include identifying role-based security training for all organizational roles in accordance with the roles capacity to introduce risk in the performance of their duties. Who We Are Looking For - 7+ years of experience in cybersecurity, with a focus on governance, compliance, risk management, or audit. - 3+ years of demonstrated experience managing or leading a distributed or hybrid team. - Expert-level understanding of major regulatory frameworks and standards, including but not limited to NIST, ISO, GDPR, and GLBA. - Proven ability to manage GRC-related projects and work with cross-functional stakeholders to deliver outcomes on time and within scope. - Strong technical acumen in cloud computing security (AWS, GCP, or Azure), DevOps, and application security. - Exceptional written and verbal communication skills, with the ability to articulate security risk and compliance requirements to technical staff and business leadership. - Prior experience in defining metrics, preparing management reports, and implementing process improvements using GRC tools. - Demonstrated experience in conducting tabletop exercises for business continuity is preferable. Education Requirements - Bachelor’s degree in computer science, information assurance, MIS, or a related technical field, or equivalent practical experience. Certification Requirements - Holds or is actively working toward one or more of the following: CISSP, CISM, CISA, CRISC, or CGRC. What You Can Expect - Compensation: The base salary for this position ranges from $150,000 to $200,000 annually, depending on your location, experience, and qualifications. Additional compensation offerings include company profit-sharing bonus program, communication stipends, and referral bonuses. - Inclusive benefits package offering: - Comprehensive medical, dental, and company paid vision insurance, 401(k) retirement plan with employer match, voluntary life and AD&D insurance options, voluntary supplemental insurances for accident, critical illness, and legal services, paid time off (PTO) and paid holidays, employee assistance and wellness programs, company paid short term disability coverage, company contributions to health saving funds (with participation in the high deductible health plan. We offer company paid access to Galileo for virtual primary care and Rula for virtual mental health resources. - Through our Anniversary Program, we celebrate the meaningful milestones and long tenure that reflect how much we value your contributions and commitment to our team. - Career and skill development resources to help advance your career and personal growth. - A mission-driven environment where your work makes a measurable impact on the real estate industry. What We Value - Wherever it Leads, Whatever it Takes® - No matter how remote, complex, or unexpected. Our commitment never wavers. - Hire NICE people - Skills can be taught but character shines through. We seek those who bring integrity, kindness, and grit. - Lift others up - We lead with empathy and strive to improve the lives of those around us. - Sweat the details - Excellence lives in the little things. Getting it just so is how we make a big impact. - Raise the bar - We don’t settle for industry standards, we redefine them. About Us Our story began in the mountain town of Truckee, California more than 20 years ago, when we pioneered simple, web-based valuation technology solutions for an industry that relied on paper. Today, we’ve grown one of the highest-coverage networks of real professionals in the county. As we continue our journey to modernize valuation we’ll hold on to our promise from day one: to go wherever it leads and do whatever it takes to serve our customer with remarkable technology and uncompromising service. Clear Capital is an equal-opportunity employer. To all recruitment agencies: Clear Capital does not accept agency resumes. Please do not forward resumes to our jobs alias, Clear Capital employees, or any other company location. Clear Capital is not responsible for any fees related to unsolicited resumes.

United States
$150K - $200K / year
University of Maryland Global Campus logo

Cyber Operations, Department of Cybersecurity - Adjunct Faculty

University of Maryland Global Campus

The University of Maryland Global Campus (UMGC), founded in 1947, is a pioneering institution dedicated to serving adult learners and military personnel worldwide. As a proud membe

Adjunct Faculty Cyber Operations Department of Cybersecurity UMGC Stateside Location: Stateside Remote University of Maryland Global Campus (UMGC) seeks adjunct faculty to teach remotely for the Cyber Dev Operations program. Specifically, the following course(s): Foundations of Cyberspace Operations (CYOP 200): A hands-on introduction to the principles of cyberspace operations that support defensive and offensive processes. The objective is to navigate, integrate, and use popular cybersecurity tools and functions in a safe environment to detect and reduce system threats and vulnerabilities. Topics include strategic and tactical planning and guidance, security objectives for information systems, cybersecurity frameworks, security design principles, vulnerabilities and exploits, network and application security techniques, and automated tools for testing and security assessment. Reverse Engineering and Malware Analysis (CYOP 310): A lab-intensive study of reverse engineering and malware analysis techniques. The objective is to recognize, dissect, and remediate infections caused by malicious code and malware using modern tools and methodologies. Topics include malware analysis, reverse engineering, common malware patterns, assembly language, debuggers and obfuscation, and packing techniques. Cyber Operations Capstone (CYOP 495): A comprehensive project-driven study of cyber operations, network collection tactics, techniques, and procedures and reverse engineering and malware analysis with an emphasis on the proactive response to triggers or unusual activity. The objective is to use appropriate tools and techniques to monitor cyber operations. Topics include wireless and virtual networks, cryptography, network monitoring and intrusion analysis, threat hunting, and secure software engineering. Required Education and Experience - Masters degree in Cyber Operations or related field from an accredited institution of higher learning. - Professional experience in Cyber Operations or related fields. - Experience teaching adult learners online and in higher education is strongly preferred. - This position is specifically to teach online. Materials needed for submission - Resume/ Curriculum Vitae - Cover letter highly preferred - If selected, candidates with international degrees may be required to submit translation/ degree evaluation from a NACES approved Vendor. Who We Are and Who We Serve UMGC—one of 12 degree-granting institutions in the University System of Maryland (USM)—is a mission-driven institution with seven core values that guide us in all we do. At the top of the list is "Students First,” and we strive to do just that for our 90,000 students at home and abroad. From its start in 1947, UMGC has demonstrated its commitment to adult learners. We recognize that adult students need flexibility and options. UMGC is proud to be a global, 24-hour, institution of higher learning. The typical UMGC student is an adult learner juggling a career, family, and other priorities. Roughly 80% work full time, half are parents, and half are minority students. They are continuing their education to better themselves, their families, and their professional opportunities. UMGC is also a leading higher education provider to the U.S. military, enrolling 55,000 active-duty service members, reservists, National Guard members, veterans, and family members annually. We are proud of our military heritage and are committed to this service. The Adjunct Faculty Role at UMGC UMGC is committed to helping students achieve success not only with us, but also in their professional fields. As a result, we actively seek faculty members who are scholar-practitioners: professionals who are actively and successfully engaged in their field who additionally wish to help the next generation of professionals grow in their knowledge and expertise through education. Your role as an adjunct faculty member will be to: - Actively engage students through frequent interaction that motivates them to succeed, and conveys a genuine energy and enthusiasm for their learning. - Guide students in active collaboration and the application of their learning in problem- and project-based learning demonstrations. - Provide rich and regular constructive feedback, utilizing rubrics effectively for the assessment of student work, and acknowledging student accomplishments. - Demonstrate relevant and current subject-matter expertise, and help students connect concepts across their academic program. - Provide feedback to your program chair on possible curricular improvements. The Computer Networks and Cybersecurity program at UMGC Please visit the following link to learn more about this program, including its description, outcomes, and coursework: https://www.umgc.edu/online-degrees/masters/cybersecurity-technology Faculty Training at UMGC We are committed to your professional success at UMGC. Each new faculty member is required to successfully complete our online two-week new faculty orientation, FacDev 411, as a condition of hire. Position Available and will Remain Open until Filled Salary Commensurate with Experience All submissions should include a cover letter and resume. The University of Maryland Global Campus (UMGC) is an equal opportunity employer and complies with all applicable federal and state laws regarding nondiscrimination. UMGC is committed to a policy of equal opportunity for all persons and does not discriminate on the basis of race, color, national origin, age, marital status, sex, sexual orientation, gender identity, gender expression, disability, religion, ancestry, political affiliation or veteran status in employment, educational programs and activities, and admissions. Workplace Accommodations: The University of Maryland Global Campus Global Campus (UMGC) is committed to creating and maintaining a welcoming and inclusive working environment for people of all abilities. UMGC is dedicated to the principle that no qualified individual with a disability shall, based on disability, be excluded from participation in or be denied the benefits of the services, programs, or activities of the University, or be subjected to discrimination. For information about UMGC’s Reasonable Workplace Accommodation Policy or to request an accommodation, applicants/candidates can contact Employee Accommodations via email at employee-accommodations@umgc.edu. Benefits Package Highlights: - Health Coverage: Access to health care, medical with vision, dental, and prescription plans for both individuals and families, effective from the 1st of the month following your hire date. NOTE: Adjuncts are not eligible for the State of Maryland subsidized rates. Adjuncts would be responsible for the total cost if enrolled. - Insurance Options: Term Life Insurance and Accidental Death and Dismemberment Insurance. - Supplemental Retirement Plans: include 401(k), 403(b), 457(b), and various Roth options. The university does not provide matching funds. For additional information please see: SS Adjunct Faculty_2020.pdf (umgc.edu) Hiring Range by Rank and Degree: Instructor: No Terminal Degree: Step 1 $806 - Step 11 $1,050 per credit hour Assistant Adjunct Professor: No Terminal Degree Step 1 $877 - Step 11 $1,127 per credit hour Assistant Adjunct Professor: Terminal Degree Step 1 $1,023 - Step 11 $1,288 per credit hour Associate Adjunct Professor: No Terminal Degree Step 1 $947 - Step 11 $1,205 per credit hour Associate Adjunct Professor: Terminal Degree Step 1 $1,202 - Step 11 $1,483 per credit hour Adjunct Professor: No Terminal Degree Step 1 $1,023 - Step 11 $1,288 per credit hour Adjunct Professor: Terminal Degree Step 1 $1,347 - Step 11 $1,645 per credit hour

United States
Job Closed