Skip to content
← Back to job listings

DevSecOps / Cloud Engineer

triallibrary · San Francisco, CA, United States

CybersecurityImported listingfull-timeabout 1 month ago

About The Role

Trial Library is an AI-native research platform with a mission to improve healthcare outcomes by expanding access to precision medicine.

About Trial Library

Trial Library is an AI-native enrollment and care navigation platform that accelerates access to precision medicine. In collaboration with biopharmaceutical manufacturers, payers, and health systems, Trial Library enables the delivery of clinical trials as a standard care option - improving patient access, advancing oncology outcomes, and reducing the total cost of care. Backed by leading healthcare venture capital firms, Trial Library’s platform is currently deployed in 840+ clinics and 3,000+ providers nationwide.

Your Responsibilities

What you'll own

-

Infrastructure as code. The Terraform codebase - module design, state strategy, drift detection, plan review discipline - and the migration of our CloudFormation/Serverless footprint where it delivers real leverage, without stalling product delivery.

-

The AWS landing zone. Multi-account structure via Control Tower and AFT: account vending, customizations, service control policies, and OU design.

-

Security engineering. Security Hub, GuardDuty, Inspector, and Config as living detection tooling: triage findings, tune signals, and run the vulnerability lifecycle from discovery through verified fix. Coordinate penetration tests and own remediation.

-

Pipeline and supply chain security. Secure the commit-to-production path in GitHub Actions: least-privilege OIDC deployment roles, secrets scanning, SAST and dependency/container gates, branch protection, and artifact integrity.

-

Developer enablement. Paved-path tooling, self-service infrastructure, and secure defaults that let product engineers move fast without filing tickets.

-

Disaster recovery and backup. Backup strategy, RPO/RTO targets, Aurora point-in-time recovery, and regular DR testing to satisfy HIPAA contingency planning requirements.

-

Compliance as code. SOC 2 and HIPAA controls encoded into the platform - encryption, KMS, CloudTrail/Config coverage, log retention - with automated evidence collection.

-

Identity and access governance. IAM Identity Center, cross-account roles, SSO, periodic access reviews, and joiner/mover/leaver deprovisioning, alongside network foundations: VPC design, WAF, and Client VPN.

Where you'll contribute

Alongside the Director of Infrastructure and the Dev Team

-
Security architecture for Bedrock AI workloads: access controls, guardrails, PHI data boundaries
-
Production incident response (reliability and security) and recurrence prevention
-
Observability and cost visibility: CloudWatch, alarms, dashboards, tagging
-
Partnership with application engineers on Lambda, Aurora PostgreSQL, and Bedrock workloads
-
Lightweight threat modeling and security review of new features and third-party integrations touching PHI, including sponsor/CRO data-handling requirements

Your Requirements

-

5+ years in DevSecOps, security, platform, or infrastructure engineering, operating production systems you were accountable for

-

Demonstrated security ownership: you have run vulnerability management, remediated real findings, and participated in incident response - not just deployed tooling

-

Deep Terraform proficiency: module hierarchies, multi-environment state, drift and refactors, critical plan review

-

Hands-on AFT and Control Tower experience - you have vended accounts through AFT and customized the pipeline, not adjacent familiarity

-

Broad AWS depth: IAM, Organizations, VPC, Lambda, RDS/Aurora, S3, KMS, CloudTrail, Config, Security Hub, GuardDuty, Secrets Manager

-

GitHub Actions as a daily environment, including pipeline hardening and secrets management

-

SOC 2 Type II and HIPAA experience in a real PHI-handling environment - you have owned controls, produced evidence, and sat in front of an auditor

-

Change and release discipline: you think about blast radius before you apply, have owned deployment and rollback strategies in production, and move quickly inside regulated-environment constraints rather than treating them as obstacles

-

Hands-on, autonomous, and clear: you write code daily, take ambiguous problems to documented decisions, and can explain security tradeoffs to non-security people

-

You use AI coding and automation tools as a daily part of how you work, and you actively explore how they change infrastructure and security practices

-

Genuine interest in improving clinical trial access and health equity

Nice to Have

-
Compliance automation platforms (Drata, Vanta) including evidence automation
-
CloudFormation/CDK/Serverless-to-Terraform migration experience
-
GitHub EMU, SCIM, and SAML SSO administration
-
Aurora PostgreSQL operations and schema migration coordination
-
Python or TypeScript for automation
-
HITRUST, NIST 800-53, or CSA STAR exposure
-
Securing LLM workloads

This is an external listing. JobSpring does not represent or verify the employer. Report this listing