
DevSecOps / Cloud Engineer
triallibrary · San Francisco, CA, United States
About The Role
Trial Library is an AI-native research platform with a mission to improve healthcare outcomes by expanding access to precision medicine.
About Trial Library
Trial Library is an AI-native enrollment and care navigation platform that accelerates access to precision medicine. In collaboration with biopharmaceutical manufacturers, payers, and health systems, Trial Library enables the delivery of clinical trials as a standard care option - improving patient access, advancing oncology outcomes, and reducing the total cost of care. Backed by leading healthcare venture capital firms, Trial Library’s platform is currently deployed in 840+ clinics and 3,000+ providers nationwide.
Your Responsibilities
What you'll own
-
Infrastructure as code. The Terraform codebase - module design, state strategy, drift detection, plan review discipline - and the migration of our CloudFormation/Serverless footprint where it delivers real leverage, without stalling product delivery.
-
The AWS landing zone. Multi-account structure via Control Tower and AFT: account vending, customizations, service control policies, and OU design.
-
Security engineering. Security Hub, GuardDuty, Inspector, and Config as living detection tooling: triage findings, tune signals, and run the vulnerability lifecycle from discovery through verified fix. Coordinate penetration tests and own remediation.
-
Pipeline and supply chain security. Secure the commit-to-production path in GitHub Actions: least-privilege OIDC deployment roles, secrets scanning, SAST and dependency/container gates, branch protection, and artifact integrity.
-
Developer enablement. Paved-path tooling, self-service infrastructure, and secure defaults that let product engineers move fast without filing tickets.
-
Disaster recovery and backup. Backup strategy, RPO/RTO targets, Aurora point-in-time recovery, and regular DR testing to satisfy HIPAA contingency planning requirements.
-
Compliance as code. SOC 2 and HIPAA controls encoded into the platform - encryption, KMS, CloudTrail/Config coverage, log retention - with automated evidence collection.
-
Identity and access governance. IAM Identity Center, cross-account roles, SSO, periodic access reviews, and joiner/mover/leaver deprovisioning, alongside network foundations: VPC design, WAF, and Client VPN.
Where you'll contribute
Alongside the Director of Infrastructure and the Dev Team
-
Security architecture for Bedrock AI workloads: access controls, guardrails, PHI data boundaries
-
Production incident response (reliability and security) and recurrence prevention
-
Observability and cost visibility: CloudWatch, alarms, dashboards, tagging
-
Partnership with application engineers on Lambda, Aurora PostgreSQL, and Bedrock workloads
-
Lightweight threat modeling and security review of new features and third-party integrations touching PHI, including sponsor/CRO data-handling requirements
Your Requirements
-
5+ years in DevSecOps, security, platform, or infrastructure engineering, operating production systems you were accountable for
-
Demonstrated security ownership: you have run vulnerability management, remediated real findings, and participated in incident response - not just deployed tooling
-
Deep Terraform proficiency: module hierarchies, multi-environment state, drift and refactors, critical plan review
-
Hands-on AFT and Control Tower experience - you have vended accounts through AFT and customized the pipeline, not adjacent familiarity
-
Broad AWS depth: IAM, Organizations, VPC, Lambda, RDS/Aurora, S3, KMS, CloudTrail, Config, Security Hub, GuardDuty, Secrets Manager
-
GitHub Actions as a daily environment, including pipeline hardening and secrets management
-
SOC 2 Type II and HIPAA experience in a real PHI-handling environment - you have owned controls, produced evidence, and sat in front of an auditor
-
Change and release discipline: you think about blast radius before you apply, have owned deployment and rollback strategies in production, and move quickly inside regulated-environment constraints rather than treating them as obstacles
-
Hands-on, autonomous, and clear: you write code daily, take ambiguous problems to documented decisions, and can explain security tradeoffs to non-security people
-
You use AI coding and automation tools as a daily part of how you work, and you actively explore how they change infrastructure and security practices
-
Genuine interest in improving clinical trial access and health equity
Nice to Have
-
Compliance automation platforms (Drata, Vanta) including evidence automation
-
CloudFormation/CDK/Serverless-to-Terraform migration experience
-
GitHub EMU, SCIM, and SAML SSO administration
-
Aurora PostgreSQL operations and schema migration coordination
-
Python or TypeScript for automation
-
HITRUST, NIST 800-53, or CSA STAR exposure
-
Securing LLM workloads
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing