See how much of this job your resume covers, and what’s missing.
Want a recruiter to go through it line by line?
Get professional reviewUpload your resume and we draft a letter for this exact role, tailored to what it asks for.
You will design and implement security guardrails, compliance evidence, and automated detection systems for a HIPAA-regulated AWS platform. Additionally, you will manage vulnerability assessments, penetration testing, and incident response procedures to ensure the platform remains secure and audit-ready.
DevSecOps Engineer
Security engineering, detection and compliance evidence for a HIPAA-regulated public-health data platform · Remote (U.S.)
We're looking for a DevSecOps engineer to make a new AWS platform for rural health data provably secure, from the first guardrail to the pre-go-live penetration test. You'll turn the contract's control list into enforced configuration and continuous evidence for the project, a cloud-based, open-source semantic data model. The project will harmonize EHR, claims and public-health data into one computable form and serve it through FHIR APIs.
The platform holds protected health information. It is held to NIST SP 800-53 moderate controls and the HIPAA Security Rule, with a seven-year tamper-evident audit log, quarterly vulnerability scanning and annual penetration testing. You'll be the engineering half of the HIPAA program, working alongside a senior platform engineer, with the HIPAA Security Officer as the accountable half.
THE ROLE AT A GLANCE
Engagement | 1099 independent contractor; you work as part of HK's team |
Term | Mid-October 2026 through September 2027; a second year is possible, subject to funding |
Commitment | Full time, 40 hours a week |
Reports to | HK's Software/Development Director, with security direction from the HIPAA Security Officer and architecture direction from the program architect |
Location | Remote within the U.S.; core hours 9:00 a.m.–3:00 p.m. Mountain; occasional travel to Salt Lake City |
Requirements | U.S. work authorization; background check before production access; HIPAA training before any access |
Stack | AWS Organizations and SCPs, IAM Identity Center, KMS, CloudTrail, Config, GuardDuty, Security Hub, Inspector, WAF; EKS with Kyverno; Keycloak; OpenSearch; OpenTofu; GitOps |
WHAT YOU'LL DO
You take the platform from its first service control policy to a passed pre-go-live penetration test in March, and you're the person who can show an assessor the evidence for every control.
YOUR FIRST 30 DAYS
The first three weeks are the critical path for the whole program. You'll pair with the platform engineer to stand up the landing zone, with security built in from day one rather than added later.
Week | What success looks like |
Week 1 | SCPs, org-wide CloudTrail with Object Lock and Config conformance packs live; GuardDuty, Security Hub and Inspector delegated to the security account; KMS key policies reviewed |
Week 2 | Identity Center and Keycloak MFA/FIDO2 enforced; break-glass procedure written; first Security Hub baseline score exported to the evidence folder |
Week 3 | OpenSearch SIEM receiving the core log sources; first detection rules; CI scanning, signing and SBOM gates; evidence folders organized by control family |
Week 4 | Network and KMS review against the architecture written up; risk-analysis workshop scheduled; penetration-test vendor shortlist |
WHAT YOU BRING
NICE TO HAVE
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 215,507+ Jobs in Software Development
Answer easy questions
215,507+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”