Jobs Companies Triallibrary DevSecOps / Cloud Engineer

Sobre esta vaga de DevSecOps / Cloud Engineer na Triallibrary

Triallibrary · Híbrido · San Francisco, CA
Trial Library is an AI-native research platform with a mission to improve healthcare outcomes by expanding access to precision medicine. 
 
About Trial Library

Trial Library is an AI-native enrollment and care navigation platform that accelerates access to precision medicine. In collaboration with biopharmaceutical manufacturers, payers, and health systems, Trial Library enables the delivery of clinical trials as a standard care option - improving patient access, advancing oncology outcomes, and reducing the total cost of care. Backed by leading healthcare venture capital firms, Trial Library’s platform is currently deployed in 840+ clinics and 3,000+ providers nationwide.


Join our small, high-trust Infrastructure team as its second engineer, reporting to the Director of Infrastructure and partnering closely with our product engineering team. You will drive two key initiatives: building a cohesive AWS foundation with Terraform, Control Tower, and AFT, and owning end-to-end security engineering for our production PHI and Bedrock AI workloads. Just as important, you'll build the paved paths, self-service tooling, and guardrails that let our engineers ship quickly.

AI is deeply embedded in how we work. We use it across coding, testing, and operations, not because of a mandate but because we've seen what it unlocks. We're looking for someone who already builds this way and is curious about what AI-augmented practice looks like in infrastructure and security work. We value fast decisions, open feedback, and empowered engineers.

Your Responsibilities

What you'll own

  • Infrastructure as code. The Terraform codebase - module design, state strategy, drift detection, plan review discipline - and the migration of our CloudFormation/Serverless footprint where it delivers real leverage, without stalling product delivery.

  • The AWS landing zone. Multi-account structure via Control Tower and AFT: account vending, customizations, service control policies, and OU design.

  • Security engineering. Security Hub, GuardDuty, Inspector, and Config as living detection tooling: triage findings, tune signals, and run the vulnerability lifecycle from discovery through verified fix. Coordinate penetration tests and own remediation.

  • Pipeline and supply chain security. Secure the commit-to-production path in GitHub Actions: least-privilege OIDC deployment roles, secrets scanning, SAST and dependency/container gates, branch protection, and artifact integrity.

  • Developer enablement. Paved-path tooling, self-service infrastructure, and secure defaults that let product engineers move fast without filing tickets.

  • Disaster recovery and backup. Backup strategy, RPO/RTO targets, Aurora point-in-time recovery, and regular DR testing to satisfy HIPAA contingency planning requirements.

  • Compliance as code. SOC 2 and HIPAA controls encoded into the platform - encryption, KMS, CloudTrail/Config coverage, log retention - with automated evidence collection.

  • Identity and access governance. IAM Identity Center, cross-account roles, SSO, periodic access reviews, and joiner/mover/leaver deprovisioning, alongside network foundations: VPC design, WAF, and Client VPN.

  • Where you'll contribute

    Alongside the Director of Infrastructure and the Dev Team:

  • Security architecture for Bedrock AI workloads: access controls, guardrails, PHI data boundaries

  • Production incident response (reliability and security) and recurrence prevention

  • Observability and cost visibility: CloudWatch, alarms, dashboards, tagging

  • Partnership with application engineers on Lambda, Aurora PostgreSQL, and Bedrock workloads

  • Lightweight threat modeling and security review of new features and third-party integrations touching PHI, including sponsor/CRO data-handling requirements

  • Your Requirements

  • 5+ years in DevSecOps, security, platform, or infrastructure engineering, operating production systems you were accountable for

  • Demonstrated security ownership: you have run vulnerability management, remediated real findings, and participated in incident response - not just deployed tooling

  • Deep Terraform proficiency: module hierarchies, multi-environment state, drift and refactors, critical plan review

  • Hands-on AFT and Control Tower experience - you have vended accounts through AFT and customized the pipeline, not adjacent familiarity

  • Broad AWS depth: IAM, Organizations, VPC, Lambda, RDS/Aurora, S3, KMS, CloudTrail, Config, Security Hub, GuardDuty, Secrets Manager

  • GitHub Actions as a daily environment, including pipeline hardening and secrets management

  • SOC 2 Type II and HIPAA experience in a real PHI-handling environment - you have owned controls, produced evidence, and sat in front of an auditor

  • Change and release discipline: you think about blast radius before you apply, have owned deployment and rollback strategies in production, and move quickly inside regulated-environment constraints rather than treating them as obstacles

  • Hands-on, autonomous, and clear: you write code daily, take ambiguous problems to documented decisions, and can explain security tradeoffs to non-security people

  • You use AI coding and automation tools as a daily part of how you work, and you actively explore how they change infrastructure and security practices

  • Genuine interest in improving clinical trial access and health equity

  • Nice to Have

  • Compliance automation platforms (Drata, Vanta) including evidence automation

  • CloudFormation/CDK/Serverless-to-Terraform migration experience

  • GitHub EMU, SCIM, and SAML SSO administration

  • Aurora PostgreSQL operations and schema migration coordination

  • Python or TypeScript for automation

  • HITRUST, NIST 800-53, or CSA STAR exposure

  • Securing LLM workloads


  • Why Trial Library

    • Meaningful impact — helping patients access clinical trials faster through better technology and workflows
    • High ownership environment — autonomy to build, test, and influence strategy across the business
    • Collaborative team culture — low ego, high trust, and close partnership across functions
    • Opportunity for growth — join at an early stage with meaningful exposure to company-building and decision-making

    Our Core Values

    • Ally is our favorite moniker
    • The broadest reach is worth the effort
    • Celebrate measurable improvements in access and  outcomes
    • Fearless advocates for representation in research
    • Incentives matter to stakeholders choosing our products
    • Taking initiative is actually giving
    • We are accountable for the experience of patients and providers
    • Empathy and humility are the real dynamic duo

    Our Benefits & Perks

    • Health & Wellness: Comprehensive medical, dental, and vision coverage for employees and eligible dependents, along with disability, life, and supplemental insurance options designed to support your overall well-being.
    • Time Off & Workplace Support: Flexible paid time off, observed company holidays, and a one-time home office stipend to help you create a productive and comfortable remote workspace within our hybrid environment.
    • Financial & Lifestyle Benefits: 401(k) program, pre-tax HSA and FSA options, commuter benefits, financial wellness resources, and access to legal protection plans to support both short- and long-term planning.
    • Additional Support & Voluntary Benefits: Access to voluntary benefit offerings including pet wellness support, domestic partner coverage, and additional programs that support the diverse needs of our team members and their families.

    Our Interview Process

    Our interview process typically includes four stages, followed by reference checks and an offer. Depending on the role, particularly for technical or senior positions, the process may vary slightly and can include a technical assessment, case study, presentation, practical exercise, additional interview conversations, or conversations with members of our leadership team and investors.

     
     
    Trial Library, Inc. is an equal opportunity employer committed to building an inclusive workplace. We provide equal employment opportunities to all employees and applicants and prohibit discrimination and harassment of any kind without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, national origin, ancestry, age, disability, genetic information, marital status, veteran status, military status, medical condition, family or medical leave status, political affiliation, or any other characteristic protected by applicable federal, state, or local law.
     
    Trial Library, Inc. is committed to providing reasonable accommodations for qualified individuals with disabilities throughout the recruiting process. If you require assistance or accommodation, please contact [email protected]
    Pronto para se candidatar à Triallibrary?
    Candidatar-se à Triallibrary

    Vagas semelhantes

    Gusto, Inc.
    Security Engineer - Cloud and Network Security
    Gusto, Inc.
    ⚡ Candidate-se cedo San Francisco, CA - Hybrid Híbrido $210,000–$210,000
    ● Nova 👁 Vista ✓ Candidatada há 2d
    Mercury
    Senior Cloud Security Engineer - InfoSec
    Mercury
    ⚡ Candidate-se cedo San Francisco, CA, New York, N... · local restrito
    ● Nova 👁 Vista ✓ Candidatada há 2d
    Fastly
    Senior Cloud Engineer
    Fastly
    ⚡ Candidate-se cedo San Francisco, CA Híbrido $122,280–$172,632
    ● Nova 👁 Vista ✓ Candidatada há 2d
    Fluidstack
    Security Engineer, Cloud
    Fluidstack
    ⚡ Candidate-se cedo Austin, TX Presencial $182,000–$224,000
    ● Nova 👁 Vista ✓ Candidatada há 5d
    CoreWeave
    Technical Support Engineer - III (Cloud)
    CoreWeave
    ⚡ Candidate-se cedo Livingston, NJ / New York, NY... Presencial $122,000–$163,000
    ● Nova 👁 Vista ✓ Candidatada há 6d
    CoreWeave
    Senior Security Engineer II, Cloud Security
    CoreWeave
    ⚡ Candidate-se cedo Livingston, NJ / New York, NY... Presencial $165,000–$242,000
    ● Nova 👁 Vista ✓ Candidatada há 6d
    SA
    Senior Software Engineer - Infrastructure Cloud Security
    Snorkel AI
    ⚡ Candidate-se cedo Redwood City, CA (Hybrid); San... Híbrido $220,000–$260,000
    ● Nova 👁 Vista ✓ Candidatada há 1sem
    Crusoe
    Principal Software Engineer, Crusoe Cloud
    Crusoe
    ⚡ Candidate-se cedo San Francisco, CA - US Presencial $256,000–$320,000
    ● Nova 👁 Vista ✓ Candidatada há 1sem
    Fluidstack
    Welding Engineer / AWS D1.1 CWI
    Fluidstack
    ⚡ Candidate-se cedo Austin, TX Presencial $169,000–$193,000
    ● Nova 👁 Vista ✓ Candidatada há 1sem

    Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

    Mais vagas na Triallibrary

    Ver todas as vagas na Triallibrary →

    Candidatar-se agora
    🤖

    Opa — calma aí

    A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

    Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

    Catch your next role the second it’s posted.

    Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

    Create free account

    Free forever · takes 30 seconds · already have one?

    Ganhe vantagem na sua busca por emprego.

    Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

    Entre no canal — é grátis