DevSecOps Engineer
$130k - $160kClaritas Rx LLC
Who We Are
Claritas Rx uses AI and predictive modeling to help rare disease and specialty brands remove the barriers that keep patients from accessing and staying on the treatments they need. By uniting the most complete view of the patient journey with purpose-built technologies, we predict and resolve access challenges before they disrupt care, combining advanced analytics, real-world data, AI, and CRM capabilities to increase start and refill rates, reduce abandonment, and improve brand performance. Our mission is to ensure patients with chronic, life-threatening diseases receive the support that enables the greatest benefit from their therapy. Simply put, our promise is progress for every patient journey.
This is the opportunity to help shape a first-in-industry digital health solution alongside a team of mission-driven professionals. We were named one of Inc.'s Best Workplaces in 2025 and recognized on the Inc. 5000 list for two consecutive years (2025 and 2026), and our team genuinely respects and supports each other. We thrive on being fast-paced, innovative, and results-driven, and our employees enjoy a flexible, collaborative work environment, unlimited PTO, stock options, and a growing set of tools and technology to drive innovation for our customers.
The Position
We are seeking a skilled and hands-on DevSecOps professional to join our Engineering team. Reporting to the Sr. Manager, Site Reliability, you will be a key individual contributor responsible for protecting the confidentiality, integrity, and availability of Claritas Rx's AWS-hosted SaaS platform — a system that processes sensitive patient and commercial data for some of the world's leading biopharmaceutical companies.
In this role, you will own day-to-day security engineering work: hardening infrastructure, managing vulnerability programs, responding to security events, and embedding security practices into the software development lifecycle. You will work closely with Software Engineering, SRE, and external compliance partners to ensure our platform maintains the rigorous compliance posture our customers and regulators require — including HIPAA, SOC 2 Type II, and HITRUST.
This is a high-impact individual contributor role suited to an engineer who thrives at the intersection of security and cloud infrastructure, takes ownership of outcomes, and brings a builder's mindset to security problems. The role is primarily remote with occasional travel requirements.
Key Accountabilities
Security Monitoring & Incident Response
- Own security monitoring across the platform: tune and triage alerts from AWS GuardDuty, Security Hub, CloudTrail, and related tooling to distinguish signal from noise and surface actionable threats.
- Serve as a primary responder for security incidents — investigate, contain, and remediate threats; document findings; and drive post-incident reviews with clear corrective actions.
- Maintain and continuously improve detection capabilities, including log analysis pipelines, alert rules, and correlation logic, to reduce mean time to detect (MTTD) and mean time to respond (MTTR).
- Participate in on-call rotation for security events, with appropriate escalation paths and runbooks in place.
Cloud Security Engineering
- Design, implement, and maintain security controls across the AWS environment — including IAM policies, SCPs, KMS key management, VPC security, WAF rulesets, and network segmentation.
- Conduct regular reviews of cloud configurations using AWS Config, Inspector, Macie, and third-party tooling; remediate findings and track resolution to closure.
- Partner with the SRE team to ensure infrastructure-as-code (AWS CDK) templates follow security best practices and that security controls are version-controlled, auditable, and reproducible.
- Evaluate new AWS services and architectural changes for security implications, providing clear guidance to engineering teams before and during adoption.
- Implement security focused observability patterns to detect threats as they emerge.
Vulnerability Management
- Support the vulnerability management lifecycle: asset discovery, scanning (infrastructure and application), risk-based prioritization, remediation tracking, and reporting.
- Coordinate with Software Engineering to integrate SAST, DAST, dependency scanning, and container image scanning into CI/CD pipelines (GitHub Actions), ensuring vulnerabilities are caught early in the SDLC.
- Track and communicate vulnerability metrics to engineering and leadership, balancing remediation urgency against engineering capacity.
- Research emerging threats, CVEs, and attacker techniques relevant to our technology stack and cloud environment; translate findings into actionable defensive improvements.
Compliance & Data Protection
- Support the maintenance and continuous improvement of Claritas Rx's HIPAA, SOC 2 Type II, and HITRUST compliance programs — including evidence collection, control testing, and gap remediation.
- Ensure PHI handling practices — at rest, in transit, and in processing — meet regulatory requirements; identify and close gaps in data classification, encryption, access control, and audit logging.
- Maintain and test data protection controls including encryption key management, secrets rotation (via AWS Secrets Manager), and DLP measures.
- Support external audits and assessments: prepare evidence packages, respond to auditor inquiries, and track audit findings through remediation.
- Contribute to the development and maintenance of security policies, standards, and procedures.
Identity & Access Management
- Administer and continuously refine AWS IAM roles, policies, and permission boundaries, applying least-privilege principles across all environments.
- Manage access lifecycle processes: provisioning, periodic access reviews, and de-provisioning for human and machine identities.
- Evaluate and improve authentication and authorization controls — including MFA enforcement, SSO integration, and privileged access management.
Cross-Functional Partnership
- Collaborate with SRE and Software Engineering to embed security requirements into production readiness reviews, architecture decisions, and deployment processes.
- Serve as a trusted security resource for engineering teams — providing practical, risk-informed guidance rather than purely compliance-driven mandates.
- Communicate security risks and program status clearly to both technical peers and non-technical stakeholders, including leadership.
Our Stack
- Cloud: AWS (ECS, EC2, Aurora RDS, DynamoDB, Lambda, S3, SQS, EventBridge, Cognito, Secrets Manager, CloudFront, WAF)
- Infrastructure as Code: AWS CDK (primary); familiarity with Terraform/OpenTofu a plus
- CI/CD: GitHub Actions
- Application Platform: NestJS/TypeScript (backend), React/TypeScript (frontend), PostgreSQL, Turborepo, pnpm
- Data Platform: AWS Glue, Lake Formation, PySpark, Kinesis (data streaming), Python-based ELT pipelines
- Observability & Monitoring: CloudWatch (logs, metrics, alarms, dashboards), Sentry, OpenFeature (feature flags), Tableau
- Languages in Use Across Engineering: TypeScript, Python, SQL; Golang familiarity a plus
- Work Management: Jira
- Compliance: HIPAA, SOC 2 Type II, HITRUST
Who You Are
Required Skills:
- 4+ years of experience in information security engineering, cloud security, or a closely related discipline with hands-on technical ownership.
- Solid, practical AWS security expertise — you understand IAM, KMS, VPC security, CloudTrail, GuardDuty, Security Hub, Config, and WAF at a working level, not just conceptually.
- Experience operating a vulnerability management program: scanning, prioritization, tracking, and reporting across infrastructure and application layers.
- Demonstrated ability to respond to and investigate security incidents in a cloud environment — from initial triage through containment, root cause analysis, and corrective action.
- Familiarity with integrating security tooling (SAST, DAST, dependency scanning, container scanning) into CI/CD pipelines and developer workflows.
- Working knowledge of HIPAA, SOC 2, and/or HITRUST requirements as they apply to technical controls — you understand what compliance requires and how to implement it in an engineering context.
- Scripting proficiency in Python, Bash, or equivalent for automating security tasks, log analysis, and tooling integrations.
- Strong written and verbal communication skills — you can explain security risk and technical trade-offs clearly to both engineering peers and non-technical stakeholders.
- Collaborative, team-oriented mindset with the ability to influence security outcomes without direct authority.
- Comfort operating independently in a fast-paced, high-growth startup environment where priorities shift and initiative is expected.
Preferred Skills:
- Experience in a healthcare technology or digital health environment with direct exposure to HIPAA-regulated PHI and the controls required to protect it.
- Hands-on experience with threat modeling methodologies (e.g., STRIDE, PASTA) applied to cloud-native application architectures.
- Familiarity with penetration testing concepts and experience participating in or coordinating third-party security assessments.
- Experience with privileged access management (PAM) tooling and secrets management at scale.
- Exposure to the Claritas Rx application stack: TypeScript, NestJS, PostgreSQL, React.
- Experience leveraging AI tools (including Claude) to accelerate threat hunting, automate security documentation, or streamline compliance evidence workflows.
- Relevant certifications such as AWS Security Specialty, CISSP, CISM, CEH, OSCP, CompTIA Security+, or equivalent.
- B.S. in Computer Science, Information Security, or a related discipline, or equivalent practical experience.
Join Us
We are seeking to add new expertise and perspective to our strong team of experienced professionals. We aspire to a culture of accelerated professional development through: shared learning and collaboration; a respectful and fun work environment; and employee empowerment through the effective use of technology and tools.
We are a highly collaborative team and prioritize opportunities to connect in person. For employees within a reasonable driving distance of each other, we host regional town hall gatherings approximately every other month. These sessions give our teams a chance to come together, share updates, and strengthen relationships beyond day-to-day work.
In addition to our great environment, we offer a competitive salary of $130,000 to $160,000 and benefits package and the opportunity to make a significant impact on a first-in-industry digital health solution. Please send a cover letter along with your resume when applying to the position of interest. Claritas Rx embraces diversity, equality, and transparency. We are committed to building a team that comprises a variety of backgrounds, perspectives, and talents. We believe the more inclusive we are, the better we are.
Join us and discover what it feels like to be part of an environment that rewards ingenuity, risk taking and smart work. It's time to fall in love with what you do!
At Claritas Rx, protecting our candidates is a top priority. If you're applying for a role with us, please note:
•All legitimate opportunities are posted first on ClaritasRx.com. Check there before trusting external listings.
• We believe in meaningful interviews: offers never come after just one phone call or form. Expect multiple video calls to get to know you.
• We never ask for fees or payments of any kind during the hiring process.
• Our People Operations Team will handle your onboarding, and all equipment comes directly from us—no purchases required.
Learn more about how to spot recruitment scams and protect yourself - FBI warning:
Claritas Rx is committed to transparency, integrity, and a safe hiring experience for every candidate. Learn more
- ...C omputational Physics, Inc. (CPI) is looking for a Full-Time Software Engineer / DevSecOps Engineer to support our customers at USNO, Washington, DC. Background A DevSecOps Engineer with strong software development fundamentals and a security-first mindset...SuggestedFull timeFor contractorsWork at officeFlexible hours
$180k - $195k
As a Sr. DevSecOps Engineer I, you’ll play a critical role in designing, implementing, and maintaining secure and efficient software development and deployment pipelines. You will collaborate with cross-functional teams to integrate security practices seamlessly into the...SuggestedFull timeLocal area$112.2k - $196.4k
...Description:Parsons is looking for an experienced, team-oriented GMD DevSecOps Engineerto join our team! In this role, you will provide... ...Directory, and user account management.Collaborate with cyber engineers to execute STIG evaluation, analysis, and implementation....SuggestedFull timeFlexible hours$77.5k - $176k
DevSecOps EngineerThe Opportunity:As a DevOps engineer, you know how to set up cloud environments and provision computer networking, storage, and virtual networks—ultimately, how to “harness the cloud.” We’re looking for an experienced DevOps infrastructure engineer like...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$113.2k - $237.8k
Job Title: Senior DevSecOps EngineerJob Category: EngineeringTime Type: Full timeMinimum Clearance Required to Start: TS/SCI with PolygraphEmployee... ...optimization. As a DevOps / Infrastructure / DevSecOps Engineer on an AWS-based, Kubernetes-native environment, you will:...SuggestedContract workWork experience placementFlexible hours$86k - $138k
ResponsibilitiesPeraton is seeking an enthusiastic and talented junior DevSecOps engineer to build on ongoing modernization efforts for the US Navy with enabling microservices to be rapidly built, tested, fielded, and integrated to container orchestration platforms through...Contract workLive inRemote workShift work$107.93k - $188k
...Join Deloitte’s Government & Public Services practice as a DevSecOps-focused Senior Consultant, Enterprise Security. In this role,... ...scanning, and secrets detectionSupporting cloud and platform engineering teams with secure configuration, infrastructure as code, container...Local area$114k - $171k
...Operations, and Missile Defense Integration Business Unit (BU) has an exciting career opportunity for a Principal/Sr. Principal DevSecOps Engineer - Level 3 or 4 to join our team of qualified, diverse individuals. Our domain provides rewarding work that contributes to the...Full timeWork experience placementRelocationShift work$62k - $141k
DevSecOps EngineerThe Opportunity:Seeking a DevSecOps Engineer to manage CI/CD pipeline and infrastructure in an Agile design, development, integration and deployment of a mission management software for heterogeneous, proliferated satellite constellations. Your ability...Full timeContract workPart timeWork at officeLocal areaRemote work$115k - $130k
Position: DevSecOps Engineer Location: Colorado Springs, CORemote Status: Hybrid Job Id: 13712-MSFITS # of Openings: 1 Auria is looking to hire a DevSecOps Engineer to join the team and support...Contract workWork at officeFlexible hours- ...subsidiary of ASRC Federal, is a premier provider of systems engineering, software engineering, system integration and project management... ...-time, mission-critical defense systems. AFSS is seeking a DevSecOps Engineers in Colorado Springs, CO to support the Ground Based...Interim role
$146.2k - $228.4k
ResponsibilitiesNoblis is seeking a highly experienced DevSecOps Engineer with an active Top Secret/SCI clearance and Polygraph to support mission-critical national security initiatives.In this role, you will be responsible for integrating security throughout the DevOps...Full timeContract workPart timeLocal areaRemote work$107.9k - $195.05k
Senior DevSecOps Platform EngineerLeidos is seeking Senior DevSecOps Platform Engineers to join the Air Traffic Business Area within the Homeland Sector, supporting the development of next-generation flight service and air traffic systems. This work aligns with the FAA...Full timeRemote work$77.6k - $176k
DevSecOps Engineer, SeniorThe Opportunity:DevOps engineering requires a specific mix of development, engineering, and communication skills. As a DevOps engineer, you know that these skills create efficiency and effectiveness—so you can quickly deliver the best solutions...Full timeContract workPart timeWork at officeLocal areaRemote work$149k - $186k
Title:Senior DevSecOps Cybersecurity EngineerBelong. Connect. Grow. with KBR!KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position,...Full timeContract workFor contractorsLocal areaImmediate startWork from homeFlexible hours$125k
Computer Technologies Consultants (CTC) is seeking a DevSecOps Engineer to support the Congressional Budget Office (CBO) in Washington, DC. With offices in Washington DC and San Diego, CA, CTC is a leading technology company providing lifecycle IT, data analytics, cloud...Full timeContract workFor contractorsWork at officeLocal areaRemote work$80k - $175k
...disability status, and protected veteran status, amongst our ranks. Additionally, we participate in the E-Verify program.As a DevSecOps Engineer, you will work with our growing DevSecOps practice delivering features to support cloud and application development. This...For contractors$62k - $141k
DevSecOps EngineerThe Opportunity:As a DevOps engineer, you know how to set up cloud environments and provision computer networking, storage, and virtual networks, ultimately, how to “harness the cloud.” We’re looking for a DevOps infrastructure engineer like you to support...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Specifically, we're recognized for hiring noted experts, experienced engineers and scientists dedicated to designing and delivering advanced,... ...in defense of our Nation.Davidson Technologies is seeking a DevSecOps Engineer in Huntsville, Alabama to support the Integrated...
$131.3k - $237.35k
...commercial fields, Leidos provides responsive, cost-effective engineering, scientific and IT solutions. Leidos is well known for our people... ...Area at Leidos currently has an opening for a talented Senior DevSecOps Engineer to work in our Huntsville office.Primary...Full timeWork at officeRelocation$145k - $215k
...active U.S. Government Security Clearance at the TS/SCI with CI poly level.Unlock your future with Vantor! We need a Senior DevSecOps Engineer with on-prem and cloud expertise to support efforts to manage our new infrastructure platform. Join our operations, software,...Full time$122.66k - $215.7k
...market, representing how TTM's time-critical, one-stop design, engineering and manufacturing services enable customers to reduce the time... ...- Aerospace and Defense Sector is seeking a Senior DevSecOps Software Engineer to support our Radar and Surveillance team locating...Permanent employmentFull timeWorldwideFlexible hoursShift work$125k - $150k
Job DescriptionEverforth ECS is seeking a DevSecOps Engineerto work in a hybrid remote/onsite capacity, with minimum of 3 business days... ...documentation, and coordinates extensively with software engineering, cybersecurity, and platform infrastructure teams to maintain...Contract workWork at officeRemote work- Reference: 85347-369905Readiness Delivered. Kratos engineers and deploys technology and systems that move national security forward, with... ...and ourselves. As part of the Build Automation team, the Sr. DevSecOps Engineer will focus on the build and deploy pipelines for...Temporary work
- ...United States Defense and Intelligence Communities to support national security.Rincon Research Corporation is looking for a DevSecOps Engineer to develop advanced secure cloud computing solutions for complex national security and defense challenges in signal processing...Temporary workRemote workFlexible hours
$98.5k - $206.8k
Job Title: Sr. DevSecOps EngineerJob Category: EngineeringTime Type: Full timeMinimum Clearance Required to Start: TS/SCIEmployee Type... ...Travel: Continental US* * *The Opportunity:As a Senior DevOps Engineer, you will be part of an Agile development team where you will...Contract workWork experience placementFlexible hours- ...intersection of advanced mathematics, computer science, physics, and engineering. Our people are leaders in their technical fields and are... ...settings. Job Description: Our Reston, VA office is seeking a DevSecOps Engineer to help secure and improve software delivery across...For contractorsWork at office
- DescriptionSAIC is looking for a full-time onsite DevOps / DevSecOps Engineer to join our team in Hampton, VA in support of the Air Operations Center Weapons System (AOC WS) Falconer Program's Application Transformation (AppTX) team. Candidates MUST be willing and able...Full timeMonday to Friday
- ...warfighters and federal agencies with technology and systems engineered to connect, protect, and prepare individuals and teams for whatever... ...OverviewExecute the development, operation and maintenance of DevSecOps processes, tools and an automation pipeline that supports...Contract workTemporary workWork experience placementLocal areaWorldwide
$200k - $220k
As a Sr. DevSecOps Engineer III, you’ll play a critical role in designing, implementing, and maintaining secure and efficient software development and deployment pipelines. You will collaborate with cross-functional teams to integrate security practices seamlessly into...Full timeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to DevSecOps Engineer. Be the first to apply!


