
Senior DevSecOps Engineer
Alto Pharmacy7 days ago
Remote, United StatesSenior
Base Salary
$128k - $160k/yr
Responsibilities
- Define and lead the DevSecOps vision across infrastructure, application, and CI/CD ecosystems.
- Architect secure-by-design cloud-native systems across AWS and GCP.
- Establish security patterns, guardrails, and reference architectures for engineering teams.
- Design, maintain, and secure CI/CD pipelines and developer workflows.
- Drive infrastructure-as-code security practices using Terraform and CloudFormation.
- Automate security testing, compliance checks, policy-as-code, governance controls, and developer tooling.
- Design and maintain Kubernetes resources and environments and strengthen container and Kubernetes security.
- Lead IAM strategy and least-privilege enforcement, including secrets management, encryption, key management, network segmentation, zero-trust architectures, and environment isolation.
- Support security programs aligned with HIPAA, SOC 2, HITRUST, PCI, and other healthcare regulatory frameworks.
- Partner with Security and Compliance teams on audits and remediation efforts.
- Provide senior-level incident leadership, root cause analysis, and long-term mitigation planning.
- Mentor engineers and influence engineering, product, IT, compliance, and executive stakeholders on security strategy and risk prioritization.
Requirements
- 6+ years of experience in software engineering, infrastructure engineering, or security engineering with significant DevSecOps experience.
- Deep expertise in cloud architecture using AWS and/or GCP.
- Strong experience designing, building, and securing containerized and Kubernetes-based environments.
- Hands-on experience with GitHub Actions, GitLab CI, CircleCI, Jenkins, or similar CI/CD systems.
- Expertise in Terraform, CloudFormation, and securing infrastructure-as-code pipelines.
- Strong knowledge of application security, OWASP Top 10, and secure coding practices.
- Deep understanding of IAM, RBAC, zero-trust models, and encryption best practices.
- Experience operating in regulated environments such as HIPAA, SOC 2, HITRUST, or PCI.
- Strong scripting or programming skills in Python, Go, Ruby, or similar.
- Preferred experience in healthcare, pharmacy, fintech, or other regulated industries.
- Preferred experience scaling DevSecOps-owned resources from early stage to production scale.
- Preferred background in site reliability engineering or platform engineering.
- Security certifications such as CISSP, CISM, CCSP, or AWS/GCP cloud security certifications are preferred.
- Preferred experience with observability platforms and integrating security telemetry into monitoring systems.
- Applicants must be authorized to work for any employer in the United States.
Benefits
- Full-time benefits include dental, vision, medical plans, 401(k), life insurance, AD&D insurance, FSA, HSA, commuter benefits, short- and long-term disability insurance, supplemental insurance, legal insurance, an employee assistance program, home health testing kits, and a fertility medication discount program.
- Flexible vacation time, accrued paid sick time, 10 paid holidays, and eligible floating holidays are provided.
- Eligible employees receive eight weeks of paid parental leave, additional paid leave for the birthing parent, and four weeks of paid caregiver leave.
- Employees receive a monthly Lifestyle Spending Account allowance.
- Remote role limited to residents of Arizona, Arkansas, California, Colorado, Florida, Kansas, Maryland, Missouri, Nevada, New Jersey, New York, North Carolina, Oregon, Pennsylvania, South Carolina, Tennessee, Texas, Washington, and Wisconsin.
- Travel is not required, with travel expected up to 0% of the time.
- Application deadline is August 31, 2026.