JobBobsReal-time global job discoveryLive

DevSecOps Engineer

Claritas Rx · United States · 2026-08-28

Full-timemid-levelRemote
Apply on the employer's site

About this role

Who We Are
Claritas Rx uses AI and predictive modeling to help rare disease and specialty brands remove the barriers that keep patients from accessing and staying on the treatments they need. By uniting the most complete view of the patient journey with purpose-built technologies, we predict and resolve access challenges before they disrupt care, combining advanced analytics, real-world data, AI, and CRM capabilities to increase start and refill rates, reduce abandonment, and improve brand performance. Our mission is to ensure patients with chronic, life-threatening diseases receive the support that enables the greatest benefit from their therapy. Simply put, our promise is progress for every patient journey.
This is the opportunity to help shape a first-in-industry digital health solution alongside a team of mission-driven professionals. We were named one of Inc.'s Best Workplaces in 2025 and recognized on the Inc. 5000 list for two consecutive years (2025 and 2026), and our team genuinely respects and supports each other. We thrive on being fast-paced, innovative, and results-driven, and our employees enjoy a flexible, collaborative work environment, unlimited PTO, stock options, and a growing set of tools and technology to drive innovation for our customers.
The Position
We are seeking a skilled and hands-on DevSecOps professional to join our Engineering team. Reporting to the Sr. Manager, Site Reliability, you will be a key individual contributor responsible for protecting the confidentiality, integrity, and availability of Claritas Rx's AWS-hosted SaaS platform — a system that processes sensitive patient and commercial data for some of the world's leading biopharmaceutical companies.
In this role, you will own day-to-day security engineering work: hardening infrastructure, managing vulnerability programs, responding to security events, and embedding security practices into the software development lifecycle. You will work closely with Software Engineering, SRE, and external compliance partners to ensure our platform maintains the rigorous compliance posture our customers and regulators require — including HIPAA, SOC 2 Type II, and HITRUST.
This is a high-impact individual contributor role suited to an engineer who thrives at the intersection of security and cloud infrastructure, takes ownership of outcomes, and brings a builder's mindset to security problems. The role is primarily remote with occasional travel requirements.
Key Accountabilities
Security Monitoring & Incident Response

• Own security monitoring across the platform: tune and triage alerts from AWS GuardDuty, Security Hub, CloudTrail, and related tooling to distinguish signal from noise and surface actionable threats.

• Serve as a primary responder for security incidents — investigate, contain, and remediate threats; document findings; and drive post-incident reviews with clear corrective actions.

• Maintain and continuously improve detection capabilities, including log analysis pipelines, alert rules, and correlation logic, to reduce mean time to detect (MTTD) and mean time to respond (MTTR).

• Participate in on-call rotation for security events, with appropriate escalation paths and runbooks in place.

Cloud Security Engineering

• Design, implement, and maintain security controls across the AWS environment — including IAM policies, SCPs, KMS key management, VPC security, WAF rulesets, and network segmentation.

• Conduct regular reviews of cloud configurations using AWS Config, Inspector, Macie, and third-party tooling; remediate findings and track resolution to closure.

• Partner with the SRE team to ensure infrastructure-as-code (AWS CDK) templates follow security best practices and that security controls are version-controlled, auditable, and reproducible.

• Evaluate new AWS services and architectural changes for security implications, providing clear guidance to engineering teams before and during adoption.

• Implement security focused observability patterns to detect threats as they emerge.

Vulnerability Management

• Support the vulnerability management lifecycle: asset discovery, scanning (infrastructure and application), risk-based prioritization, remediation tracking, and reporting.

• Coordinate with Software Engineering to integrate SAST, DAST, dependency scanning, and container image scanning into CI/CD pipelines (GitHub Actions), ensuring vulnerabilities are caught early in the SDLC.

• Track and communicate vulnerability metrics to engineering and leadership, balancing remediation urgency against engineering capacity.

• Research emerging threats, CVEs, and attacker techniques relevant to our technology stack and cloud environment; translate findings into actionable defensive improvements.

Compliance & Data Protection

• Support the maintenance and continuous improvement of Claritas Rx's HIPAA, SOC 2 Type II, and HITRUST compliance programs — including evidence collection, control testing, and gap remediation.

• Ensure PHI handling practices — at rest, in transit, and in processing — meet regulatory requirements; identify and close gaps in data classification, encryption, access control, and audit logging.

• Maintain and test data protection controls including encryption key management, secrets rotation (via AWS Secrets Manager), and DLP measures.

• Support external audits and assessments: prepare evidence packages, respond to auditor inquiries, and track audit findings through remediation.

• Contribute to the development and maintenance of security policies, standards, and procedures.

Identity & Access Management

• Administer and continuously refine AWS IAM roles, policies, and permission boundaries, applying least-privilege principles across all environments.

• Manage access lifecycle processes: provisioning, periodic access reviews, and de-provisioning for human and machine identities.

• Evaluate and improve authentication and authorization controls — including MFA enforcement, SSO…

Skills asked for

Similar jobs

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.