DevSecOps Engineer
# DevSecOps Engineer **HK TECH** · Utah · `On-site` 🕒 **Статус:** *Опубликовано: 5 дней назад* · *Источник: Indeed* --- ### About the Role DevSecOps Engineer Security engineering, detection and compliance evidence for a HIPAA-regulated public-health data platform · Remote (U.S.) We're looking for a DevSecOps engineer to make a new AWS platform for rural health data provably secure, from the first guardrail to the pre-go-live penetration test. You'll turn the contract's control list into enforced configuration and continuous evidence for the project, a cloud-based, open-source semantic data model. The project will harmonize EHR, claims and public-health data into one computable form and serve it through FHIR APIs. The platform holds protected health information. It is held to NIST SP 800-53 moderate controls and the HIPAA Security Rule, with a seven-year tamper-evident audit log, quarterly vulnerability scanning and annual penetration testing. You'll be the engineering half of the HIPAA program, working alongside a senior platform engineer, with the HIPAA Security Officer as the accountable half. THE ROLE AT A GLANCE Engagement 1099 independent contractor; you work as part of HK's team Term Mid-October 2026 through September 2027; a second year is possible, subject to funding Commitment Full time, 40 hours a week Reports to HK's Software/Development Director, with security direction from the HIPAA Security Officer and architecture direction from the program architect Location Remote within the U.S.; core hours 9:00 a.m.–3:00 p.m. Mountain; occasional travel to Salt Lake City Requirements U.S. work authorization; background check before production access; HIPAA training before any access Stack AWS Organizations and SCPs, IAM Identity Center, KMS, CloudTrail, Config, GuardDuty, Security Hub, Inspector, WAF; EKS with Kyverno; Keycloak; OpenSearch; OpenTofu; GitOps WHAT YOU'LL DO You take the platform from its first service control policy to a passed pre-go-live penetration test in March, and you're the person who can show an assessor the evidence for every control. - Write the guardrails: service control policies (no public ingress, no unencrypted storage, no disabling of logging or security services, region restriction), AWS Config conformance packs for NIST 800-53 Rev 5 and HIPAA, Kyverno admission policies, and OpenTofu policy gates in CI. - Own identity and access: IAM Identity Center permission sets, MFA and FIDO2 for privileged roles, Keycloak realm security, service-account and OIDC trust design, the break-glass procedure and the quarterly access review. - Build the SIEM: CloudTrail, GuardDuty (including EKS runtime), Security Hub, Inspector, Config, VPC Flow, EKS audit, WAF, Keycloak and application logs into OpenSearch. You'll write Sigma-style detections (impossible travel, bulk-export anomalies, privilege escalation, root use, policy changes) and tune alerting. - Protect the audit trail: design and verify, with the backend team, a tamper-evident FHIR audit chain (Kafka audit topic, Merkle-chained blocks, S3 Object Lock in compliance mode for seven years) and its nightly verification job. - Manage vulnerabilities: Inspector and Trivy in CI, an authenticated quarterly scan, patch SLAs and a remediation tracker. You'll scope, host and remediate the pre-go-live third-party penetration test and the second annual test. - Prepare for incidents: write the incident-response runbooks (severity model, containment, evidence preservation, the Clients's 24-hour notice and HIPAA breach-clock procedures), run the pre-go-live tabletop exercise, and take on-call for severity-1 incidents. - Keep the evidence: lead the technical half of the annual HIPAA risk analysis, file monthly Security Hub, Config and GuardDuty exports, access-review sign-offs and restore results by NIST 800-53 control family, and keep the System Security Plan current and OSCAL-ready. - Secure the supply chain and the data: distroless, pinned images, cosign signing, an SBOM per release, dependency and license checks; KMS and Secrets Manager rotation, PHI bucket tagging and TLS on Aurora and MSK. You'll be able to cover the platform engineer's on-call, and they yours. YOUR FIRST 30 DAYS The first three weeks are the critical path for the whole program. You'll pair with the platform engineer to stand up the landing zone, with security built in from day one rather than added later. Week What success looks like Week 1 SCPs, org-wide CloudTrail with Object Lock and Config conformance packs live; GuardDuty, Security Hub and Inspector delegated to the security account; KMS key policies reviewed Week 2 Identity Center and Keycloak MFA/FIDO2 enforced; break-glass procedure written; first Security Hub baseline score exported to the evidence folder Week 3 OpenSearch SIEM receiving the core log sources; first detection rules; CI scanning, signing and SBOM gates; evidence folders organized by control family Week 4 Network and KMS review against the architecture written up; risk-analysis workshop scheduled; penetration-test vendor shortlist WHAT YOU BRING - 5+ years in security engineering or DevSecOps on AWS, including 2+ years in a HIPAA, FedRAMP, StateRAMP or similarly regulated environment. - Working knowledge of NIST SP 800-53 Rev 5 and the HIPAA Security Rule. You've produced control evidence for an assessor or auditor before. - AWS security services in depth: Organizations and SCPs, IAM Identity Center, KMS, CloudTrail, Config, GuardDuty, Security Hub, Inspector and WAF, including Security Hub standards and conformance packs. - SIEM and detection engineering: OpenSearch Security Analytics, Elastic, Splunk or Sentinel; log pipelines, Sigma rules and alert tuning. - Kubernetes security: pod security standards, network policies, admission control (Kyverno or Gatekeeper), image signing and runtime detection. - Terraform or OpenTofu and policy as code, and enough Java or Kotlin to review security-relevant code. - You've run vulnerability management and a penetration test end to end, and you write precise policies, runbooks, risk analyses and assessor responses. NICE TO HAVE - FHIR or healthcare integration security: SMART on FHIR scopes, Bulk Data, HL7 v2 over VPN or mTLS; 42 CFR Part 2 handling. - Tamper-evident logging designs: Merkle chains, S3 Object Lock compliance mode, ledger databases. - OSCAL and System Security Plan authoring; CMMC or StateRAMP assessments. - CISSP, AWS Security Specialty, CKS or a GIAC cloud security certification. - Write the incident-response runbooks (severity model, containment, evidence preservation, 24-hour notice and HIPAA breach-clock procedures), run the pre-go-live tabletop exercise, and take on-call for severity-1 incidents.
Наблюдалась 2026-10-07, впервые 2026-10-01, источник — Indeed.