- Company Name
- Skin Analytics
- Job Title
- DevOps Engineer (Security Operations)
- Job Description
-
**Job Title:**
DevOps Engineer (Security Operations)
**Role Summary:**
Lead the design, implementation, and management of secure, compliant DevOps workflows for regulated clinical software (SaMD). Own SecOps across AWS infrastructure, CI/CD pipelines, and developer environments, ensuring adherence to ISO 27001, IEC 62304, and related standards while enabling rapid, reliable delivery.
**Expectations:**
- **First 3 months:** Complete access audits, enforce MFA and least‑privilege access, remediate top 5 security risks, fully integrate Snyk with automated alerts.
- **First 6 months:** Mature pipelines with automated tests, security gates, and gated deployments across all services.
- **First 12 months:** Deploy full‑stack observability with ELK‑based dashboards, anomaly detection, and alerting for security and reliability.
**Key Responsibilities:**
- Manage secure AWS infrastructure (EC2, S3, RDS, IAM, VPC, Lambda, etc.) using Terraform and Ansible.
- Design, build, and maintain Docker‑first CI/CD pipelines in Bitbucket (or equivalent) with automated security scanning (Snyk, container, IaC).
- Develop and enforce SOPs for secure deployment and incident response aligned to ISO 27001 and IEC 62304.
- Conduct threat modeling, risk remediation, and compliance automation (HIPAA, MDR).
- Extend observability via CloudWatch, ELK stack dashboards, and automated alerting.
- Support transformation team on client security queries during onboarding and deployment.
- Produce documentation, audit evidence, and participate in regulatory submissions.
**Required Skills:**
- Deep expertise in AWS services (EC2, S3, RDS, IAM, VPC, CloudWatch, CloudTrail, Lambda, SQS/SNS).
- Strong infrastructure‑as‑code skills with Terraform and Ansible.
- CI/CD pipeline development (Bitbucket Pipelines or similar) with multi‑stage, gated deployments.
- Security operations experience: Snyk, IAM policies, zero‑trust, MFA, secrets management, threat modeling.
- Automation of compliance requirements (ISO 27001, IEC 62304, HIPAA, MDR).
- Proficiency with Docker, container image scanning, and artifact management.
- Monitoring/observability: CloudWatch, ELK stack, dashboard creation, anomaly detection.
- Networking knowledge: VPCs, subnets, routing, security groups, NACLs, Route 53, load balancers.
- Experience securing Node.js, React, and Docker‑based applications.
- Strong communication, ownership, and collaborative mindset.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Engineering, or a related technical field (or equivalent experience).
- Relevant certifications preferred: AWS Certified Solutions Architect/DevOps Engineer, Terraform Certified Associate, Security‑focused certifications (e.g., CISSP, CISM, ISO 27001 Lead Auditor).