{"id":1645890,"url":"https://alion.io/job/gifthealth-devsecops-engineer","title":"DevSecOps Engineer","company":{"id":3854482,"name":"Gifthealth","domain":"gifthealth.com","url":"https://alion.io/company/gifthealth","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Paylocity","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Columbus, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":115000,"max":165000,"currency":"USD","period":"year","gross":null,"usd_annual":165000},"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"CloudFormation","optional":false},{"name":"Dependabot","optional":false},{"name":"Heroku","optional":false},{"name":"Kubernetes","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"AWS","optional":true},{"name":"Brakeman","optional":true},{"name":"CodeQL","optional":true},{"name":"Git","optional":true},{"name":"GitHub","optional":true},{"name":"JavaScript","optional":true},{"name":"OWASP Top 10","optional":true},{"name":"PostgreSQL","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"Redis","optional":true},{"name":"Ruby","optional":true},{"name":"Ruby on Rails","optional":true},{"name":"Trunk-Based Development","optional":true}],"status":"live","first_seen_at":"2026-09-15T16:32:24Z","employer_posted_date":"2026-10-01","last_verified_at":"2026-10-03T17:45:57Z","board_verified":true,"closed_at":null,"days_open":18,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":18},"description":"Description\nAbout\nAt Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives.\nPosition Summary\nWe are seeking a DevSecOps Engineer to integrate security into the organization's software development and delivery processes. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.\nThis role partners closely with Software Engineering, Platform Engineering, DevOps, and Security teams to build security controls directly into CI/CD pipelines, development workflows, infrastructure-as-code, container environments, and application delivery processes. Rather than operating as a final security checkpoint, the DevSecOps Engineer helps engineering teams identify and address security issues earlier in the development lifecycle while building scalable security automation that allows teams to move quickly without sacrificing security.\nKey Responsibilities\nSecure Software Development:\nIntegrate security controls into the software development lifecycle.\nPartner with engineering teams to establish practical secure development standards.\nHelp developers identify and remediate application security vulnerabilities.\nProvide technical guidance on secure coding practices and common vulnerability classes.\nSupport security reviews for new applications, services, APIs, and major architectural changes.\nCI/CD Security:\nDesign and implement automated security testing within CI/CD pipelines.\nImplement and manage capabilities such as:\nStatic Application Security Testing (SAST)\nSoftware Composition Analysis (SCA)\nSecret scanning\nContainer image scanning\nInfrastructure-as-Code scanning\nDependency and package vulnerability detection\nDevelop appropriate security gates for build and deployment pipelines.\nReduce alert fatigue by correlating and de-duplicating vulnerability signals across Dependabot, Vanta, and Tenable, escalating only when standard remediation timelines are at risk of being missed.\nWork with engineering teams to ensure security controls minimize unnecessary friction.\nApplication and API Security:\nEvaluate applications and APIs for common security weaknesses.\nHelp establish secure API authentication and authorization patterns.\nSupport threat modeling for applications and new engineering initiatives.\nAssist engineering teams with remediation of application security findings.\nIdentify systemic security issues that can be addressed through reusable controls or engineering patterns.\nInfrastructure-as-Code and Automation:\nReview Terraform, CloudFormation, Kubernetes manifests, and similar infrastructure definitions for security risks.\nDevelop automated controls that detect insecure infrastructure configurations before deployment.\nCreate reusable secure infrastructure patterns and guardrails.\nBuild security automation using scripting, APIs, and cloud-native services.\nContainer and Kubernetes Security:\nHelp establish security standards for containers and Kubernetes environments.\nSupport container image security, workload configuration, secrets management, and runtime security.\nIdentify insecure deployment patterns and help engineering teams adopt safer alternatives.\nSupport the security review of the planned migration from Heroku to Render.com, including secrets handling, network posture, and changes to the deployment model.\nDesign a synthetic or de-identified data seeding strategy to enable Dynamic Application Security Testing (DAST) in staging without exposing PHI, currently a gap given the application's PHI-heavy data model.\nSecurity Architecture and Engineering Partnership:\nParticipate in architecture and design reviews.\nTranslate security requirements into technical controls engineering teams can implement.\nWork with Cloud Security and Security Operations to improve visibility into applications and workloads.\nHelp engineering teams understand and address security findings without becoming a bottleneck to delivery.\nMetrics and Continuous Improvement:\nTrack application and pipeline security findings through remediation.\nMeasure vulnerability trends, remediation times, security coverage, and adoption of secure development practices.\nIdentify opportunities to replace manual reviews with automated preventative controls.\nQualifications\nEducation: Not specified as a requirement; we evaluate demonstrated hands-on experience.\nLicensure/Certification: Not required. Relevant certifications in cloud, security, Kubernetes, or application security are a plus.\nExperience: 3+ years of experience in DevOps, DevSecOps, application security, platform engineering, software engineering, or security engineering.\nKnowledge, Skills, and Abilities:\nExperience with modern CI/CD systems and software delivery practices. Gifthealth's core application is a GitHub-hosted Rails repo using trunk-based development, with GitHub Advanced Security/CodeQL and Dependabot integrated into CI.\nExperience with modern application hosting platforms. Gifthealth's core application runs on Heroku (migrating to Render.com), with Crunchy Data for managed Postgres and a Redis instance hosted in AWS. Direct AWS/Kubernetes experience is a plus but not the primary environment today.\nWorking knowledge of application security, API security, GitHub Advanced Security/CodeQL, dependency and vulnerability alert triage (e.g., Dependabot), CI/CD pipelines, Infrastructure-as-Code, secrets management, and software supply chain security.\nExperience with scripting or programming using languages such as Python, Go, JavaScript, PowerShell, or Bash. Ruby experience is a strong plus, since GifthealthOS, the core application, is built on Ruby on Rails.\nExperience with Git-based development workflows and the ability to work directly with developers and engineering teams.\nDemonstrated application of the above Qualification\nPreferred: experience with Terraform, Kubernetes, or container orchestration. Gifthealth's core application runs on Heroku today (migrating to Render.com), not Kubernetes.\nPreferred: experience with Rails-specific security tooling such as Brakeman for SAST and bundler-audit or Dependabot for dependency scanning, given GifthealthOS's Ruby on Rails stack.\nPreferred: experience implementing SAST, SCA, secrets scanning, or IaC security tools. Gifthealth uses GitHub Advanced Security/CodeQL for SAST and Dependabot for dependency scanning.\nPreferred: familiarity with the OWASP Top 10 and common application vulnerability classes, cloud-native security services, and threat modeling methodologies.\nPreferred: understanding of identity, authentication, authorization, and secrets management, and experience working within regulated environments.\nMeasures of Success\nSuccess in this role includes:\nSecurity testing becomes consistently integrated into engineering pipelines.\nSecurity vulnerabilities are identified earlier in the development lifecycle.\nEngineering teams have clear, usable guidance for resolving security findings.\nReusable security controls reduce reliance on manual security reviews.\nCritical security issues can prevent unsafe deployments without creating excessive development friction.\nApplication and software supply chain risks are measurable and actively managed.\nSecure development practices become part of normal engineering workflows.\nWork Environment\nLocation: Not specified in the source job description; to be confirmed with the hiring manager.\nSchedule: Full-time; standard business hours.\nMay require flexibility for security-critical deployment reviews or urgent remediation timelines.\nRegular collaboration with Software Engineering, Platform Engineering, DevOps, and Security teams to ensure alignment.\nKey Essential Functions\nMust be able to work at a computer for extended periods\nMust be able to communicate effectively, verbally and in writing, with engineering and security stakeholders\nMust be able to handle and access sensitive security and system data in compliance with organizational data handling requirements\nMust be able to respond to critical security or deployment issues outside standard working hours when required\nEmployment Classification\nStatus: Full-time\nFLSA: Exempt\nEqual Employment Opportunity (EEO) Statement\nGifthealth is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. All employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, transgender status, national origin, age, disability, veteran status, or any other legally protected status.\nWe celebrate diversity and are committed to creating an inclusive environment for all employees. If you do not meet every requirement but still feel you would be a great fit for this role, we encourage you to apply!\nDisclaimer\nThis job description is intended to describe the general nature and level of work being performed. It is not intended to be an exhaustive list of all responsibilities, duties, or skills required of personnel. Gifthealth reserves the right to modify job duties or descriptions at any time.\nSalary Description\n$115,000-$165,000","description_format":"text","description_chars":9457,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps"],"lifecycle":[{"event":"open","at":"2026-10-01T23:37:38Z"}],"visa":[],"liveness":{"score":52,"band":"ok","label":"Likely open","p_open":1,"p_active":0.697,"p_room":0.75,"age_days":17,"expected_fill_days":19,"reasons":["conf:0","velocity","win:late"],"computed_at":"2026-10-03T05:45:00Z"},"pay":{"stated_usd_annual":165000,"is_top_pay":true},"html_url":"https://alion.io/job/gifthealth-devsecops-engineer","json_url":"https://alion.io/job/gifthealth-devsecops-engineer.json","meta":{"generated_at":"2026-10-04T01:07:28Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1424,"day_limit":5000,"remaining_today":3576,"minute_limit":60,"resets_at":"2026-10-05T00:00:00Z"}}}