698,241open jobs
41,057companies
105,127added this week
Browse all
Salary
$168k – $205k per year
Location
Remote/Hybrid (San Francisco, United States)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
AI platform connecting patients to clinical trials. Activate providers, identify eligible patients, and navigate them through trials across health systems.

About the role

Join our small, high-trust Infrastructure team as its second engineer, reporting to the Director of Infrastructure and partnering closely with our product engineering team. You will drive two key initiatives: building a cohesive AWS foundation with Terraform, Control Tower, and AFT, and owning end-to-end security engineering for our production PHI and Bedrock AI workloads. Just as important, you'll build the paved paths, self-service tooling, and guardrails that let our engineers ship quickly.

AI is deeply embedded in how we work. We use it across coding, testing, and operations, not because of a mandate but because we've seen what it unlocks. We're looking for someone who already builds this way and is curious about what AI-augmented practice looks like in infrastructure and security work. We value fast decisions, open feedback, and empowered engineers.

Your Responsibilities

    What you'll own

  • Infrastructure as code. The Terraform codebase - module design, state strategy, drift detection, plan review discipline - and the migration of our CloudFormation/Serverless footprint where it delivers real leverage, without stalling product delivery.

  • The AWS landing zone. Multi-account structure via Control Tower and AFT: account vending, customizations, service control policies, and OU design.

  • Security engineering. Security Hub, GuardDuty, Inspector, and Config as living detection tooling: triage findings, tune signals, and run the vulnerability lifecycle from discovery through verified fix. Coordinate penetration tests and own remediation.

  • Pipeline and supply chain security. Secure the commit-to-production path in GitHub Actions: least-privilege OIDC deployment roles, secrets scanning, SAST and dependency/container gates, branch protection, and artifact integrity.

  • Developer enablement. Paved-path tooling, self-service infrastructure, and secure defaults that let product engineers move fast without filing tickets.

  • Disaster recovery and backup. Backup strategy, RPO/RTO targets, Aurora point-in-time recovery, and regular DR testing to satisfy HIPAA contingency planning requirements.

  • Compliance as code. SOC 2 and HIPAA controls encoded into the platform - encryption, KMS, CloudTrail/Config coverage, log retention - with automated evidence collection.

  • Identity and access governance. IAM Identity Center, cross-account roles, SSO, periodic access reviews, and joiner/mover/leaver deprovisioning, alongside network foundations: VPC design, WAF, and Client VPN.

  • Where you'll contribute

    Alongside the Director of Infrastructure and the Dev Team:

  • Security architecture for Bedrock AI workloads: access controls, guardrails, PHI data boundaries

  • Production incident response (reliability and security) and recurrence prevention

  • Observability and cost visibility: CloudWatch, alarms, dashboards, tagging

  • Partnership with application engineers on Lambda, Aurora PostgreSQL, and Bedrock workloads

  • Lightweight threat modeling and security review of new features and third-party integrations touching PHI, including sponsor/CRO data-handling requirements

Your Requirements

  • 5+ years in DevSecOps, security, platform, or infrastructure engineering, operating production systems you were accountable for

  • Demonstrated security ownership: you have run vulnerability management, remediated real findings, and participated in incident response - not just deployed tooling

  • Deep Terraform proficiency: module hierarchies, multi-environment state, drift and refactors, critical plan review

  • Hands-on AFT and Control Tower experience - you have vended accounts through AFT and customized the pipeline, not adjacent familiarity

  • Broad AWS depth: IAM, Organizations, VPC, Lambda, RDS/Aurora, S3, KMS, CloudTrail, Config, Security Hub, GuardDuty, Secrets Manager

  • GitHub Actions as a daily environment, including pipeline hardening and secrets management

  • SOC 2 Type II and HIPAA experience in a real PHI-handling environment - you have owned controls, produced evidence, and sat in front of an auditor

  • Change and release discipline: you think about blast radius before you apply, have owned deployment and rollback strategies in production, and move quickly inside regulated-environment constraints rather than treating them as obstacles

  • Hands-on, autonomous, and clear: you write code daily, take ambiguous problems to documented decisions, and can explain security tradeoffs to non-security people

  • You use AI coding and automation tools as a daily part of how you work, and you actively explore how they change infrastructure and security practices

  • Genuine interest in improving clinical trial access and health equity

Nice to Have

  • Compliance automation platforms (Drata, Vanta) including evidence automation

  • CloudFormation/CDK/Serverless-to-Terraform migration experience

  • GitHub EMU, SCIM, and SAML SSO administration

  • Aurora PostgreSQL operations and schema migration coordination

  • Python or TypeScript for automation

  • HITRUST, NIST 800-53, or CSA STAR exposure

  • Securing LLM workloads

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
698,241 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Francisco
AI Platform Engineer 6 hours ago
$89k – $230k per year (Estimated) • Remote • 3+ years exp
Python
Go
Bash
AI/ML
Copilot
Cursor
Claude
AI Agents
LLM
RAG
Agentic Workflows
DevOps
Terraform
GCP
CloudFormation
Pulumi
Azure
CI/CD
Git
AWS
Docker
Kubernetes
FinOps
Incident Management
GitHub
IAM
Linux
Unix
Apply
AI Platform Engineer 6 hours ago
$94k – $243k per year (Estimated) • Remote • 3+ years exp
Python
Go
Bash
AI/ML
Copilot
Cursor
Claude
AI Agents
LLM
RAG
Agentic Workflows
DevOps
Terraform
GCP
CloudFormation
Pulumi
Azure
CI/CD
Git
AWS
Docker
Kubernetes
FinOps
Incident Management
GitHub
IAM
Linux
Unix
Apply
$117k – $242k per year (Estimated) • Remote • 8+ years exp
DevOps
Terraform
Ansible
CloudFormation
Azure
AWS
Platform Engineering
IAM
Apply
$107k – $201k per year • Equity 0.2–0.8% • In office • Full-Time • 1+ year exp • London
TypeScript
Databases
PostgreSQL
AI/ML
Red Teaming
Edge AI
Browser Agents
DevOps
Linux
Windows
Cybersecurity
Okta
ISO 27001
OWASP Top 10
SOC 2
Zero Trust
Microsoft Entra ID
Apply
$80k – $161k per year • Equity 0.2–0.8% • In office • Full-Time • 1+ year exp • London
TypeScript
Databases
PostgreSQL
AI/ML
Browser Agents
DevOps
Linux
Windows
Cybersecurity
Okta
Zero Trust
Microsoft Entra ID
QA
Selenium
Apply
$108k – $135k per year • Remote/Hybrid • Full-Time • San Francisco
Marketing
Salesforce
Apply
$58k – $78k per year • Remote • Contractor • 2+ years exp
Marketing
Salesforce
LinkedIn
Apply
$120k – $150k per year • Remote/Hybrid • Full-Time • 3+ years exp • San Francisco
Marketing
Salesforce
Apply
Staff Data Engineer 1 month ago
$168k – $230k per year • Remote/Hybrid • Full-Time • 8+ years exp • San Francisco
Python
TypeScript
SQL
Databases
PostgreSQL
AI/ML
AWS Bedrock
DevOps
Terraform
Pulumi
AWS
AWS Fargate
AWS Lambda
Cybersecurity
HIPAA
Management
Slack
Apply
$120k – $150k per year • Remote/Hybrid • Full-Time • 10+ years exp • San Francisco
Marketing
Salesforce
Apply
Account Executive 5 min ago
$150k – $250k per year • In office • Full-Time • 3+ years exp • San Francisco
Marketing
LinkedIn
Apply
$100k – $120k per year • In office • Full-Time • 3+ years exp • San Francisco
Marketing
LinkedIn
Apply
$55k – $120k per year • In office • Full-Time • San Francisco
Marketing
LinkedIn
Apply
$100k – $200k per year • Equity 0.1–2% • In office • Full-Time • San Francisco
Python
JavaScript
TypeScript
AI/ML
LLM
OpenAI
Anthropic
Frontend
React.js
Apply
$120k – $200k per year • Equity 0.5–2% • Remote/Hybrid • Full-Time • 6+ years exp • San Francisco
AI/ML
Prompt Engineering
Apply
See all jobs
This is one of many
698,241 more open roles from verified company boards, updated every day.