Claritas Rx logo
Claritas Rx
Posted 43 days agoVerified live 1d ago

DevSecOps Engineer

Brief overview

Remote
UndergradOr in progress
$130k–$160k/yrStated range
4+ yrsMinimum
7 H-1B approvalsDept. of Labor
1 green cardsCertified filings
AWS Cloud SecurityAWS Identity and Access Management (IAM)Vulnerability ManagementCloud Security Incident ResponseCI/CD Security IntegrationHIPAA, SOC 2, and HITRUST CompliancePythonBashThreat ModelingPenetration TestingPrivileged Access ManagementSecrets ManagementWritten and Verbal Communication

About the company

Claritas Rx logo
Claritas Rxclaritasrx.com

Provides data analytics for specialty biopharmaceutical patient journeys.

Visa sponsorship history

3 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
7H-1B approved
100%approval rate
2new H-1B hires
1PERM certified
$215,000median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20242
20254
20261
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20261
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20251
Top sponsored roles
Data Quality and Operations Scientist

Job description

Summary

Claritas Rx uses AI, predictive modeling, advanced analytics, real-world data, and CRM capabilities to help rare disease and specialty brands improve patient access and treatment adherence. The DevSecOps Engineer will protect the confidentiality, integrity, and availability of the company’s AWS-hosted SaaS platform by managing security monitoring, cloud security engineering, vulnerability management, compliance, identity and access management, and security practices across the software development lifecycle.

Responsibilities

  • Own security monitoring across the platform: tune and triage alerts from AWS GuardDuty, Security Hub, CloudTrail, and related tooling to distinguish signal from noise and surface actionable threats
  • Serve as a primary responder for security incidents — investigate, contain, and remediate threats; document findings; and drive post-incident reviews with clear corrective actions
  • Maintain and continuously improve detection capabilities, including log analysis pipelines, alert rules, and correlation logic, to reduce mean time to detect (MTTD) and mean time to respond (MTTR)
  • Participate in on-call rotation for security events, with appropriate escalation paths and runbooks in place
  • Design, implement, and maintain security controls across the AWS environment — including IAM policies, SCPs, KMS key management, VPC security, WAF rulesets, and network segmentation
  • Conduct regular reviews of cloud configurations using AWS Config, Inspector, Macie, and third-party tooling; remediate findings and track resolution to closure
  • Partner with the SRE team to ensure infrastructure-as-code (AWS CDK) templates follow security best practices and that security controls are version-controlled, auditable, and reproducible
  • Evaluate new AWS services and architectural changes for security implications, providing clear guidance to engineering teams before and during adoption
  • Implement security focused observability patterns to detect threats as they emerge
  • Support the vulnerability management lifecycle: asset discovery, scanning (infrastructure and application), risk-based prioritization, remediation tracking, and reporting
  • Coordinate with Software Engineering to integrate SAST, DAST, dependency scanning, and container image scanning into CI/CD pipelines (GitHub Actions), ensuring vulnerabilities are caught early in the SDLC
  • Track and communicate vulnerability metrics to engineering and leadership, balancing remediation urgency against engineering capacity
  • Research emerging threats, CVEs, and attacker techniques relevant to our technology stack and cloud environment; translate findings into actionable defensive improvements
  • Support the maintenance and continuous improvement of Claritas Rx's HIPAA, SOC 2 Type II, and HITRUST compliance programs — including evidence collection, control testing, and gap remediation
  • Ensure PHI handling practices — at rest, in transit, and in processing — meet regulatory requirements; identify and close gaps in data classification, encryption, access control, and audit logging
  • Maintain and test data protection controls including encryption key management, secrets rotation (via AWS Secrets Manager), and DLP measures
  • Support external audits and assessments: prepare evidence packages, respond to auditor inquiries, and track audit findings through remediation
  • Contribute to the development and maintenance of security policies, standards, and procedures
  • Administer and continuously refine AWS IAM roles, policies, and permission boundaries, applying least-privilege principles across all environments
  • Manage access lifecycle processes: provisioning, periodic access reviews, and de-provisioning for human and machine identities
  • Evaluate and improve authentication and authorization controls — including MFA enforcement, SSO integration, and privileged access management
  • Collaborate with SRE and Software Engineering to embed security requirements into production readiness reviews, architecture decisions, and deployment processes
  • Serve as a trusted security resource for engineering teams — providing practical, risk-informed guidance rather than purely compliance-driven mandates
  • Communicate security risks and program status clearly to both technical peers and non-technical stakeholders, including leadership

Skills

  • • 4+ years of experience in information security engineering, cloud security, or a closely related discipline with hands-on technical ownership
  • • Solid, practical AWS security expertise — you understand IAM, KMS, VPC security, CloudTrail, GuardDuty, Security Hub, Config, and WAF at a working level, not just conceptually
  • • Experience operating a vulnerability management program: scanning, prioritization, tracking, and reporting across infrastructure and application layers
  • • Demonstrated ability to respond to and investigate security incidents in a cloud environment — from initial triage through containment, root cause analysis, and corrective action
  • • Familiarity with integrating security tooling (SAST, DAST, dependency scanning, container scanning) into CI/CD pipelines and developer workflows
  • • Working knowledge of HIPAA, SOC 2, and/or HITRUST requirements as they apply to technical controls — you understand what compliance requires and how to implement it in an engineering context
  • • Scripting proficiency in Python, Bash, or equivalent for automating security tasks, log analysis, and tooling integrations
  • • Strong written and verbal communication skills — you can explain security risk and technical trade-offs clearly to both engineering peers and non-technical stakeholders
  • • Collaborative, team-oriented mindset with the ability to influence security outcomes without direct authority
  • • Comfort operating independently in a fast-paced, high-growth startup environment where priorities shift and initiative is expected
  • • Experience in a healthcare technology or digital health environment with direct exposure to HIPAA-regulated PHI and the controls required to protect it
  • • Hands-on experience with threat modeling methodologies (e.g., STRIDE, PASTA) applied to cloud-native application architectures
  • • Familiarity with penetration testing concepts and experience participating in or coordinating third-party security assessments
  • • Experience with privileged access management (PAM) tooling and secrets management at scale
  • • Exposure to the Claritas Rx application stack: TypeScript, NestJS, PostgreSQL, React
  • • Experience leveraging AI tools (including Claude) to accelerate threat hunting, automate security documentation, or streamline compliance evidence workflows
  • • Relevant certifications such as AWS Security Specialty, CISSP, CISM, CEH, OSCP, CompTIA Security+, or equivalent
  • • B.S. in Computer Science, Information Security, or a related discipline, or equivalent practical experience

Qualifications

Must Haves

  • • 4+ years of experience in information security engineering, cloud security, or a closely related discipline with hands-on technical ownership
  • • Solid, practical AWS security expertise — you understand IAM, KMS, VPC security, CloudTrail, GuardDuty, Security Hub, Config, and WAF at a working level, not just conceptually
  • • Experience operating a vulnerability management program: scanning, prioritization, tracking, and reporting across infrastructure and application layers
  • • Demonstrated ability to respond to and investigate security incidents in a cloud environment — from initial triage through containment, root cause analysis, and corrective action
  • • Familiarity with integrating security tooling (SAST, DAST, dependency scanning, container scanning) into CI/CD pipelines and developer workflows
  • • Working knowledge of HIPAA, SOC 2, and/or HITRUST requirements as they apply to technical controls — you understand what compliance requires and how to implement it in an engineering context
  • • Scripting proficiency in Python, Bash, or equivalent for automating security tasks, log analysis, and tooling integrations
  • • Strong written and verbal communication skills — you can explain security risk and technical trade-offs clearly to both engineering peers and non-technical stakeholders
  • • Collaborative, team-oriented mindset with the ability to influence security outcomes without direct authority
  • • Comfort operating independently in a fast-paced, high-growth startup environment where priorities shift and initiative is expected

Nice to Haves

  • • Experience in a healthcare technology or digital health environment with direct exposure to HIPAA-regulated PHI and the controls required to protect it
  • • Hands-on experience with threat modeling methodologies (e.g., STRIDE, PASTA) applied to cloud-native application architectures
  • • Familiarity with penetration testing concepts and experience participating in or coordinating third-party security assessments
  • • Experience with privileged access management (PAM) tooling and secrets management at scale
  • • Exposure to the Claritas Rx application stack: TypeScript, NestJS, PostgreSQL, React
  • • Experience leveraging AI tools (including Claude) to accelerate threat hunting, automate security documentation, or streamline compliance evidence workflows
  • • Relevant certifications such as AWS Security Specialty, CISSP, CISM, CEH, OSCP, CompTIA Security+, or equivalent
  • • B.S. in Computer Science, Information Security, or a related discipline, or equivalent practical experience

Benefits

  • Flexible, collaborative work environment
  • Unlimited PTO
  • Stock options
  • A growing set of tools and technology to drive innovation for our customers
  • Primarily remote work arrangement
  • Regional town hall gatherings approximately every other month for employees within a reasonable driving distance of each other
  • Employee equipment provided directly by Claritas Rx; no purchases required

More jobs like this