Direct Meds LLC is a fast-growing national team focused on transforming healthcare access. They are seeking a Senior DevSecOps Engineer to own the full security lifecycle of their platform, ensuring compliance with regulations like HIPAA while automating security checks in their development processes.
Responsibilities:
- Define and enforce our approach to handling PHI, making HIPAA adherence a non-negotiable part of every system we build or update
- Build robust CI/CD pipelines that aren't just deploy code; they automatically inject security checks—from vulnerable scanning to compliance verification and ensuring least-privilege access at every single step
- Lead design and code reviews, proactively identifying architectural weak points or compliance risks before they become problems in production
- Keep our core platforms running smoothly by continually hardening them, establishing security baselines, and maintaining thorough documentation to ensure we are always audit-ready
Requirements:
- Experience in DevSecOps practices and principles
- Strong understanding of security compliance, particularly HIPAA
- Proficiency in building CI/CD pipelines with integrated security checks
- Ability to lead design and code reviews
- Experience in identifying architectural weak points or compliance risks
- Skills in hardening platforms and establishing security baselines
- Strong documentation skills to maintain audit readiness