DevSecOps / Cloud Engineer

Trial LibrarySan Francisco, CA
$168,000 - $205,000Hybrid

About The Position

Trial Library is an AI-native research platform with a mission to improve healthcare outcomes by expanding access to precision medicine. Trial Library is an AI-native enrollment and care navigation platform that accelerates access to precision medicine. In collaboration with biopharmaceutical manufacturers, payers, and health systems, Trial Library enables the delivery of clinical trials as a standard care option - improving patient access, advancing oncology outcomes, and reducing the total cost of care. Backed by leading healthcare venture capital firms, Trial Library’s platform is currently deployed in 840+ clinics and 3,000+ providers nationwide. Join our small, high-trust Infrastructure team as its second engineer, reporting to the Director of Infrastructure and partnering closely with our product engineering team. You will drive two key initiatives: building a cohesive AWS foundation with Terraform, Control Tower, and AFT, and owning end-to-end security engineering for our production PHI and Bedrock AI workloads. Just as important, you'll build the paved paths, self-service tooling, and guardrails that let our engineers ship quickly. AI is deeply embedded in how we work. We use it across coding, testing, and operations, not because of a mandate but because we've seen what it unlocks. We're looking for someone who already builds this way and is curious about what AI-augmented practice looks like in infrastructure and security work. We value fast decisions, open feedback, and empowered engineers.

Requirements

  • 5+ years in DevSecOps, security, platform, or infrastructure engineering, operating production systems you were accountable for
  • Demonstrated security ownership: you have run vulnerability management, remediated real findings, and participated in incident response - not just deployed tooling
  • Deep Terraform proficiency: module hierarchies, multi-environment state, drift and refactors, critical plan review
  • Hands-on AFT and Control Tower experience - you have vended accounts through AFT and customized the pipeline, not adjacent familiarity
  • Broad AWS depth: IAM, Organizations, VPC, Lambda, RDS/Aurora, S3, KMS, CloudTrail, Config, Security Hub, GuardDuty, Secrets Manager
  • GitHub Actions as a daily environment, including pipeline hardening and secrets management
  • SOC 2 Type II and HIPAA experience in a real PHI-handling environment - you have owned controls, produced evidence, and sat in front of an auditor
  • Change and release discipline: you think about blast radius before you apply, have owned deployment and rollback strategies in production, and move quickly inside regulated-environment constraints rather than treating them as obstacles
  • Hands-on, autonomous, and clear: you write code daily, take ambiguous problems to documented decisions, and can explain security tradeoffs to non-security people
  • You use AI coding and automation tools as a daily part of how you work, and you actively explore how they change infrastructure and security practices
  • Genuine interest in improving clinical trial access and health equity

Nice To Haves

  • Compliance automation platforms (Drata, Vanta) including evidence automation
  • CloudFormation/CDK/Serverless-to-Terraform migration experience
  • GitHub EMU, SCIM, and SAML SSO administration
  • Aurora PostgreSQL operations and schema migration coordination
  • Python or TypeScript for automation
  • HITRUST, NIST 800-53, or CSA STAR exposure
  • Securing LLM workloads

Responsibilities

  • Infrastructure as code. The Terraform codebase - module design, state strategy, drift detection, plan review discipline - and the migration of our CloudFormation/Serverless footprint where it delivers real leverage, without stalling product delivery.
  • The AWS landing zone. Multi-account structure via Control Tower and AFT: account vending, customizations, service control policies, and OU design.
  • Security engineering. Security Hub, GuardDuty, Inspector, and Config as living detection tooling: triage findings, tune signals, and run the vulnerability lifecycle from discovery through verified fix. Coordinate penetration tests and own remediation.
  • Pipeline and supply chain security. Secure the commit-to-production path in GitHub Actions: least-privilege OIDC deployment roles, secrets scanning, SAST and dependency/container gates, branch protection, and artifact integrity.
  • Developer enablement. Paved-path tooling, self-service infrastructure, and secure defaults that let product engineers move fast without filing tickets.
  • Disaster recovery and backup. Backup strategy, RPO/RTO targets, Aurora point-in-time recovery, and regular DR testing to satisfy HIPAA contingency planning requirements.
  • Compliance as code. SOC 2 and HIPAA controls encoded into the platform - encryption, KMS, CloudTrail/Config coverage, log retention - with automated evidence collection.
  • Identity and access governance. IAM Identity Center, cross-account roles, SSO, periodic access reviews, and joiner/mover/leaver deprovisioning, alongside network foundations: VPC design, WAF, and Client VPN.
  • Security architecture for Bedrock AI workloads: access controls, guardrails, PHI data boundaries
  • Production incident response (reliability and security) and recurrence prevention
  • Observability and cost visibility: CloudWatch, alarms, dashboards, tagging
  • Partnership with application engineers on Lambda, Aurora PostgreSQL, and Bedrock workloads
  • Lightweight threat modeling and security review of new features and third-party integrations touching PHI, including sponsor/CRO data-handling requirements

Benefits

  • Comprehensive medical, dental, and vision coverage for employees and eligible dependents, along with disability, life, and supplemental insurance options designed to support your overall well-being.
  • Flexible paid time off, observed company holidays, and a one-time home office stipend to help you create a productive and comfortable remote workspace within our hybrid environment.
  • 401(k) program, pre-tax HSA and FSA options, commuter benefits, financial wellness resources, and access to legal protection plans to support both short- and long-term planning.
  • Access to voluntary benefit offerings including pet wellness support, domestic partner coverage, and additional programs that support the diverse needs of our team members and their families.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service