San Francisco, CAremote

Salary
$168,000–$205,000
Posted
Aug 18, 2026
Location
San Francisco, CA
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

This is a hands-on DevSecOps / platform security engineering role at an early-stage healthcare AI company. The hire will own the Terraform codebase, AWS multi-account landing zone (Control Tower/AFT), and the full security lifecycle — vulnerability management, pipeline hardening, compliance-as-code for SOC 2 and HIPAA, and IAM governance — while also enabling product engineers with self-service infrastructure and secure defaults. Strong AWS depth and daily coding are expected.

Senior level · 5+ years · Remote · Full-time

Quick apply — this platform usually takes a CV and a few fields.

Must have (12)
TerraformAWS Control TowerAWS AFTAWS IAM or Aws CdkAWS OrganizationsAWS KMSAWS ConfigAWS Security HubAWS GuardDutyGitHub ActionsSOC 2HIPAA
Nice to have (9)
AWS WAFAurora PostgreSQLAWS BedrockAWS InspectorDrata or VantaPython or TypeScriptHITRUSTNIST 800-53CSA STAR

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
SOC 28%HIPAA10%Terraform11%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
GitHub Actions40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $138,970 (middle half $107,524–$175,762).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 20, 2026. It is a model, not a headcount.

Why we read it this way (8)

No work location or metro is specified beyond a 'hybrid environment' reference; the role appears remote-eligible based on the home office stipend language, but a physical office location is never named.

No compensation figures are provided anywhere in the posting.

SOC classification is a genuine judgment call: the role writes infrastructure code daily (Terraform, GitHub Actions pipelines, compliance-as-code) pointing to 15-1252, but its primary accountability — vulnerability lifecycle, security controls, compliance evidence, and incident response — also fits 15-1212. The coding emphasis and 'write code daily' requirement tipped the classification to 15-1252.

AWS IAM Identity Center, WAF, CloudWatch, Aurora PostgreSQL, Inspector, and Bedrock appear in the 'Where you'll contribute' section rather than the hard requirements block; they are captured as preferred accordingly.

CloudFormation/CDK migration experience is listed under 'Nice to Have' alongside Serverless-to-Terraform migration.

Drata and Vanta are listed together as alternatives under 'Nice to Have' compliance automation platforms.

Python and TypeScript are listed together under 'Nice to Have' for automation scripting; emitted as a single skill with TypeScript as the alternative.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): AWS IAM Identity Center.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗