New York, NY

Salary
$180,000–$200,000
Posted
Aug 11, 2026
Location
New York, NY
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

A DevSecOps / security engineering role at an AI-driven oncology biotech, responsible for owning security architecture end-to-end across cloud infrastructure, CI/CD pipelines, agentic AI systems, and clinical/patient data stores. The hire will design and personally build threat models, guardrails, detection tooling, and access controls — with particular emphasis on securing large numbers of autonomous AI agents and a GCP-hosted data environment subject to HIPAA. The role is hands-on individual-contributor work in a small, fast-moving team at the company's NYC headquarters four days per week.

Senior level · 6+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time

Must have (10)
Python or TypeScriptGCP, AWS or AzureIAMCI/CDTerraform or PulumiSASTDASTthreat modelingincident responsenetwork security
Nice to have (5)
HIPAALLMsMCPOSCPCISSP

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 130 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 95–160

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
incident response62%Python51%TypeScript51%IAM45%CI/CD45%network security45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $143,559 (middle half $110,181–$179,574).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 13, 2026. It is a model, not a headcount.

Why we read it this way (6)

The role title is 'DevSecOps engineer' but the day-to-day work spans both hands-on security analysis/architecture (threat modeling, detection, incident response, HIPAA compliance) and substantial software engineering (writing production Python/TypeScript, building CI/CD guardrails, infrastructure-as-code). 15-1212 was chosen as primary because security architecture and threat defense are the explicit ownership mandate; 15-1252 is a credible runner-up given the strong emphasis on shipping code.

Python and TypeScript are listed together as 'Python and/or TypeScript' — one skill entry is emitted for each with the other as an alternative, reflecting that fluency in at least one is the hard gate.

GCP is listed as preferred but AWS and Azure are explicitly accepted substitutes; the cloud security requirement itself is a hard gate.

Terraform is listed as 'Terraform or similar' under Must-haves — alternatives populated with common IaC substitutes.

HIPAA, LLM/agentic AI security, MCP tooling, OSCP, and CISSP all appear under the Bonus section and are marked preferred accordingly.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secrets management.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗