DevSecOps / Cloud Engineer
triallibrary
San Francisco, CA
Posted Aug 19, 2026
- Full-time
- Engineering
Job description
**Trial Library is an AI-native research platform with a mission to improve healthcare outcomes by expanding access to precision medicine.** **About Trial Library** Trial Library is an AI-native enrollment and care navigation platform that accelerates access to precision medicine. In collaboration with biopharmaceutical manufacturers, payers, and health systems, Trial Library enables the delivery of clinical trials as a standard care option - improving patient access, advancing oncology outcomes, and reducing the total cost of care. Backed by leading healthcare venture capital firms, Trial Library’s platform is currently deployed in 840+ clinics and 3,000+ providers nationwide. ### **About the role** Join our small, high-trust Infrastructure team as its second engineer, reporting to the Director of Infrastructure and partnering closely with our product engineering team. You will drive two key initiatives: building a cohesive AWS foundation with Terraform, Control Tower, and AFT, and owning end-to-end security engineering for our production PHI and Bedrock AI workloads. Just as important, you'll build the paved paths, self-service tooling, and guardrails that let our engineers ship quickly. AI is deeply embedded in how we work. We use it across coding, testing, and operations, not because of a mandate but because we've seen what it unlocks. We're looking for someone who already builds this way and is curious about what AI-augmented practice looks like in infrastructure and security work. We value fast decisions, open feedback, and empowered engineers. ### Your Responsibilities ### **What you'll own** - **Infrastructure as code.** The Terraform codebase - module design, state strategy, drift detection, plan review discipline - and the migration of our CloudFormation/Serverless footprint where it delivers real leverage, without stalling product delivery. - **The AWS landing zone.** Multi-account structure via Control Tower and AFT: account vending, customizations, service control policies, and OU design. - **Security engineering.** Security Hub, GuardDuty, Inspector, and Config as living detection tooling: triage findings, tune signals, and run the vulnerability lifecycle from discovery through verified fix. Coordinate penetration tests and own remediation. - **Pipeline and supply chain security.** Secure the commit-to-production path in GitHub Actions: least-privilege OIDC deployment roles, secrets scanning, SAST and dependency/container gates, branch protection, and artifact integrity. - **Developer enablement.** Paved-path tooling, self-service infrastructure, and secure defaults that let product engineers move fast without filing tickets. - **Disaster recovery and backup.** Backup strategy, RPO/RTO targets, Aurora point-in-time recovery, and regular DR testing to satisfy HIPAA contingency planning requirements. - **Compliance as code.** SOC 2 and HIPAA controls encoded into the platform - encryption, KMS, CloudTrail/Config coverage, log retention - with automated evidence collection. - **Identity and access governance.** IAM Identity Center, cross-account roles, SSO, periodic access reviews, and joiner/mover/leaver deprovisioning, alongside network foundations: VPC design, WAF, and Client VPN. ### **Where you'll contribute** Alongside the Director of Infrastructure and the Dev Team: - Security architecture for Bedrock AI workloads: access controls, guardrails, PHI data boundaries - Production incident response (reliability and security) and recurrence prevention - Observability and cost visibility: CloudWatch, alarms, dashboards, tagging - Partnership with application engineers on Lambda, Aurora PostgreSQL, and Bedrock workloads - Lightweight threat modeling and security review of new features and third-party integrations touching PHI, including sponsor/CRO data-handling requirements ### Your Requirements - 5+ years in DevSecOps, security, platform, or infrastructure engineering, operating production systems you were accountable for - Demonstrated security ownership: you have run vulnerability management, remediated real findings, and participated in incident response - not just deployed tooling - Deep Terraform proficiency: module hierarchies, multi-environment state, drift and refactors, critical plan review - Hands-on AFT and Control Tower experience - you have vended accounts through AFT and customized the pipeline, not adjacent familiarity - Broad AWS depth: IAM, Organizations, VPC, Lambda, RDS/Aurora, S3, KMS, CloudTrail, Config, Security Hub, GuardDuty, Secrets Manager - GitHub Actions as a daily environment, including pipeline hardening and secrets management - SOC 2 Type II and HIPAA experience in a real PHI-handling environment - you have owned controls, produced evidence, and sat in front of an auditor - Change and release discipline: you think about blast radius before you apply, have owned deployment and rollback strategies in production, and move quickly inside regulated-environment constraints rather than treating them as obstacles - Hands-on, autonomous, and clear: you write code daily, take ambiguous problems to documented decisions, and can explain security tradeoffs to non-security people - You use AI coding and automation tools as a daily part of how you work, and you actively explore how they change infrastructure and security practices - Genuine interest in improving clinical trial access and health equity ### Nice to Have - Compliance automation platforms (Drata, Vanta) including evidence automation - CloudFormation/CDK/Serverless-to-Terraform migration experience - GitHub EMU, SCIM, and SAML SSO administration - Aurora PostgreSQL operations and schema migration coordination - Python or TypeScript for automation - HITRUST, NIST 800-53, or CSA STAR exposure - Securing LLM workloads