donator JOBS

IT 与编程

DevOps & Security Engineer - AI-Native Healthcare SaaS(远程职位)

Zenara Health

不限地点远程Anywhere in the World
申请

链接会跳转到原始招聘信息。Donator 不代收申请。

可分享的海报
发布时间: (6 天前)有效期: 截至 2026年9月28日

DevOps & Security Engineer - AI-Native Healthcare SaaS:「IT 与编程」类别,完全远程

这条招聘信息来自 Zenara Health,岗位是 DevOps & Security Engineer - AI-Native Healthcare SaaS。职位属于「IT 与编程」类别,完全远程。公司不限制候选人的居住地,在任何地方都可以申请。

公司没有公布具体数字,这一项会在面试时谈定。对工作时间,招聘信息没有提出任何条件。

这个职位通过了自动核查:凡是要求外国工作许可、签证担保、特定国籍,或者必须居住在指定国家的招聘信息,都不会进入列表。

要点

公司
Zenara Health
类别
IT 与编程
谁可以申请
来自世界任何国家
工作方式
完全远程
发布时间
2026年8月19日 (6 天前)
有效期
截至 2026年9月28日
来源
We Work Remotely

新职位邮件提醒:IT 与编程

职位板每天更新数次。只有出现新的、已核查的职位时才会写信。不发垃圾邮件,也不需要注册账号。

已经订阅过了? 管理订阅设置

公司发布的职位描述

Headquarters: India

About the Company Zenara Health is a mental healthcare organization driven by technology, aiming to improve the accessibility and quality of mental wellness services. By integrating AI-driven platforms with professional clinical care, we deliver personalized and effective mental health solutions, creating a smooth digital experience for both patients and providers. We operate as a startup, distinct from a mere department. Why This Role Exists This position serves as the company's foremost line of defense. You will operate under the assumption that systems are constantly under threat, crafting infrastructure that is resilient, auditable, and inherently secure. You will be the most risk-aware individual in the startup - and that’s exactly what we require. While others concentrate on feature rollout, you will prioritize the security of patient data, regulatory compliance, and system integrity. About the Role If your understanding of DevOps is limited to "I occasionally execute kubectl apply," this position is likely not for you. This role is not suited for those who prioritize speed over safety or view security as an afterthought to be addressed later. At Zenara, safeguarding patient data and maintaining system integrity takes precedence over rapid deployment. Our team is in the process of developing a platform that manages clinical data, operates AI workflows, and processes insurance billing - all within a HIPAA-regulated environment catering to real psychiatric practices. Our infrastructure is operational; however, we lack an individual who will take ownership with a security-first perspective. We currently do not have a dedicated CI/CD owner, a comprehensive security posture, or monitoring that extends beyond simple uptime checks. If HIPAA auditors were to arrive tomorrow, we could withstand the scrutiny - but it wouldn’t be a pleasant experience. You will be responsible for Zenara’s infrastructure, security posture, and compliance engineering - everything from the ground up. This includes CI/CD pipelines, HIPAA-compliant deployment automation, monitoring and alerting systems, cybersecurity measures and threat defense, access controls, and audit logging - the complete spectrum of "essential elements that ensure the safe operation of a healthcare company." However, your role will go beyond mere maintenance. You will also develop infrastructure for our AI platform, encompassing model serving, scaling AI workloads, and supporting production AI pipelines. You will have a dual mandate: ensure the stability and security of the platform while also building the necessary infrastructure for AI at scale. This represents a unique opportunity for greenfield infrastructure engineering within a healthcare AI company with genuine compliance obligations and real users. You will devise systems from fundamental principles, make architectural choices, establish best practices to guide us through growth and compliance audits, and serve as the ultimate security gatekeeper. What You Will Own 1. Cybersecurity & Threat Defense You will manage threat modeling, reduce attack surfaces, oversee intrusion detection, handle vulnerability management, and plan incident responses. You will be the final reviewer for infrastructure and security risks, possessing the authority to halt releases that do not satisfy security or compliance criteria. The security of patient data is non-negotiable. 2. CI/CD and Deployment Automation You will design and implement CI/CD pipelines for all Zenara products, establishing deployment automation, managing environments, and setting quality thresholds. Your goal is to eliminate chaotic releases and establish a system that enables the team to deploy confidently and consistently - without compromising security. 3. Security Posture and HIPAA Compliance You will develop and uphold a HIPAA-compliant security posture across all Zenara systems. This involves implementing access controls, managing secrets, maintaining audit logs, and enforcing encryption standards. You will ensure our adherence to regulatory requirements while avoiding bureaucratic slowdowns. 4. Monitoring, Alerting, and Incident Response You will create monitoring and alerting capabilities to proactively identify issues before they affect users. You will establish incident response protocols, define service level objectives (SLOs), and monitor reliability metrics. You will lead the on-call rotation and develop runbooks for common incidents. 5. AI Infrastructure Support You will address the AI infrastructure needs, including model serving, GPU provisioning (if necessary), and autoscaling for AI workloads. You will collaborate with the Head of AI to ensure that the infrastructure supports production AI efficiently and securely. 6. Cloud Infrastructure Management You will oversee cloud infrastructure (AWS/Azure), focusing on cost optimization, reliability, disaster recovery, and capacity planning. You will make architectural decisions that find a balance between cost, performance, and compliance obligations. 7. SOC 2 Readiness You will spearhead SOC 2 Type II preparedness as we approach fundraising, implementing necessary controls, organizing evidence collection, and liaising with auditors. You will ensure compliance becomes an integrated process rather than an ad-hoc measure. 8. Security Incident Response You will take charge of security incident response, establishing procedures, conducting regular security evaluations, and responding to incidents as they arise. Your efforts will help the organization recognize security as an essential discipline rather than an afterthought. Your First 90 Days Week 1-2: Fully immerse yourself in the current infrastructure, deployment processes, and security posture. Identify the most significant security vulnerabilities and critical gaps. Build rapport through active listening and insightful inquiries. Month 1: Set up basic monitoring and alerting systems. Outline the CI/CD roadmap. Begin documenting existing systems and security protocols. Establish communication channels with engineering leadership. Conduct initial threat assessments. Month 2-3: Develop CI/CD pipelines for high-priority services with security gates. Implement secrets management and access controls. Create the first set of operational and security runbooks. Initiate SOC 2 gap analysis and planning for remediation. Introduce intrusion detection and vulnerability scanning. Ongoing: Take on full ownership of infrastructure and security. Deliver reliable and secure systems. Establish compliance practices and enhance security standards. Assertively say “no” when risks are unacceptable. Inspire confidence in the CEO that infrastructure and security are in capable hands. Values & Vibe (Who You Are) You perceive infrastructure primarily through the lens of security and reliability , rather than merely uptime. You are the one who enters an unmanaged infrastructure landscape and brings order - not through an excess of tools, but through clarity, automation, and effective monitoring. For you, security is not a mere checklist; it shapes your worldview. You possess an innate sense of paranoia - assuming systems are under threat and designing with that understanding. You find an infrastructure environment that functions like a black box, relying on heroic measures rather than standard practices, to be unacceptable. You recognize that healthcare compliance is mandatory and understand how to implement it practically, without hindering development speed. You are hands-on enough to diagnose production issues, write Terraform modules, and review security configurations - yet you know that your primary responsibility lies in creating systems that are both reliable and secure, rather than solely reacting to incidents. You have successfully built infrastructure in regulated sectors while adhering to compliance constraints.…

职位正文保留公司发布时的原文,因为投递的时候用的也是同一种语言。

该职位发布于 We Work Remotely. 原始招聘信息 (We Work Remotely)

关于这个职位的常见问题

我可以在自己居住的地方申请「DevOps & Security Engineer - AI-Native Healthcare SaaS」这个职位吗?

可以。对于这个职位,Zenara Health 接受来自世界任何国家的候选人,所以你不需要其他国家的工作许可。这条招聘信息通过了自动核查:如果雇主要求工作许可、签证担保,或者必须居住在某个特定国家,它就不会出现在本站。

标明的报酬是多少?

对于这个职位,Zenara Health 没有公布报酬。多数远程招聘信息不给出具体数字,这件事会在面试时谈定。

怎么申请?

你通过发布在 We Work Remotely 上的原始招聘信息,直接向雇主提交申请。Donator 不代收申请,不收取佣金,也不保存简历。

这是什么类型的职位?

这是「IT 与编程」类别中的一个完全远程职位。混合办公的招聘信息,以及任何需要到办公室的职位,本站都不会发布。

适合这个职位的免费证书

这个领域里分量最重的几张免费证书。每一张都在发证方自己的页面上核实过。

全部免费证书:「IT and cloud」

相似职位

远程职位:DevOps & Security Engineer - AI-Native Hea… | Donator