DevSecOps / Cloud Engineer
Trial Library is an AI-native enrollment and care navigation platform that accelerates access to precision medicine. In collaboration with biopharmaceutical manufacturers, payers, and health systems, we enable the delivery of clinical trials as a standard care option—improving patient access, advancing oncology outcomes, and reducing the total cost of care. Backed by leading healthcare venture capital firms, our platform is currently deployed in 840+ clinics and 3,000+ providers nationwide.
About the role
Join our small, high-trust Infrastructure team as its second engineer, reporting to the Director of Infrastructure and partnering closely with our product engineering team. You will drive two key initiatives: building a cohesive AWS foundation with Terraform, Control Tower, and AFT, and owning end-to-end security engineering for our production PHI and Bedrock AI workloads. You'll also build the paved paths, self-service tooling, and guardrails that let our engineers ship quickly. AI is deeply embedded in how we work—we use it across coding, testing, and operations because we've seen what it unlocks. We're looking for someone who already builds this way and is curious about AI-augmented practice in infrastructure and security work. We value fast decisions, open feedback, and empowered engineers.
Responsibilities
- Infrastructure as code: Own the Terraform codebase—module design, state strategy, drift detection, plan review discipline—and migrate our CloudFormation/Serverless footprint where it delivers leverage without stalling product delivery.
- The AWS landing zone: Design and implement multi-account structure via Control Tower and AFT, including account vending, customizations, service control policies, and OU design.
- Security engineering: Operate Security Hub, GuardDuty, Inspector, and Config as living detection tooling—triage findings, tune signals, and run the vulnerability lifecycle from discovery through verified fix. Coordinate penetration tests and own remediation.
- Pipeline and supply chain security: Secure the commit-to-production path in GitHub Actions with least-privilege OIDC deployment roles, secrets scanning, SAST, dependency/container gates, branch protection, and artifact integrity.
- Developer enablement: Build paved-path tooling, self-service infrastructure, and secure defaults that let product engineers move fast without filing tickets.
- Disaster recovery and backup: Define backup strategy, RPO/RTO targets, Aurora point-in-time recovery, and conduct regular DR testing to satisfy HIPAA contingency planning requirements.
- Compliance as code: Encode SOC 2 and HIPAA controls into the platform—encryption, KMS, CloudTrail/Config coverage, log retention—with automated evidence collection.
- Identity and access governance: Manage IAM Identity Center, cross-account roles, SSO, periodic access reviews, and joiner/mover/leaver deprovisioning, alongside network foundations like VPC design, WAF, and Client VPN.
Alongside the Director of Infrastructure and the Dev Team, you will also contribute to:
- Security architecture for Bedrock AI workloads: access controls, guardrails, PHI data boundaries
- Production incident response (reliability and security) and recurrence prevention
- Observability and cost visibility: CloudWatch, alarms, dashboards, tagging
- Partnership with application engineers on Lambda, Aurora PostgreSQL, and Bedrock workloads
- Lightweight threat modeling and security review of new features and third-party integrations touching PHI, including sponsor/CRO data-handling requirements
Requirements
- 5+ years in DevSecOps, security, platform, or infrastructure engineering, operating production systems you were accountable for
- Demonstrated security ownership: you have run vulnerability management, remediated real findings, and participated in incident response—not just deployed tooling
- Deep Terraform proficiency: module hierarchies, multi-environment state, drift and refactors, critical plan review
- Hands-on AFT and Control Tower experience: you have vended accounts through AFT and customized the pipeline
- Broad AWS depth: IAM, Organizations, VPC, Lambda, RDS/Aurora, S3, KMS, CloudTrail, Config, Security Hub, GuardDuty, Secrets Manager
- GitHub Actions as a daily environment, including pipeline hardening and secrets management
- SOC 2 Type II and HIPAA experience in a real PHI-handling environment: you have owned controls, produced evidence, and sat in front of an auditor
- Change and release discipline: you think about blast radius before you apply, have owned deployment and rollback strategies in production, and move quickly inside regulated-environment constraints
- Hands-on, autonomous, and clear: you write code daily, take ambiguous problems to documented decisions, and can explain security tradeoffs to non-security people
- You use AI coding and automation tools as a daily part of how you work and actively explore how they change infrastructure and security practices
- Genuine interest in improving clinical trial access and health equity
Nice to Have
- Compliance automation platforms (Drata, Vanta) including evidence automation
- CloudFormation/CDK/Serverless-to-Terraform migration experience
- GitHub EMU, SCIM, and SAML SSO administration
- Aurora PostgreSQL operations and schema migration coordination
- Python or TypeScript for automation
- HITRUST, NIST 800-53, or CSA STAR exposure
- Securing LLM workloads
Why Trial Library
- Meaningful impact: Help patients access clinical trials faster through better technology and workflows
- High ownership environment: Autonomy to build, test, and influence strategy across the business
- Collaborative team culture: Low ego, high trust, and close partnership across functions
- Opportunity for growth: Join at an early stage with meaningful exposure to company-building and decision-making
Core Values
- Ally is our favorite moniker
- The broadest reach is worth the effort
- Celebrate measurable improvements in access and outcomes
- Fearless advocates for representation in research
- Incentives matter to stakeholders choosing our products
- Taking initiative is actually giving
- We are accountable for the experience of patients and providers
- Empathy and humility are the real dynamic duo
Benefits
- Health & Wellness: Comprehensive medical, dental, and vision coverage for employees and eligible dependents, along with disability, life, and supplemental insurance options
- Time Off & Workplace Support: Flexible paid time off, observed company holidays, and a one-time home office stipend for remote workspace setup
- Financial & Lifestyle Benefits: 401(k) program, pre-tax HSA and FSA options, commuter benefits, financial wellness resources, and access to legal protection plans
- Additional Support & Voluntary Benefits: Access to voluntary offerings including pet wellness support, domestic partner coverage, and programs supporting diverse team member needs
Pay
The salary range for this position is $168,000–$205,000 per year and reflects a good faith estimate of base pay for candidates working in San Francisco, CA. Final compensation will be based on experience, skills, and qualifications.
Schedule
This is a hybrid role based in San Francisco, CA, with a requirement of three days per week in the office: Wednesday, Thursday, and Friday.