Posted today · be early
DevOps & Security Engineer - AI-Native Healthcare SaaS
Zenara Health
IndiaremotePosted 1 day ago
Z
Skill Required
DevOpsDevSecOpsSecurity-EngineeringSite-Reliability-EngineeringPlatform-EngineeringCloud-SecurityInfrastructure-EngineeringHealthcare-IT-SecurityAI-InfrastructureCompliance-EngineeringHealthcare-ComplianceSecurity-DevOps-EngineerDevOps-Security-EngineerSecure-DevOps-EngineerCloud-Native-Security-EngineerSenior-DevOps-Engineer-AI-MLAI EngineerDevOps EngineerSecurity EngineersecurityAIBackup and RecoverySOCCybersecurityCD pipelinesWeb AccessibilityEngineeringautomationdevelopingObservabilityCryptographybuildingAzuredesignISO 27001CI/CDCloudAWSandGoCICDFulltime
Key highlights
- Salary: ₹22 – 35 LPA.
- Required experience: 5–10 years in DevOps/SRE/Platform Engineering.
- Fully remote work available across India.
- Direct, regular communication with the CEO.
- Must maintain HIPAA‑compliant security posture and lead SOC 2 Type II readiness.
- On‑call availability with 4–8 hours overlap with US Pacific time.
Role overview
Zenara Health is a mental healthcare organization that leverages AI‑driven platforms to deliver personalized mental wellness services. Operating as a startup, the company is building a HIPAA‑regulated platform that manages clinical data, AI workflows, and insurance billing for psychiatric practices. This role is the company’s primary line of defense, responsible for creating and maintaining a security‑first infrastructure, compliance engineering, and AI‑supporting systems.
Responsibilities
- Manage threat modeling, reduce attack surfaces, oversee intrusion detection, handle vulnerability management, and plan incident responses; act as final reviewer for infrastructure and security risks with authority to halt releases that do not meet security or compliance criteria.
- Design and implement CI/CD pipelines for all Zenara products, establishing deployment automation, managing environments, and setting quality thresholds to eliminate chaotic releases.
- Develop and uphold a HIPAA‑compliant security posture across all Zenara systems, including implementing access controls, managing secrets, maintaining audit logs, and enforcing encryption standards.
- Create monitoring and alerting capabilities to proactively identify issues, establish incident response protocols, define service level objectives (SLOs), monitor reliability metrics, lead the on‑call rotation, and develop runbooks for common incidents.
- Address AI infrastructure needs such as model serving, GPU provisioning, and autoscaling for AI workloads; collaborate with the Head of AI to ensure production AI infrastructure is efficient and secure.
- Oversee cloud infrastructure (AWS/Azure) focusing on cost optimization, reliability, disaster recovery, and capacity planning; make architectural decisions balancing cost, performance, and compliance.
- Lead SOC 2 Type II readiness efforts, implementing necessary controls, organizing evidence collection, and liaising with auditors.
- Take charge of security incident response, establishing procedures, conducting regular security evaluations, and responding to incidents as they arise.
- Own full infrastructure and security ownership, delivering reliable and secure systems, establishing compliance practices, and asserting “no” when risks are unacceptable.
- Lead on‑call rotation for security incidents and develop operational and security runbooks.
- Document existing systems and security protocols, set up basic monitoring and alerting in the first month, and outline the CI/CD roadmap.
- Conduct initial threat assessments, perform intrusion detection and vulnerability scanning in early months.
Requirements
- 5–10 years of experience in DevOps, SRE, or Platform Engineering, with experience designing and maintaining large‑scale production infrastructure.
- Strong security mindset: naturally cautious, detail‑focused, and able to express concerns when risks are too high.
- Familiarity with HIPAA, SOC 2, or healthcare compliance frameworks; understanding of BAAs, audit trails, and regulatory obligations, with proven implementation of compliant systems.
- Proficiency in AWS or Azure with infrastructure‑as‑code tools (Terraform, Pulumi, or CloudFormation) and ability to manage infrastructure programmatically.
- Experience designing and implementing CI/CD pipelines using tools such as GitHub Actions, CircleCI, Jenkins, or similar.
- Experience with container orchestration platforms (Kubernetes, ECS, or equivalent) for deploying and scaling applications.
- Skills in cybersecurity, including threat modeling, vulnerability assessment, intrusion detection, and incident response.
- Strong English communication skills for asynchronous work, clear written documentation, incident reports, and architectural designs.
- Experience in startup or high‑growth environments, thriving amid uncertainty, constrained resources, and pressing deadlines.
Nice to have
- Experience supporting ML/AI infrastructure, including model serving and GPU clusters.
- Security expertise in healthcare SaaS, handling PHI, encryption at rest/transit, and access auditing.
- Background in penetration testing or security audits.
- Prior experience with SOC 2 or HITRUST certification processes.
- Knowledge of observability and monitoring tools such as Datadog, Prometheus, Grafana, or similar.
- Understanding of FHIR/HL7 healthcare data standards.
- Production experience with Kubernetes.
- Familiarity with multi‑tenant SaaS security strategies.
- Exposure to mental health or behavioral health sectors.
- Experience with cloud infrastructure cost optimization.
- Relevant security certifications (CISSP, CEH, or equivalent).
Benefits
- Salary between ₹22–35 LPA, based on skills and responsibilities.
- Fully remote work options available throughout India.
- Provision for equipment allowance.
- Acknowledgment of culturally significant local holidays in India.
- Flexible paid leave options.
- Direct and regular communication with the CEO without intermediaries.
- Opportunity to build infrastructure and security practices from the ground up.
Additional details
- About the Company: Zenara Health is a mental healthcare organization driven by technology, aiming to improve accessibility and quality of mental wellness services by integrating AI‑driven platforms with professional clinical care.
- Why This Role Exists: Serves as the company’s foremost line of defense, assuming systems are constantly under threat and building resilient, auditable, and secure infrastructure; prioritizes security of patient data, regulatory compliance, and system integrity over rapid feature rollout.
- Values & Vibe (Who You Are): Emphasizes infrastructure viewed through security and reliability, a paranoid mindset about threats, hands‑on ability to diagnose production issues, experience building regulated‑sector infrastructure, comfort saying “no” to unacceptable risks, and belief that security shapes worldview.
- Schedule: Evening IST hours with 4–8 hours daily overlap with US Pacific (9 am–5 pm PT); flexibility to propose a schedule; on‑call availability expected during key security incidents.
- First 90 Days Plan: Week 1‑2 immersion and vulnerability identification; Month 1 set up basic monitoring, outline CI/CD roadmap, document systems, conduct initial threat assessments; Month 2‑3 develop security‑gated CI/CD pipelines, implement secrets management and access controls, create operational and security runbooks, initiate SOC 2 gap analysis, introduce intrusion detection and vulnerability scanning; Ongoing full ownership of infrastructure and security.
- The role is not for someone who only occasionally runs “kubectl apply” or who prioritizes speed over safety; it requires a security‑first perspective and the ability to halt releases that present unacceptable risk.