Statewise is looking for a hands‑on Infrastructure and Security Engineer who treats security and reliability as engineering disciplines, not checklists. This is not a “keep the lights on” role. This is an ownership role for someone who wants to design, harden, and scale the infrastructure behind a complex, state‑configurable Medicaid EHR platform serving pediatric nursing and IDD home care providers.
Responsibilities
- Architect and maintain AWS infrastructure across compute, networking, databases, caching, storage, and serverless services
- Design for scalability, elasticity, and cost efficiency
- Own VPC architecture, subnet segmentation, routing, and security boundaries
- Design and enforce IAM policies, least‑privilege access, and secrets management
- Strengthen encryption standards (at rest and in transit) and key management
- Design and improve monitoring, alerting, and observability across the stack
- Move from reactive alerts to proactive system health signals
- Define uptime expectations, SLAs, and capacity planning
- Create and maintain incident response runbooks and disaster recovery plans
- Regularly test and validate backup and recovery procedures
- Strengthen AWS security services usage including GuardDuty, WAF, CloudTrail, Config, and Security Hub
- Own vulnerability scanning, patch management, and remediation tracking
- Support audits, security assessments, and penetration test remediation
- Drive toward steady‑state audit readiness, not scramble‑based compliance
- Improve and maintain Azure DevOps build and release pipelines
- Implement low‑blast‑radius release strategies
- Enforce security gates within deployment workflows
- Improve rollback confidence and deployment predictability
- Collaborate on infrastructure needs for new services and features
- Drive toward infrastructure‑as‑code practices where they create leverage
- Influence architectural decisions related to scalability, cost, and security
- Raise operational awareness and security discipline across the team
- You will own infrastructure confidence across our production systems: web platform, mobile backend, data pipelines, and integrations
- You will define how our systems are provisioned, secured, monitored, and recovered
Requirements
- 5+ years of infrastructure, DevOps, or cloud engineering experience
- Deep hands‑on experience with AWS (EC2, RDS, VPC, S3, Lambda, IAM)
- Strong understanding of AWS security services and IAM best practices
- Experience designing scalable, elastic production systems
- Experience maturing and hardening HIPAA‑compliant environments
- Strong networking fundamentals: VPCs, subnets, routing, DNS, load balancing
- Experience with monitoring and observability tools (CloudWatch, Datadog, or similar)
- Hands‑on experience with CI/CD pipelines (Azure DevOps preferred)
- Familiarity with Infrastructure‑as‑Code (Terraform, CloudFormation, or CDK)
- Must be located in and authorized to work in the United States. Statewise does not provide visa sponsorship at this time.
Nice to have
- Experience in healthcare or regulated software environments strongly preferred
Benefits
- Remote-first role (Nashville or Fort Worth proximity is a plus, not a requirement)
- Medical insurance with employer contribution
- HSA with employer contribution
- Dental insurance available (employee-paid)
- 401(k) with employer match
- Flexible PTO with an expectation that people actually take time off
- Paid parental leave
Additional details
- Originally posted on Himalayas
- You learn systems quickly and reduce ambiguity for yourself and others
- You take ownership of production outcomes, not just task completion
- You think in systems: blast radius, failure domains, and network topology
- You design for security and reliability from the beginning
- You automate what matters without over‑engineering
- You are comfortable making production decisions under pressure
- You communicate risk and tradeoffs clearly
- You are hands‑on and operate confidently in live environments
- You use AI tools thoughtfully to accelerate investigation, documentation, and operational clarity
- This Role Is Not a Fit If You
- Prefer managing infrastructure through the console rather than repeatable processes
- Treat security as a compliance checkbox rather than an engineering practice
- Are uncomfortable making production decisions without a full committee
- Focus on tooling over outcomes
- Avoid documentation and knowledge sharing
- Need someone else to define what “secure” means for your systems
- See monitoring as optional rather than foundational
- What Success Looks Like
- Within 45 days, you understand our AWS architecture and security posture and have identified high‑leverage improvements
- Within 90 days, monitoring coverage is stronger, security controls are tightened, and release processes are safer and more predictable
- Within 6 months, infrastructure is more resilient, observable, and audit‑ready as a steady state
- The team trusts production. Deployments are predictable. Incidents are contained quickly. Leadership has visibility into operational health and security posture.