DevOps Engineer

OXBRIDGE HEALTH, INC.
United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Amazon Web Services Amazon S3 JIRA Cloud Computing System Configuration Continuous Integration Data Infrastructure Software Debugging DevOps Github
+32 more
Google Talk Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language) Linux System Administration Windows Servers OpenVPN OpenID Role-Based Access Control Next.js Message Oriented Middleware Security Assertion Markup Language (SAML) TypeScript AWS Cdk File Transfer Protocol (FTP) Okta ReactJS Delivery Pipeline Large Language Models Amazon Virtual Private Cloud (VPC) AWS ECS Cloudformation Production Code Cloudflare AWS Fargate Route53 Functional Programming Cloudwatch Api Gateway Terraform Webhooks Static Application Security Testing

Job description

  • Build and maintain our IaC estate: We run a fleet of TypeScript AWS CDK repos (one per platform: message bus, SFTP exchange, OpenSearch, org policies, and more) deploying via CodePipeline into a dozen+ accounts. You’ll extend existing stacks, split monoliths apart cleanly, and bootstrap new accounts into the pattern.
  • Own production services: ECS Fargate behind ALBs, Aurora, Lambda, API Gateway, S3, AWS Transfer Family for partner SFTP, OpenSearch, DMS replication. Deploy, monitor, right-size, and debug them.
  • Make observability actually catch things: CloudWatch alarms, Synthetics canaries, VPC flow logs, CloudTrail, log retention and redaction policies. We care about the difference between an alarm that exists and an alarm that pages someone.
  • Automate security and compliance: Service Control Policies as guardrails, IAM Identity Center permission sets, Prowler-driven evidence collection into WORM storage for SOC 2, secret scanning and SAST in PR pipelines. You’ll help move controls from “reviewed quarterly” to “enforced continuously.”
  • Run access management as a product: Okta SSO/SAML, SCIM provisioning, our OpenVPN Access Server fleet, and the approval-gated automation that provisions VPN and AWS access from a Jira ticket or a chat command.
  • Build internal tooling: A lot of our ops surface is chat-native: Google Chat bots and webhooks that review PRs, report compliance drift, page on-call, and provision access. Several are LLM-backed on Amazon Bedrock. You’ll ship these, not just consume them.
  • Improve CI/CD: GitHub Actions workflows, PR gates, org rulesets, auto-merge policy, deployment safety (changeset previews before anything touches prod).
  • On-call rotation: Participate in on-call for production infrastructure.

Requirements

  • 4+ years in DevOps, SRE, platform, or cloud infrastructure engineering.
  • Deep, hands-on AWS: You can reason about IAM trust policies, VPC networking, and cross-account access without a diagram.
  • Real Infrastructure-as-Code experience: AWS CDK strongly preferred; Terraform/CloudFormation background transfers fine, but you’ll be writing TypeScript CDK here.
  • Production Coding: Comfortable writing production code, not just config (TypeScript and/or Python).
  • CI/CD Pipeline Ownership: GitHub Actions, CodePipeline, or equivalent.
  • Containers on AWS: ECS or EKS, image builds, ECR, task/service configuration.
  • Linux Administration: Shell fluency; comfortable on a box with systemctl, journalctl, and no GUI.
  • Identity Systems: SSO/SAML/OIDC, IAM roles vs. users, least privilege in practice.
  • Clear Written Communication: Our runbooks, PR descriptions, and incident notes are how the team scales.

Optional Qualifications

  • Healthcare, fintech, or another regulated environment; HIPAA or SOC 2 audit experience.
  • AWS Organizations at scale: SCPs, Control Tower, Identity Center, multi-account CDK bootstrapping.
  • Data platform exposure: Glue, Athena, QuickSight, Lake Formation, DMS.
  • Amazon Bedrock or other LLM API work-we build with Claude and are actively expanding internal AI tooling.
  • Windows Server administration via SSM (a slice of our analytics estate is Windows).
  • OpenVPN Access Server, Cloudflare, Route 53 at an operational level.
  • Next.js / React-several internal dashboards are full-stack and you’d own them soup to nuts.

About the company

Our company is a start-up that specializes in episodes of care benefit plans. We have a deep expertise in episode pricing and analytics and our goal is to bring transparency and efficiency to the healthcare market. Our company is committed to providing high-quality, affordable healthcare to our customers.

Role Description Oxbridge Health runs healthcare data exchange, member-facing portals, and analytics platforms on AWS. Our infrastructure is a multi-account AWS Organization managed almost entirely as code-every environment, pipeline, and guardrail lives in a CDK repo and deploys through CodePipeline. PHI moves through our systems daily, so we operate under SOC 2 and HIPAA, and our security controls are automated rather than documented-and-hoped-for.

We’re a small team with a large surface area. You’ll own real systems end to end-not tickets handed down from an architecture group. If you like building the automation that makes compliance and access management boring, this is that job.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all