Information Security Development Engineer

Viva Health
Birmingham, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate

Job location

Birmingham, United States of America

Tech stack

Kubernetes Security
API
Amazon Web Services (AWS)
Azure
Cloud Computing Security
Configuration Management
Computer Security
Continuous Delivery
Continuous Integration
DevOps
Github
Health Information Technology
Identity and Access Management
Information Systems Security Architecture Professional
Key Management
Systems Development Life Cycle
Reliability Engineering
Software Engineering
Data Logging
Cloud Platform System
Cloudformation
Gitlab-ci
Kubernetes
Information Technology
Bicep
Terraform
Devsecops
Jenkins
Static Application Security Testing
Dynamic Application Security Testing

Job description

The Information Security Development Engineer will partner closely with software engineering, infrastructure, compliance, and operations teams to integrate security, risk management, and automation throughout the software development lifecycle (SDLC). This role will help design, build, and maintain secure continuous integration/continuous delivery (CI/CD) pipelines, infrastructure as code (IaC), monitoring, threat detection, and compliance controls, especially healthcare-specific such as Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH).

This individual plays a key role in proactively identifying and mitigating risks, improving our security posture, and enabling rapid, reliable delivery of software and infrastructure changes. This position will oversee and manage patching and maintaining throughout the life cycle of the software., * Design, implement, and maintain secure CI/CD pipelines across applications, Application Programming Interfaces (APIs), and cloud platforms.

  • Develop and manage infrastructure as code with security-first principles. (Terraform, CloudFormation, ARM/Bicep)
  • Integrate automated security testing throughout the software development lifecycle. (SAST, DAST, dependency, and container scanning)
  • Embed secure development practices, threat modeling, and security review gates into engineering workflows.
  • Monitor, detect, and respond to security vulnerabilities and incidents including remediation and root-cause analysis.
  • Maintain observability for systems and security events through logging, monitoring, and alerting actions.
  • Support regulatory compliance and contribute to audits and control implementation. (HIPAA, HITECH, CMS)
  • Perform risk assessments and security architecture reviews for internal systems, cloud environments, and third-party vendors. Offer guidance, training, and promote security awareness across development and operations teams.
  • Stay current on evolving security threats, tool sets, frameworks, and cloud provider best practices. Recommend improvements and drive adoption.

Requirements

  • Bachelor's Degree in Computer Science, Information Security, or related field; Work experience may substitute for education requirement
  • 4+ years' experience in DevSecOps, site reliability engineering with a security focus or similar role
  • Strong experience with major cloud platforms (AWS, Azure) and cloud security best practices
  • Proven ability to build and manage CI/CD pipelines with integrated security controls (Jenkins, GitHub Actions, GitLab CI, Azure, DevOps)
  • Hands-on experience with Infrastructure as Code and configuration management (Terraform, CloudFormation, ARM/Bicep)
  • Proficiency with security tooling including SAST/DAST, dependency and container scanning, and cloud security posture management
  • Solid understanding of networking, IAM, encryption, key management, and secure architecture principles
  • Familiarity with healthcare regulations and frameworks (HIPAA, HITECH, CMS)
  • Strong communication and collaboration skills across engineering, security, compliance, and business teams, * CSSLP, GSSP, Security+, SSCP
  • Experience with Kubernetes and container security
  • Familiarity with SRE and resilience practices

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Paid parental leave
  • Parental leave
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance, * Comprehensive Health, Vision, and Dental Coverage
  • 401(k) Savings Plan with company match and immediate vesting
  • Paid Time Off (PTO)
  • 9 Paid Holidays annually plus a Floating Holiday to use as you choose
  • Tuition Assistance
  • Flexible Spending Accounts
  • Healthcare Reimbursement Account
  • Paid Parental Leave
  • Community Service Time Off
  • Life Insurance and Disability Coverage
  • Employee Wellness Program
  • Training and Development Programs to develop new skills and reach career goals
  • Employee Assistance Program

See more about the benefits of working at Viva Health - https://www.vivahealth.com/careers/benefits (https://www.vivahealth.com/careers/benefits)

About the company

VIVA HEALTH, part of the renowned University of Alabama at Birmingham (UAB) Health System, is a health maintenance organization providing quality, accessible health care. Our employees are a part of the communities they serve and proudly partner with members on their healthcare journeys. VIVA HEALTH has been recognized by Centers for Medicare & Medicaid Services (CMS) as a high-performing health plan and has been repeatedly ranked as one of the nation's Best Places to Work by Modern Healthcare.

Apply for this position