Job Title: DevOps Engineer
Location: Remote
Duration: Direct Hire
Job Summary
We are seeking an experienced Infrastructure / DevOps Engineer to own, enhance, and secure the cloud infrastructure powering our HIPAA-compliant healthcare document processing platform.
Our platform is AWS-native and PHI-sensitive, built with PHP 8.3 / Symfony, React, Aurora MySQL, and MongoDB. The architecture consists of a distributed ecosystem of independently deployed and scaled microservices connected through a central REST API. This role will be responsible for designing, automating, securing, and maintaining the infrastructure that enables a reliable, scalable, and compliant multi-tenant healthcare platform.
The ideal candidate is a hands-on infrastructure engineer who thrives in Linux environments, approaches challenges through automation and infrastructure-as-code, and understands that security, reliability, and compliance are fundamental requirements—not afterthoughts.
Key Responsibilities
Cloud Infrastructure & Reliability
Own the reliability, performance, scalability, and security of our AWS production environment, including:
EC2
Application Load Balancers (ALB)
Aurora MySQL
S3
ECS
CloudWatch
SNS
IAM
VPC and security groups
Design, implement, and improve infrastructure practices that support a highly available, multi-tenant healthcare platform.
Troubleshoot production issues across application, infrastructure, networking, and deployment layers.
Partner with engineering teams to improve system reliability, deployment safety, and operational maturity.
CI/CD & Release Engineering
Design, maintain, and optimize CI/CD pipelines for PHP/Symfony and React applications from code commit through production deployment.
Manage automated build, test, security scanning, and deployment workflows using Bitbucket Pipelines.
Implement and maintain security gates that prevent vulnerable builds from reaching production, including Aikido security scanning and equivalent tooling.
Improve release processes, rollback strategies, and environment consistency across Development, UAT, and Production.
Infrastructure Automation & Infrastructure-as-Code
Establish and mature our infrastructure-as-code practices.
Help transition manually managed infrastructure into repeatable, version-controlled, automated deployments.
Develop and maintain infrastructure automation using tools such as Terraform and/or Ansible.
Create scalable operational processes that reduce manual intervention and improve reliability.
Monitoring, Logging & Observability
Build and enhance centralized logging, monitoring, dashboards, and alerting across AWS CloudWatch and Datadog.
Support the continued rollout and adoption of Datadog throughout the platform.
Proactively identify performance issues and operational risks before they impact customers.
Familiarity with ELK Stack, Splunk, or similar observability platforms is a plus.
Containerization & Distributed Systems
Manage production container workloads using Docker and AWS ECS.
Support specialized containerized workloads, including FreeSWITCH fax and telephony services.
Operate infrastructure supporting a distributed system of independently deployed and scaled microservices.
Configure and optimize:
ECS service scaling
Load balancing
Resource allocation and right-sizing
Deployment strategies
Stateless application infrastructure patterns
Collaborate closely with engineering teams on application scaling, performance optimization, and deployment improvements.
Database & Application Infrastructure Support
Support database reliability and performance initiatives across:
Aurora MySQL
RDS MySQL
MongoDB
Assist with:
Query performance optimization
Read replicas
Partitioning strategies
Backup and restore processes
Database troubleshooting
Manage and optimize Apache, PHP-FPM, and web application infrastructure behind load-balanced environments.
Security, Compliance & Access Management
Operate infrastructure that securely stores and transmits Protected Health Information (PHI) in accordance with HIPAA requirements.
Implement and maintain security best practices, including:
Encryption at rest and in transit
Audit logging
Least-privilege access controls
Network segmentation and isolation
Manage secrets, credentials, keys, and access across environments, including:
AWS credentials and IAM policies
Symfony secrets management
Docker secrets
Bitbucket integrations
Support penetration testing activities, vulnerability remediation, and compliance initiatives.
Maintain awareness of common web application vulnerabilities, including:
Injection vulnerabilities
IDOR
Broken cryptography
Host header injection
Other OWASP-related risks
Secure File Transfer
Configure, secure, and maintain SFTP environments used for external partner and EHR integrations.
Support:
Chroot/jail configurations
SSH key and password authentication
Automated file exchanges
Transfer monitoring and troubleshooting
Required Experience & Skills
Strong Linux system administration experience, with specific proficiency in Ubuntu 24.04 LTS.
Hands-on production experience with AWS infrastructure, including:
EC2
ALB/ELB
Aurora/RDS MySQL
S3
ECS
CloudWatch
IAM
VPC
Security groups
Strong Docker experience building, deploying, and troubleshooting production containers.
Experience designing and maintaining CI/CD pipelines, specifically:
Bitbucket Pipelines
Branching strategies
Environment promotion workflows
Build/test/deploy automation
Pipeline troubleshooting
Strong Bash scripting skills for automation and operational support.
Experience implementing centralized logging and observability solutions:
AWS CloudWatch
Datadog
ELK Stack or Splunk experience is a plus
Experience configuring and troubleshooting:
Apache
PHP-FPM
Load-balanced web applications
Database administration experience with MySQL/Aurora/RDS, including backup, recovery, and performance troubleshooting.
Exposure to MongoDB operations.
Experience managing:
SSH keys
API credentials
Environment-specific secrets
Strong understanding of distributed systems and stateless application architectures, including:
Auto-scaling
Load balancing
Externalized state management (Redis/S3)
Resource optimization
Experience administering secure file transfer systems using SFTP.
Security & Compliance Requirements
Working knowledge of HIPAA-regulated infrastructure environments and PHI protection requirements.
Experience operating security tools and automated security checks within CI/CD pipelines, including:
SAST
DAST
Software composition analysis (SCA)
Container scanning
Infrastructure-as-code scanning
Secrets detection
Experience with security tooling such as Aikido, Snyk, Semgrep, Trivy, or similar platforms.
Experience supporting:
Security audits
Penetration testing
Vulnerability remediation
Compliance activities
Preferred Qualifications
Experience implementing infrastructure-as-code using Terraform and/or Ansible.
Experience building infrastructure automation from an existing manually managed environment.
AWS ECS orchestration experience at scale.
Kubernetes experience is a plus for future orchestration initiatives.
Experience with Jenkins or other CI/CD platforms beyond Bitbucket Pipelines.
Experience with AWS SNS and messaging/notification infrastructure.
Education & Experience Requirements
Bachelor’s degree in Computer Science, Engineering, Information Technology, or another technical discipline preferred; equivalent professional experience, training, or certifications will also be considered.
Proven experience supporting production infrastructure in a cloud-based, security-sensitive environment.