DevOps & Security Engineer - AI-Native Healthcare SaaS

Zenara Health

India

Remote

INR 2,200,000 - 3,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equipment allowance
Flexible paid leave
Direct communication with the CEO

Job summary

A healthcare technology company in India is seeking a skilled DevOps Engineer to enhance the security and infrastructure of its mental health services platform. The role involves ensuring the security of patient data, designing CI/CD pipelines, and maintaining compliance with regulations like HIPAA. Candidates should have a strong security mindset, experience in cloud environments, and proficiency in cybersecurity practices. This position offers a salary between ₹22-35 LPA, remote work options, and flexible scheduling.

Qualifications

  • 5-10 years of experience in DevOps, SRE, or Platform Engineering.
  • Familiarity with healthcare compliance frameworks (HIPAA, SOC 2).
  • Experience in startup or high-growth environments.

Responsibilities

  • Manage threat modeling, oversee intrusion detection.
  • Design and implement CI/CD pipelines for all Zenara products.
  • Develop and uphold a HIPAA-compliant security posture.

Skills

Strong security mindset
Experience with AWS or Azure
CI/CD pipeline design and implementation
Proficient in Terraform or similar
Cybersecurity skills
Strong English communication skills

Tools

GitHub Actions
Kubernetes
CloudFormation

Job description

About The Company

Zenara Health is a mental healthcare organization driven by technology, aiming to improve the accessibility and quality of mental wellness services. By integrating AI-driven platforms with professional clinical care, we deliver personalized and effective mental health solutions, creating a smooth digital experience for both patients and providers. We operate as a startup, distinct from a mere department.

Why This Role Exists

This position serves as the company's foremost line of defense. You will operate under the assumption that systems are constantly under threat, crafting infrastructure that is resilient, auditable, and inherently secure. You will be the most risk-aware individual in the startup — and that's exactly what we require. While others concentrate on feature rollout, you will prioritize the security of patient data, regulatory compliance, and system integrity.

About The Role

If your understanding of DevOps is limited to "I occasionally execute kubectl apply," this position is likely not for you. This role is not suited for those who prioritize speed over safety or view security as an afterthought to be addressed later. At Zenara, safeguarding patient data and maintaining system integrity takes precedence over rapid deployment.

Our team is developing a platform that manages clinical data, operates AI workflows, and processes insurance billing — all within a HIPAA-regulated environment catering to real psychiatric practices. Our infrastructure is operational; however, we lack an individual who will take ownership with a security-first perspective. We currently do not have a dedicated CI/CD owner, a comprehensive security posture, or monitoring that extends beyond simple uptime checks.

You will be responsible for Zenara's infrastructure, security posture, and compliance engineering — everything from the ground up. This includes CI/CD pipelines, HIPAA-compliant deployment automation, monitoring and alerting systems, cybersecurity measures and threat defense, access controls, and audit logging — the complete spectrum of "essential elements that ensure the safe operation of a healthcare company." You will also develop infrastructure for our AI platform, encompassing model serving, scaling AI workloads, and supporting production AI pipelines.

What You Will Own
  • Cybersecurity & Threat Defense: manage threat modeling, reduce attack surfaces, oversee intrusion detection, handle vulnerability management, and plan incident responses. You will be the final reviewer for infrastructure and security risks, possessing the authority to halt releases that do not satisfy security or compliance criteria.
  • CI/CD and Deployment Automation: design and implement CI/CD pipelines for all Zenara products, establishing deployment automation, managing environments, and setting quality thresholds to eliminate chaotic releases.
  • Security Posture and HIPAA Compliance: develop and uphold a HIPAA-compliant security posture across all Zenara systems, implementing access controls, managing secrets, maintaining audit logs, and enforcing encryption standards.
  • Monitoring, Alerting, and Incident Response: create monitoring and alerting capabilities to proactively identify issues before they affect users, establish incident response protocols, define SLOs, and lead the on‑call rotation.
  • AI Infrastructure Support: address AI infrastructure needs, including model serving, GPU provisioning (if necessary), and autoscaling for AI workloads, collaborating with the Head of AI.
  • Cloud Infrastructure Management: oversee cloud infrastructure (AWS/Azure), focusing on cost optimization, reliability, disaster recovery, and capacity planning.
  • SOC 2 Readiness: spearhead SOC 2 Type II preparedness, implementing controls, organizing evidence collection, and liaising with auditors.
  • Security Incident Response: take charge of security incident response, establishing procedures, conducting regular security evaluations, and responding to incidents.
Your First 90 Days

Week 1-2: Fully immerse yourself in the current infrastructure, deployment processes, and security posture. Identify the most significant security vulnerabilities and critical gaps. Build rapport through active listening and insightful inquiries.

Month 1: Set up basic monitoring and alerting systems. Outline the CI/CD roadmap. Begin documenting existing systems and security protocols. Establish communication channels with engineering leadership. Conduct initial threat assessments.

Month 2-3: Develop CI/CD pipelines for high-priority services with security gates. Implement secrets management and access controls. Create the first set of operational and security runbooks. Initiate SOC 2 gap analysis and planning for remediation. Introduce intrusion detection and vulnerability scanning.

Ongoing: Take on full ownership of infrastructure and security. Deliver reliable and secure systems. Establish compliance practices and enhance security standards. Assertively say "no" when risks are unacceptable. Inspire confidence in the CEO that infrastructure and security are in capable hands.

Values & Vibe (Who You Are)

You perceive infrastructure primarily through the lens of security and reliability, rather than merely uptime. You are the one who enters an unmanaged infrastructure landscape and brings order — not through an excess of tools, but through clarity, automation, and effective monitoring. For you, security is not a mere checklist; it shapes your worldview.

You possess an innate sense of paranoia — assuming systems are under threat and designing with that understanding. You recognize that healthcare compliance is mandatory and understand how to implement it practically, without hindering development speed.

You are hands‑on enough to diagnose production issues, write Terraform modules, and review security configurations — yet you know that your primary responsibility lies in creating systems that are both reliable and secure, rather than solely reacting to incidents. You have successfully built infrastructure in regulated sectors while adhering to compliance constraints.

You have considered issues related to security threats, compliance frameworks, and disaster recovery — moving beyond the simplistic notion of "we use AWS defaults." You understand the trade‑offs between security, cost, developer experience, and compliance requirements. When faced with uncertainty, your choice will always be security.

You are comfortable saying "no" when risks are unacceptable, even if it delays feature deployment. This is not obstruction; it is part of your role.

What Success Looks Like
  • The infrastructure is both reliable and secure — the CEO no longer concerns themselves with outages or breaches.
  • CI/CD pipelines are in place and delivering regularly — deployments become routine, low‑risk, and security‑gated.
  • The cybersecurity posture is robust — threat modeling is thorough, attack surfaces are minimized, and vulnerabilities are monitored for remediation.
  • The security posture is firm — access controls, audit trails, and secrets management are strictly enforced.
  • Monitoring and alerting systems identify issues before they are reported by users.
  • HIPAA compliance is systematic — we are audit‑ready without frantic preparations.
  • AI infrastructure supports production workloads reliably and cost‑effectively.
  • A security review process is established — any risky releases are identified and halted prior to shipping.
  • Incident response is documented and efficient — problems are resolved swiftly.
  • The infrastructure and security posture are more robust, reliable, and compliant than upon your arrival.
Requirements
Required
  • 5-10 years of experience in DevOps, SRE, or Platform Engineering — you have designed and maintained large‑scale production infrastructure.
  • A strong security mindset: naturally cautious, detail‑focused, and able to express concerns when risks are too high.
  • Familiarity with HIPAA, SOC 2, or healthcare compliance frameworks — you comprehend BAAs, audit trails, and regulatory obligations.
  • Proficient in AWS or Azure with infrastructure‑as‑code (Terraform, Pulumi, or CloudFormation).
  • CI/CD pipeline design and implementation (GitHub Actions, CircleCI, Jenkins, or similar).
  • Experience in container orchestration (Kubernetes, ECS, or equivalent).
  • Skills in cybersecurity: threat modeling, vulnerability assessment, intrusion detection, and incident response.
  • Strong English communication skills — you operate asynchronously and provide clear written documentation, incident reports, and architectural designs.
  • Experience in startup or high‑growth environments — you have thrived in situations marked by uncertainty, constrained resources, and pressing deadlines.
Strongly Preferred
  • Experience in supporting ML/AI infrastructure (model serving, GPU clusters).
  • Security expertise in healthcare SaaS (handling PHI, encryption at rest/transit, access auditing).
  • Background in penetration testing or security audits.
  • Prior experience with SOC 2 or HITRUST certification processes.
  • Knowledge of observability and monitoring tools (Datadog, Prometheus, Grafana, or similar).
Nice to Have
  • Understanding of FHIR/HL7 healthcare data standards.
  • Production experience with Kubernetes.
  • Acquainted with multi‑tenant SaaS security strategies.
  • Exposure to mental health or behavioral health sectors.
  • Experience with cloud infrastructure cost optimization.
  • Relevant security certifications (CISSP, CEH, or equivalent).
Schedule

Evening IST hours with 4-8 hours of daily overlap with US Pacific (9am‑5pm PT). You are welcome to propose a schedule that works best for you — our emphasis is on overlap and team availability rather than rigid clock‑in requirements. On‑call availability is expected during key security incidents.

Benefits
  • Salary between ₹22-35 LPA, based on your skills and responsibilities.
  • Fully remote work options available throughout India.
  • Provision for equipment allowance.
  • Acknowledgment of culturally significant local holidays (India).
  • Flexible paid leave options.
  • Direct and regular communication with the CEO — you will have direct access without any intermediaries.
  • Opportunity to build infrastructure and security practices from the ground up.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevOps & Security Engineer - AI-Native Healthcare SaaS
DevOps & Security Engineer - AI-Native Healthcare SaaS

Embedded Shishya • Gopalganj

Hybrid
INR 2,200,000 - 3,500,000
Remote work in India
Equipment allowance
Flexible paid leave
Head of AI - AI-Native Healthcare SaaS | Zenara Health
Head of AI - AI-Native Healthcare SaaS | Zenara Health

Zenara Health • India

Remote
INR 5,000,000 - 7,000,000
Salary range of ₹50-70 LPA
Fully remote work opportunities
Equipment allowance
+2
UI/UX Designer - AI-Native Healthcare SaaS | Zenara Health
UI/UX Designer - AI-Native Healthcare SaaS | Zenara Health

Zenara Health • India

Remote
INR 1,800,000 - 3,000,000
Salary range of ₹18-30 LPA
Fully remote opportunities
Comprehensive health insurance
+2
Senior Site Reliability Engineer
Senior Site Reliability Engineer

SourcingXPress • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Security and Compliance Lead – AI Agents (Healthcare)
Security and Compliance Lead – AI Agents (Healthcare)

100MS • Bengaluru

On-site
INR 5,000,000 - 8,000,000
Competitive salary
Significant ESOP grant
Comprehensive health insurance
+1
Senior Backend Engineer – AI-Native Care Orchestration Platform
Senior Backend Engineer – AI-Native Care Orchestration Platform

Azodha • Pune District

Hybrid
INR 1,200,000 - 1,800,000
Head of AI - AI-Native Healthcare SaaS | Zenara Health
Head of AI - AI-Native Healthcare SaaS | Zenara Health

Visa Hunt • India

On-site
INR 4,500,000 - 7,500,000
Senior Staff Platform Engineer
Senior Staff Platform Engineer

Zscaler • Bengaluru

On-site
INR 450,000 - 650,000
DevOps / Cloud Engineer
DevOps / Cloud Engineer

India Health Link • Chennai District

On-site
INR 1,800,000 - 2,400,000
Head of Marketing
Head of Marketing

xponentiate • India

Remote
INR 4,000,000 - 8,000,000
Equipment allowance
Remote work throughout India
Flexible paid time off
+1