Senior DevSecOps Engineer - (DCFIL)
About the role
We are looking for a hands-on Senior DevSecOps Engineer to own the security, reliability, delivery platform, and day-to-day operability of the Digital Customer First Innovation Lab (DCFIL). DCFIL is a cloud-native medical-imaging research platform that manages DICOM data, enables annotation and algorithm workflows, and maintains compliance-grade audit trails. You will provide the DevSecOps capability that allows product teams to deliver safely and independently. You will build and operate secure AWS/Kubernetes foundations, improve engineering delivery and operational visibility, and make security controls practical for developers. This is a technical ownership role, not a people-management-only role.
What you will do
- Own the platform-level DevSecOps posture across development, test, and production environments, including operational readiness, availability, security, cost, and lifecycle management.
- Operate and evolve the Kubernetes platform: AWS EKS, Karpenter, Helm/Kustomize, Argo CD GitOps, ingress/load-balancing, pod autoscaling, disruption budgets, health probes, and resource governance.
- Own and evolve CI/CD engineering across Azure DevOps Pipelines and GitHub Actions, including the migration of pipelines and delivery controls to GitHub; manage Amazon ECR, image promotion, Git based environment promotion, and safe rollback/recovery practices.
- Build security into delivery and runtime: container and dependency scanning, SBOM and vulnerability management, image provenance, least-privilege IAM/IRSA, secrets management, certificate lifecycle management, and policy-as-code with Kyverno.
- Maintain the platform's zero-trust model: default-deny Kubernetes NetworkPolicies, explicit service-to-service rules, secure ingress/egress, TLS configuration, and secure internal communications.
- Operate identity and access components in partnership with product teams, including Dex/OIDC federation, JWT validation patterns, role/claim security, session controls, and integration with enterprise identity providers.
- Manage AWS platform services used by DCFIL, particularly S3, DocumentDB, SQS/DLQs, ALB, ECR, Secrets Manager, CloudWatch/AWS health signals, and backup/recovery controls.
- Protect sensitive medical-imaging data by implementing sound controls for data access, encryption, retention/lifecycle, auditability, and separation of Quarantine Zone and Hospital Data ready datasets.
- Establish observability standards and dashboards using OpenTelemetry/OTLP, Prometheus, Grafana, Fluent Bit, structured logs, traces, and actionable alerting. Drive incident diagnosis and service reliability improvements.
- Lead patching and technology-lifecycle management for AWS services, AMIs/base images, Kubernetes add-ons, CI/CD dependencies, and infrastructure components; assess and remediate relevant security advisories.
- Partner with software engineers and technical leads to define production-ready service templates, deployment standards, SLOs, capacity assumptions, failure testing, and secure-by-default patterns.
- Support quality and compliance evidence appropriate for a medical-imaging research platform, including traceable security controls, audit evidence, SOUP/dependency awareness, and IEC 62304 Class A engineering practices.
- Improve cloud cost visibility and drive pragmatic optimisation without compromising availability, security, or developer productivity.
- Contribute to DCFIL's portability direction by keeping service deployment patterns compatible with future sovereign-cloud Kubernetes environments, while operating AWS EKS as the current reference platform.
The platform you will work with
- AWS: EKS, S3, DocumentDB, SQS, ALB, ECR, IAM/IRSA, Secrets Manager, CloudWatch and related security services.
- Kubernetes and delivery: Argo CD, Helm, Kustomize, Karpenter, Crossplane, cert-manager, External Secrets Operator, Kyverno, Azure DevOps Pipelines, and GitHub Actions.
- Security and identity: Dex, OAuth 2.0/OIDC, JWT, RBAC, NetworkPolicies, TLS, secrets and certificate management.
- Observability: OpenTelemetry/OTLP, Prometheus, Grafana, Fluent Bit, distributed tracing and structured logging.
- Workloads: C++20 and .NET microservices, WebAssembly-based frontends, DICOMweb APIs, S3-backed binary data, and MongoDB-compatible data stores.
What you bring
- 5+ years of hands-on DevOps, platform engineering, SRE, cloud security, or DevSecOps experience, including production responsibility for Kubernetes-based systems.
- Strong practical experience with AWS and Amazon EKS, including networking, IAM, managed storage/queues, container registry, and multi-environment operations.
- Strong Kubernetes expertise: workload design, autoscaling, networking, ingress, RBAC, policies, troubleshooting, upgrades, and resource management.
- Experience with GitOps and infrastructure-as-code. Argo CD, Helm, Kustomize, Terraform, and Crossplane experience is highly relevant.
- Experience migrating or operating CI/CD workflows in GitHub Actions, alongside Azure DevOps during a phased migration.
- Experience designing secure CI/CD pipelines and integrating vulnerability scanning, supply-chain controls, policy checks, and release governance.
- Solid understanding of cloud and Kubernetes security: least privilege, IAM/IRSA, secrets, certificates, network segmentation, runtime hardening, and incident response.
- Practical experience with observability and operational diagnostics, including metrics, logs, traces, alerting, and root-cause analysis.
- Ability to work directly with developers: simplify platform complexity, set clear engineering standards, and solve real delivery problems.
- Strong written communication and an ownership mindset; able to turn operational risks into prioritised, actionable work.
Advantageous experience
- Healthcare, medical-imaging, DICOM/DICOMweb, or other regulated-data environments.
- Working knowledge of IEC 62304, ISO 27001, privacy/data-residency requirements, audit controls, or software-of-unknown-provenance management.
- Experience with DocumentDB/MongoDB-compatible stores, S3 data lakes, or event-driven systems using SQS.
- Experience supporting OpenShift, OpenStack, RKE2, or other sovereign/private-cloud Kubernetes environments.
- Relevant certifications such as CKA/CKS, AWS Solutions Architect, AWS Security Specialty, or equivalent demonstrated experience.
What success looks like
Within the first year, DCFIL has a clearly owned, repeatable, and secure delivery platform: reliable GitOps deployments; healthy, observable services; timely patching and vulnerability remediation; tested recovery paths; useful operational dashboards and alerts; clear cloud-cost accountability; and developers who can ship product changes safely with minimal platform friction.
How we work together
We believe that we are better together than apart. For our office-based teams, this means working in-person at least 3 days per week. Onsite roles require full-time presence in the company’s facilities. Field roles are most effectively done outside of the company’s main facilities, generally at the customers’ or suppliers’ locations. Indicate if this role is an office/field/onsite role.
About Philips
We are a health technology company. We built our entire company around the belief that every human matters, and we won't stop until everybody everywhere has access to the quality healthcare that we all deserve. Do the work of your life to help the lives of others. At Philips, we believe that every human matters. As a global health-tech leader, we focus on improving people’s health and wellbeing through meaningful innovation. The people who work here share our passion and are motivated to bring this purpose to life. For more than 130 years, we have created technologies and innovations that improve people’s lives and support healthcare practitioners. Headquartered in the Netherlands and operating in more than 100 countries globally, we focus our advanced technology and deep clinical and consumer insights on Precision Diagnosis, Image Guided Therapy, Enterprise Informatics, Monitoring/ Connected Care, Sleep & Respiratory Care and Personal Health. Together, we deliver better care for more people because we believe that every human matters. That's why we're taking steps to create an environment where we acknowledge and embrace our differences and uniqueness and listen to and value each other's views. When people feel cared for and listened to, they bring their best qualities to work, leading to better collaboration, communication, innovation and success.
Equal Employment & Opportunity
It is the policy of Philips to provide equal employment and advancement opportunities to all qualified employees and applicants for employment without regard to race, color, religion, sex, pregnancy/childbirth or related medical conditions, age, ethnic or national origin, sexual orientation, gender identity or expression, physical or mental disability, genetic information, citizenship status, veteran or military status, marital or domestic partner status or any other characteristic protected by law. As an equal opportunity employer, Philips is committed to fostering a culture where all are treated with respect and professionalism.
Accommodations
To ensure reasonable accommodations for individuals protected by Section503 of the Rehabilitation Act of 1973, the Vietnam Veterans' Readjustment Act of 1974 and TitleI of the Americans with Disabilities Act of 1990, applicants that require accommodation in the job application process may contact888‑367‑7223, option5, for assistance.
Additional Information
Philips is an Equal Employment and Opportunity Employer including Disability/Vets and maintains a drug‑free workplace. Know Your Rights