DevSecOps Engineer | Remote from Pakistan | PKR Tax-free Salary

HR Ways

Sindh

Remote

PKR 27,739,000 - 44,383,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

HR Ways is seeking a DevSecOps Engineer for an early-stage healthtech SaaS startup in the Kingdom of Saudi Arabia. You will own the GCP infrastructure and security, shaping production access, data segregation, and governance as the first platform and security hire.

You will implement least-privilege access, build secure CI/CD with GitLab runners, and manage PostgreSQL operations while collaborating with cross-functional teams. Remote work offered with international scope.

Qualifications

  • You have carried production for a multi-tenant B2B SaaS with paying customers.
  • You have designed and enforced least-privilege access for a real engineering team.
  • An identity provider, role design, and the removal of access from people who had it.
  • Deep GCP knowledge: Cloud Run, Cloud SQL, VPC, IAM, Secret Manager, workload identity.
  • Terraform in production, including codifying an existing estate.
  • Extensive experience operating on GitLab.
  • CI/CD you built and made the only path, including runner and secrets hardening.
  • PostgreSQL operations — pooling, replicas, failover, a restore you ran.
  • You write code — enough Python or C# to open the merge request yourself.
  • Ability to work in cross-functional teams.
  • High proficiency in English communication.

Responsibilities

  • The path to production: merge requests, reviews, tests, staged rollout, rollback.
  • Identity & access: one identity provider across tools and prod data.
  • Secrets and devices: manage Secret Manager and rotation with owners.
  • Tenant operations: client onboarding with provisioning and data segregation.
  • Infrastructure as code: Terraform across the estate and safe defaults.
  • Audit & detection: tamper-evident logging and security alerts.
  • Observability & on-call: tracing across .NET and Python with SLOs.
  • PostgreSQL & real-time: pooling, replicas, failover, and restore drills.

Skills

Production for multi-tenant SaaS
Least-privilege access
Identity provider design
GCP expertise
Terraform in production
GitLab experienced
CI/CD pipelines
PostgreSQL operations
Python or C# scripting
Cross-functional collaboration
English communication

Tools

Cloud Run
Cloud SQL
VPC
IAM
Secret Manager
Workload identity
Terraform
GitLab
PostgreSQL
Python
C#

Job description

About the Company:

A technology and digital solutions company that helps businesses move complex digital initiatives forward through expertise in Artificial Intelligence (AI), cloud technologies, software delivery, and technical talent.

Role Overview - DevSecOps Engineer

Job Overview: You will work at an early-stage healthtech SaaSstartup in KSA. You own the GCP infrastructure and the security of the platform. How a change gets to production, how a clinic is provisioned with its data segregated from day one, who can touch what, and how we know. You are the first platform hire and the first security hire, so the conventions everyone inherits are yours.

Must Have:

  • You have carried production for a multi-tenant B2B SaaS with paying customers

  • You have designed and enforced least-privilege access for a real engineering team.

  • An identity provider, role design, and the removal of access from people who had it.

  • Deep GCP — Cloud Run, Cloud SQL, VPC, IAM, Secret Manager, workload identity

  • Terraform in production, including codifying an existing estate.

  • Extensive experience operating on GITLAB.

  • CI/CD you built and made the only path, including runner and secrets hardening.

  • PostgreSQL operations — pooling, replicas, failover, a restore you ran.

  • You write code — enough Python or C# to open the merge request yourself.

  • Ability to work in cross-functional teams.

  • High proficiency in English communication.

Responsibilities and ownership:

  • The path to production: The pipeline is the only way anything reaches a client: merge request, review, green tests, staged rollout, rollback that has been used. Migrations managed across environments. Hardened runners. Delivery that does not depend on who is awake.

  • Identity & access: One identity provider across GitLab, GCP, production data, and internal tools. Role-based access designed around what each engineer does, reviewed on a schedule, time-boxed elevation for the exception. Joining and leaving are checklists that run in under an hour.

  • Secrets, keys & devices: Secret Manager, masked CI variables, workload identity instead of long-lived keys, rotation with an owner. A minimum standard for the personal machines the team works from, and a way to verify it. Secrets never live on a laptop.

  • Tenant operations: Onboarding a client is a pipeline which includes provisioning, configuration, seeding, and a segregation model for deployment, data, and audit that is built in rather than bolted on.

  • Infrastructure as code: Terraform across the whole estate; environments that can be destroyed and recreated. Private data tier, controlled egress, edge protection, organisation policy that makes the safe thing the default.

  • Audit & detection: Who touched which system and who opened which patient record — tamper-evident, queryable, written to a sink you do not control. Alerts on what should never happen.

  • Observability & on-call: Tracing across .NET and Python so a booking is followable end to end. SLOs per clinical journey, alerts that page on a broken journey, a blameless incident process with post-mortems people read.

  • PostgreSQL & real-time: Pooling that survives Cloud Run scale-out, replicas, failover, restore drills actually run. WebSocket sessions that last a whole appointment, kept alive across scaling.

Good to have:

  • Healthcare or other regulated SaaS.

  • Understanding and experience of HIPAA, NPHIES, PDPL, and ISO 27001.

  • Kafka or Pub/Sub — we move to an event bus after the current direct-HTTP phase.

Other Details:

Experience:5+ years
Location: Remote

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote DevSecOps Engineer: Healthtech SaaS Cloud & Security
Remote DevSecOps Engineer: Healthtech SaaS Cloud & Security

HR Ways • Sindh

Remote
PKR 27,739,000 - 44,383,000
DevOps Engineer
DevOps Engineer

Mission.dev • Pakistan

On-site
PKR 1,800,000 - 3,000,000
DevOps / Cloud Engineer (AWS)
DevOps / Cloud Engineer (AWS)

BearPlex, Inc • Lahore

On-site
PKR 2,000,000 - 3,200,000
Senior peers
Production work
Lahore hybrid
+2
DevOps Engineer
DevOps Engineer

Technology Rivers, LLC • Islamabad

On-site
PKR 1,800,000 - 2,400,000
Company lunch facility
Healthcare benefits
Provident Fund (Employer Matching)
+3
Cloud Engineer
Cloud Engineer

Mission.dev • Pakistan

On-site
PKR 22,222,000 - 40,000,000
DevOps Engineer (Onsite, Karachi, PKR Salary)
DevOps Engineer (Onsite, Karachi, PKR Salary)

HR POD Careers • Karachi Division

On-site
PKR 2,400,000 - 3,600,000
Senior Site Reliability Engineer - (GCP) - Afternoon
Senior Site Reliability Engineer - (GCP) - Afternoon

10Pearls, LLC • Lahore, Karachi Division, Islamabad

On-site
PKR 2,000,000 - 3,000,000
DevSecOps Engineer
DevSecOps Engineer

Purelogics Llc • Lahore

On-site
PKR 1,200,000 - 2,000,000
Annual Paid Leaves
Leave Encashment
Paid Certifications
+7
Senior DevOps / Cloud Engineer (Azure)
Senior DevOps / Cloud Engineer (Azure)

Digifloat • Islamabad

On-site
PKR 3,000,000 - 5,400,000
GCP DevOps & Production Support Engineer
GCP DevOps & Production Support Engineer

Navigatorhr • Islamabad

On-site
PKR 2,790,000 - 3,348,000