Cloud Security Operations Engineer (GCP/AWS) - Remote

Medable

United States

Remote

USD 140,000 - 175,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote from start
Stock options
Annual performance-based bonus
Comprehensive health insurance

Job summary

Medable is seeking a skilled cloud security professional to secure multi-cloud infrastructure (GCP/AWS) and Kubernetes environments. You will triage alerts, lead remediation, and collaborate with DevOps to implement secure baselines.

Experience with AI security integrations and data protection is a plus. The role offers a fully remote arrangement from the US, with competitive compensation and stock options.

Qualifications

  • Bachelor's degree in cybersecurity, information technology or related field.
  • Hands-on experience securing cloud platforms (GCP/AWS) and Kubernetes.
  • Strong vulnerability management and incident response skills.

Responsibilities

  • Administer and optimize security posture across multi-cloud infrastructure (GCP/AWS).
  • Triage cloud security alerts, patching, and remediation activities.
  • Harden security configurations for Kubernetes environments and IAM.
  • Collaborate with DevOps to implement secure baselines and guardrails.
  • Support AI security integrations and data protection controls.
  • Provide evidence and reporting for SOC 2 / ISO-aligned controls.

Skills

Cross-functional
InfoSec
DevOps
Programming

Education

Bachelor's degree in Cybersecurity/IT or related field

Tools

GCP
AWS
Kubernetes
IAM
Terraform
CI/CD

Job description

Medable's mission is to get effective therapies to patients faster. We provide an end-to-end, agentic clinical trial platform with a flexible suite of tools that allows patients, healthcare providers, clinical research organizations and pharmaceutical sponsors to work together as a team in clinical trials. Our solutions enable more efficient clinical research, more effective healthcare delivery, and more accurate precision and predictive medicine. Our target audiences are patients, providers, principal investigators, and innovators who work in healthcare and life sciences.

Our vision is to accelerate the path to human discovery and medical cures. We are passionate about driving innovation and empowering consumers. We are proactive, collaborative, self-motivated learners, committed, bold and tenacious. We are dedicated to making this world a healthier place.

1. Responsibilities
  • Work cross-functionally with Information Security Operations and Infrastructure/DevOps teams, to administer and optimize security posture across multi-cloud (GCP/AWS) infrastructure, including native security services, IAM, logging, and threat detection.
  • Triage and respond to cloud security alerts and vulnerabilities; implement timely mitigations, configuration changes, and patches.
  • Own configuration and hygiene for cloud security consoles (examples: GCP Security Command Center, Cloud Logging, Cloud Armor, KMS, IAM , etc.).
  • Partner with DevOps to implement secure baseline configurations and guardrails (network segmentation, least privilege, encryption, key management, secrets handling, egress controls), in alignment with industry standard frameworks such as CIS, NIST 800-53, OWASP Top 10, etc.
  • Run day-to-day vulnerability workflows: detection, prioritization, remediation, and validation across cloud services, hosts, containers, and third-party dependencies.
  • Manage and harden security configurations for Kubernetes Engine environments, including:
    • Cluster and node security settings, RBAC, pod security controls, network policies, admission controls, and runtime security, Image vulnerability scanning, container supply-chain controls, patch cadence and version lifecycle management for clusters/nodes and supporting components.
  • Support secure implementations/integrations of AI within cloud infrastructure, including:
    • Data protection controls (PII/PHI handling, encryption, retention, audit logging).
    • Network controls (private connectivity where feasible, egress restrictions, proxying, allowlists).
    • Usage monitoring, abuse prevention, and security reviews for AI-driven features/workflows.
    • Contributing to internal AI security standards (prompt/data handling guidance, logging strategy, third-party risk considerations).
  • Work cross-functionally with IS Risk and Compliance team to produce evidence and reporting to support internal security requirements and external compliance obligations (e.g., SOC 2 / ISO-aligned controls, healthcare and privacy expectations).
  • Participate in security incident response for cloud-related events, including containment and recovery actions.
  • Other duties as assigned.
2. Experience
  • 4+ years of hands-on experience in cloud security, DevSecOps, cloud engineering with security focus, or security operations in cloud environments or a combination of education and experience.
  • Experience in healthcare technology and/or regulated environments (privacy, audit evidence, security control documentation).
  • Practical experience administering security controls in GCP and AWS (IAM, logging, encryption/KMS, network security, cloud security services).
  • Experience securing Kubernetes environments, including RBAC, cluster hardening, workload controls, and patch/version management.
  • Strong vulnerability management experience (triage, remediation coordination, patching workflows, validation).
  • Experience supporting secure integrations of LLM/AI services (e.g., ChatGPT/Grok) in production systems, including data governance and key management.
3. Skills
  • Ability to work cross-functionally between InfoSec and Infrastructure/DevOps, and translate security requirements into implementable controls.
  • Comfort working from tickets/alerts through to implemented changes in production cloud environments.
  • Comfortable writing code in any one programming language: Javascript/Python/Bash.
  • Familiarity with Infrastructure-as-Code and automation concepts (Terraform/CloudFormation, CI/CD pipelines, scripting).
4. Education, Certifications, Licenses
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or a related field preferred.
  • Security certifications (one or more): GCP Professional Cloud Security Engineer, CISSP, CCSP, Security+.
5. Travel Requirements

As required.

At Medable, we believe that our team of Medaballers is our greatest asset. That is why we are committed to your personal and professional well-being. Our rewards are more than just benefits - they demonstrate our commitment to providing an inclusive, healthy and rewarding experience for all our team members.

Flexible Work
  • Remote from the start, we believe in a flexible employee experience
Compensation
  • Competitive base salaries

  • Annual performance-based bonus

  • Stock options for employees, aligning personal achievements to Medable's success

Health and Wellness
  • Comprehensive medical, dental, and vision insurance coverage

  • Carrot Fertility Program

  • Health Saving Accounts (HSA) and Flexible Spending Accounts (FSA)

  • Wellness program (Mental, Physical and Financial)

Recognition
  • Peer-to-peer recognition program, celebrating achievements and milestones
Community Involvement
  • Volunteer time off to support causes you care about

Medable is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or would like to request an accommodation due to a disability, please contact us at hr@medable.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DevOps & Security Engineer
Senior DevOps & Security Engineer

careMESH • Washington

On-site
USD 120,000 - 160,000
Remote work flexibility
Quarterly meetings for collaboration
DevSecOps Engineer
DevSecOps Engineer

Claritas Rx • Northern (KY)

Hybrid
USD 130,000 - 160,000
Staff Site Reliability Engineer
Staff Site Reliability Engineer

Medallia, Inc. • McLean (VA)

Hybrid
USD 159,000 - 230,000
Senior Staff Security Engineer
Senior Staff Security Engineer

Hidden Jobs • United States

Remote
USD 150,000 - 210,000
Equity grants
Performance bonus eligibility
Education budget
+5
Senior Security Engineer - Application Security
Senior Security Engineer - Application Security

Socket.dev • New York (NY)

On-site
USD 150,000 - 185,000
Hybrid work schedule
18 vacation days
Stock options
+2
Cloud Security Engineer
Cloud Security Engineer

Gifthealth Inc • Columbus (OH)

On-site
USD 120,000 - 170,000
Cloud Engineering Manager
Cloud Engineering Manager

Modernizing Medicine, Inc. • United States

Hybrid
USD 150,000 - 210,000
Healthcare benefits
401(k) matching
Paid time off
Cyber Security Lead
Cyber Security Lead

Mednition • Burlingame (CA)

On-site
USD 140,000 - 230,000
Cyber Security Lead
Cyber Security Lead

Valid8 Financial, Inc. • Burlingame (CA)

On-site
USD 180,000 - 240,000
Security Operations Engineer
Security Operations Engineer

Hmixray • Somerville (MA), Northern (KY)

Hybrid
USD 120,000 - 180,000