DevOps Engineer

Oxbridge Health

Norwalk (CA)

On-site

USD 140,000 - 190,000

Full time

29 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Oxbridge Health runs healthcare data exchange, member-facing portals, and analytics platforms on AWS. You will own real systems end to end—not tickets handed down from an architecture group—building automation that makes compliance and access management boring.

Join a small team with a large surface area, extending TypeScript CDK stacks, deploying across many accounts, and shipping internal tooling including chatbots and Bedrock-backed solutions.

Qualifications

  • 4+ years in DevOps, SRE, platform, or cloud infrastructure engineering.
  • Deep, hands-on AWS: IAM, VPC networking, cross-account access.
  • Infrastructure-as-Code experience with AWS CDK; TypeScript preferred.
  • Production coding in TypeScript and/or Python.
  • CI/CD pipeline ownership with GitHub Actions, CodePipeline, or equivalent.
  • Containers on AWS: ECS or EKS, ECR, and related configs.
  • Linux administration: shell fluency, systemd/journalctl.
  • Identity systems: SSO/SAML/OIDC with least privilege.
  • Strong written communication for runbooks and incident notes.

Responsibilities

  • Build and maintain IaC estate using TypeScript AWS CDK across multiple platforms.
  • Own production services (ECS Fargate, Aurora, Lambda, API Gateway, S3, OpenSearch, etc.).
  • Deploy, monitor, right-size, and debug services in production.
  • Automate security and compliance with guardrails, IAM, and SOC 2/HIPAA requirements.
  • Run access management as a product (Okta SSO/SAML, SCIM, VPN provisioning).
  • Build internal tooling, including chat-native bots and LLM-backed tooling.
  • Improve CI/CD with GitHub Actions workflows, gates, and safe deploys.
  • Participate in on-call rotation for production infrastructure.

Skills

DevOps
SRE mindset
Clear written communication
Production coding
CI/CD ownership
Security awareness

Tools

AWS CDK
Terraform/CloudFormation
GitHub Actions
CodePipeline
ECS/EKS
OpenVPN

Job description

Role Description

Oxbridge Health runs healthcare data exchange, member-facing portals, and analytics platforms on AWS. Our infrastructure is a multi-account AWS Organization managed almost entirely as code—every environment, pipeline, and guardrail lives in a CDK repo and deploys through CodePipeline. PHI moves through our systems daily, so we operate under SOC 2 and HIPAA, and our security controls are automated rather than documented-and-hoped-for.

Oxbridge Health runs healthcare data exchange, member-facing portals, and analytics platforms on AWS. Our infrastructure is a multi-account AWS Organization managed almost entirely as code—every environment, pipeline, and guardrail lives in a CDK repo and deploys through CodePipeline. PHI moves through our systems daily, so we operate under SOC 2 and HIPAA, and our security controls are automated rather than documented-and-hoped-for.

We're a small team with a large surface area. You'll own real systems end to end—not tickets handed down from an architecture group. If you like building the automation that makes compliance and access management boring, this is that job.

Responsibilities
  • Build and maintain our IaC estate: We run a fleet of TypeScript AWS CDK repos (one per platform: message bus, SFTP exchange, OpenSearch, org policies, and more) deploying via CodePipeline into a dozen+ accounts. You'll extend existing stacks, split monoliths apart cleanly, and bootstrap new accounts into the pattern.
  • Own production services: ECS Fargate behind ALBs, Aurora, Lambda, API Gateway, S3, AWS Transfer Family for partner SFTP, OpenSearch, DMS replication. Deploy, monitor, right-size, and debug them.
  • Make observability actually catch things: CloudWatch alarms, Synthetics canaries, VPC flow logs, CloudTrail, log retention and redaction policies. We care about the difference between an alarm that exists and an alarm that pages someone.
  • Automate security and compliance: Service Control Policies as guardrails, IAM Identity Center permission sets, Prowler-driven evidence collection into WORM storage for SOC 2, secret scanning and SAST in PR pipelines. You'll help move controls from "reviewed quarterly" to "enforced continuously."
  • Run access management as a product: Okta SSO/SAML, SCIM provisioning, our OpenVPN Access Server fleet, and the approval-gated automation that provisions VPN and AWS access from a Jira ticket or a chat command.
  • Build internal tooling: A lot of our ops surface is chat-native: Google Chat bots and webhooks that review PRs, report compliance drift, page on-call, and provision access. Several are LLM-backed on Amazon Bedrock. You'll ship these, not just consume them.
  • Improve CI/CD: GitHub Actions workflows, PR gates, org rulesets, auto-merge policy, deployment safety (changeset previews before anything touches prod).
  • On-call rotation: Participate in on-call for production infrastructure.
Qualifications
  • 4+ years in DevOps, SRE, platform, or cloud infrastructure engineering.
  • Deep, hands-on AWS: You can reason about IAM trust policies, VPC networking, and cross-account access without a diagram.
  • Real Infrastructure-as-Code experience: AWS CDK strongly preferred; Terraform/CloudFormation background transfers fine, but you'll be writing TypeScript CDK here.
  • Production Coding: Comfortable writing production code, not just config (TypeScript and/or Python).
  • CI/CD Pipeline Ownership: GitHub Actions, CodePipeline, or equivalent.
  • Containers on AWS: ECS or EKS, image builds, ECR, task/service configuration.
  • Linux Administration: Shell fluency; comfortable on a box with systemctl, journalctl, and no GUI.
  • Identity Systems: SSO/SAML/OIDC, IAM roles vs. users, least privilege in practice.
  • Clear Written Communication: Our runbooks, PR descriptions, and incident notes are how the team scales.
Optional Qualifications
  • Healthcare, fintech, or another regulated environment; HIPAA or SOC 2 audit experience.
  • AWS Organizations at scale: SCPs, Control Tower, Identity Center, multi-account CDK bootstrapping.
  • Data platform exposure: Glue, Athena, QuickSight, Lake Formation, DMS.
  • Amazon Bedrock or other LLM API work—we build with Claude and are actively expanding internal AI tooling.
  • Windows Server administration via SSM (a slice of our analytics estate is Windows).
  • OpenVPN Access Server, Cloudflare, Route 53 at an operational level.
  • Next.js / React—several internal dashboards are full-stack and you'd own them soup to nuts.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevOps Engineer
DevOps Engineer

Oxbridge Health, Inc. • Norwalk (CT)

On-site
USD 120,000 - 160,000
DevOps Engineer
DevOps Engineer

Jobless • Norwalk (CT), Northern (KY)

Hybrid
USD 120,000 - 180,000
DevOps Engineer (local)
DevOps Engineer (local)

Pitch Aeronautics • Idaho

On-site
USD 120,000 - 180,000
Health Insurance
Dental & Vision Insurance
120 hrs of paid time off
+5
DevOps Engineer DevOps Engineer
DevOps Engineer DevOps Engineer

Kurai • Seattle (WA)

On-site
USD 120,000 - 180,000
Senior Software Engineer, Platform (Developer Experience)
Senior Software Engineer, Platform (Developer Experience)

ECP • Chicago (IL)

On-site
USD 140,000 - 190,000
DevSecOps / Platform Engineer (Boston preferred)
DevSecOps / Platform Engineer (Boston preferred)

RightMove Health LLC • Boston (MA)

On-site
USD 100,000 - 130,000
Sr DevOps Engineer
Sr DevOps Engineer

Clarity Rcm • Indiana (PA)

On-site
USD 140,000 - 190,000
Senior Software Engineer, Platform (Developer Experience)
Senior Software Engineer, Platform (Developer Experience)

Ecp123 • Chicago (IL), Northern (KY)

Hybrid
USD 140,000 - 210,000
DevSecOps / Platform Engineer (Boston preferred)
DevSecOps / Platform Engineer (Boston preferred)

RightMove • Boston (MA)

On-site
USD 100,000 - 130,000
Sr. Python Full Stack Engineer
Sr. Python Full Stack Engineer

QMD Scientific • Sandy Springs (GA)

On-site
USD 130,000 - 180,000