Every day, healthcare providers across the country navigate systems that are supposed to make care better, faster, and more affordable — and too often don’t. Behind every claim, every quality measure, every interoperability standard is a doctor trying to treat a patient, a clinic trying to stay open, a family trying to understand their options.
At Octave, we partnered with the U.S. government to fix that. We’re looking for a DevSecOps and AI Ops engineer who is ready to bring those hard-won skills to a mission-critical program at the Centers for Medicare & Medicaid Services (CMS).
This role is for someone bold enough to challenge outdated assumptions, talented enough to translate complex healthcare operations into systems that actually work, and motivated by the simple fact that better healthcare IT means better digital experience for millions of people.
About Octave
At Octave, we’re on a mission that matters. We partner with the US government to build digital solutions that directly impact millions of Americans—from agile software development and human-centered design to cloud services, data analytics, and AI/ML. We’re a purpose-driven company where people come first, and many roles are fully remote.
The Role
We’re hiring a DevSecOps Engineer (AIOps) to support our IT operations, cloud infrastructure, and cybersecurity teams across CMS healthcare IT platforms. You’ll work across the full DevSecOps lifecycle — systems analysis and design, CI/CD and infrastructure-as-code, security controls embedded in the pipeline, and ongoing monitoring and modernization — in a program environment where compliance evidence matters as much as the engineering itself.
Where it genuinely helps, you’ll also bring AI into that work: using LLM-based agents and automation to speed up analysis, triage security findings, and cut down on noisy monitoring, always with a human reviewing anything that touches production or compliance posture. This isn’t a role about chasing AI for its own sake — it’s about applying it where it measurably reduces toil and risk in a regulated environment.
What You’ll Do
Provides information technology services in support of DevSecOps activities, including systems analysis, integration, design, development, implementation, and testing. Supports the development and maintenance of CI/CD pipelines, infrastructure as code, containerized environments, and automated configuration management solutions. Assists in integrating security controls and automated checks throughout the system development and deployment lifecycle to support compliance, risk reduction, and reliable system operations. Supports system modernization, deployment automation, monitoring, and performance optimization in alignment with technical, cybersecurity, and organizational requirements.
At Octave, that mandate carries an AI layer: where it genuinely reduces toil and risk, you’ll use LLM-based agents and automation to do the analysis, checks, and monitoring described below — not replace the engineering judgment behind them.
Applies AI/ML capabilities in accordance with CMS security, privacy, data governance, and responsible AI requirements.
Systems analysis, integration, design, development, implementation & testing
- Analyze existing systems and workflows to identify integration points, technical debt, and modernization candidates — using AI-assisted code and log analysis to speed up discovery on unfamiliar or legacy systems
- Participate in the design and development of DevSecOps tooling and integrations
- Support implementation and testing of new services and pipeline components, including automated test generation and AI-assisted test-case coverage analysis
- Document system designs, integration decisions, and test results clearly enough that another engineer — or an automation — can act on them
CI/CD pipelines, infrastructure as code, containers & configuration management
- Build and maintain CI/CD pipelines (GitLab CI, GitHub Actions, Jenkins, or similar) as reusable, versioned components
- Develop and maintain Infrastructure-as-Code (Terraform/CloudFormation) for AWS environments
- Support containerized environments on Kubernetes/EKS, including image build automation and registry management
- Maintain automated configuration management (Ansible, Puppet, or similar) across environments, using AI-assisted drift detection to flag configuration state that’s silently diverged from what’s declared
Security controls & automated checks across the SDLC
- Integrate security controls and automated checks — SAST/SCA, secrets scanning, IaC scanning, container scanning — directly into CI/CD pipelines
- Support software supply chain integrity: SBOM generation, artifact/image signing, and provenance tracking
- Assist in building AI-driven triage for security findings — correlating scanner output against actual runtime exposure in AWS/Kubernetes, prioritizing what’s real, and drafting remediation pull requests for engineers to review
- Support compliance evidence-gathering against HIPAA and, where contracts require it, NIST SP 800-171/CMMC controls
- Assist in threat modeling LLM-powered features against the OWASP LLM Top 10 (prompt injection, excessive agency, data leakage) as part of the standard security review
- Build and maintain monitoring and observability (CloudWatch, Prometheus, Grafana, or similar), including AI-assisted anomaly detection and alert correlation to cut down on noise and false pages
- Supports production troubleshooting, incident response, root-cause analysis, and implementation of corrective and preventive actions.
- Support performance optimization and cost efficiency across AWS workloads
- Contribute to system modernization efforts, retiring manual runbooks in favor of automated
What We’re Looking For
Required
- 4 years of experience in DevSecOps, systems engineering, including exposure to CI/CD pipelines and cloud infrastructure
- Working knowledge of AWS (IAM, networking, logging) and Infrastructure-as-Code tools (Terraform or CloudFormation)
- Familiarity with containerized environments (Docker, Kubernetes/EKS) and configuration management tooling (Ansible, Puppet, or similar)
- Exposure to security scanning and controls integrated into a development pipeline (SAST/SCA, secrets scanning, or similar)
- Comfort operating within a regulated environment and following documented compliance processes
- Solid understanding of the software development lifecycle (SDLC) and DevSecOps practices within Agile/Scrum or SAFe environments.
Preferred
- Experience with HIPAA-regulated systems or NIST SP 800-171/CMMC compliance work
- Familiarity with the OWASP LLM Top 10 and securing AI/ML models, agents, or data pipelines
- Software supply chain security exposure (SBOM tooling, artifact signing)
- Experience with monitoring/observability tooling (CloudWatch, Prometheus, Grafana, or similar)
- Practical, hands-on experience using LLM-based tools or agent frameworks for operational tasks
Why Octave
- Purpose-driven work. You’ll help modernize systems that touch the lives of millions of Medicare and Medicaid beneficiaries and the providers who care for them.
- A remote-first, people-first culture. We build teams around trust, flexibility, and doing meaningful work together — wherever you are.
- Real influence. Your expertise will directly shape the systems CMS and its healthcare provider and beneficiary community rely on every day.
- A team that has your back. You’ll join talented, mission-aligned colleagues who care as much about how the work gets done as what gets built.
Octave is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.