Information Security Development Engineer

Viva Health

Birmingham (AL)

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health Insurance
401(k) Plan
Paid Time Off
9 Paid Holidays + Floating Holiday
Tuition Assistance
Flexible Spending Accounts
Community Service Time Off
Life Insurance
Disability Coverage
Employee Wellness Program
Training and Development Programs

Job summary

VIVA HEALTH in Birmingham, AL is seeking an Information Security Development Engineer to integrate security across the SDLC and implement secure CI/CD pipelines and IaC practices. You will collaborate with software engineering, infrastructure, and compliance teams to embed risk management, automation, and governance in development processes.

The role focuses on secure design, threat modeling, vulnerability response, and regulatory compliance (HIPAA/HITECH).

Qualifications

  • Bachelor's Degree in Computer Science, Information Security, or related field; Work experience may substitute for education requirement
  • 4+ years’ experience in DevSecOps, site reliability engineering with a security focus or similar role
  • Strong experience with major cloud platforms (AWS, Azure) and cloud security best practices
  • Proven ability to build and manage CI/CD pipelines with integrated security controls (Jenkins, GitHub Actions, GitLab CI, Azure, DevOps)
  • Hands-on experience with Infrastructure as Code and configuration management (Terraform, CloudFormation, ARM/Bicep)
  • Proficiency with security tooling including SAST/DAST, dependency and container scanning, and cloud security posture management
  • Solid understanding of networking, IAM, encryption, key management, and secure architecture principles
  • Familiarity with healthcare regulations and frameworks (HIPAA, HITECH, CMS)
  • Strong communication and collaboration skills across engineering, security, compliance, and business teams

Responsibilities

  • Design, build, and maintain secure CI/CD pipelines, IaC, monitoring, threat detection, and compliance controls across applications, APIs, and cloud platforms
  • Oversee patching and maintenance throughout the software lifecycle
  • Partner with software engineering, infrastructure, compliance, and operations teams to embed security, risk management, and automation in the SDLC
  • Monitor, detect, and respond to security vulnerabilities and incidents including remediation and root-cause analysis
  • Maintain observability for systems and security events through logging, monitoring, and alerting actions
  • Support regulatory compliance and contribute to audits and control implementation (HIPAA, CMS)
  • Perform risk assessments and security architecture reviews for internal systems, cloud environments, and third-party vendors
  • Embed secure development practices, threat modeling, and security review gates into engineering workflows
  • Stay current on evolving threats, tools, and cloud best practices; drive adoption

Skills

DevSecOps
Site Reliability Engineering
Cloud Platforms (AWS/Azure)
CI/CD with security
Infrastructure as Code (Terraform,  CF
Security testing tools (SAST/DAST)
Networking & IAM & encryption
Regulatory compliance knowledge (HIPAA
Security collaboration

Education

Bachelor's Degree in CS/Info Security

Tools

Terraform
CloudFormation
ARM/Bicep
Jenkins
GitHub Actions
GitLab CI

Job description

Information Security Development Engineer

Job Category: Technical

Requisition Number: INFOR003057

  • Posted : July 23, 2026
  • Full-Time
Locations

Showing 1 location

Bham-Corporate Office
Birmingham, AL 35203, USA

Description

Information Security Development Engineer

Location: Birmingham, AL

Job Summary

The Information Security Development Engineer will partner closely with software engineering, infrastructure, compliance, and operations teams to integrate security, risk management, and automation throughout the software development lifecycle (SDLC). This role will help design, build, and maintain secure continuous integration/continuous delivery (CI/CD) pipelines, infrastructure as code (IaC), monitoring, threat detection, and compliance controls, especially healthcare-specific such as Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH).

This individual plays a key role in proactively identifying and mitigating risks, improving our security posture, and enabling rapid, reliable delivery of software and infrastructure changes. This position will oversee and manage patching and maintaining throughout the life cycle of the software.

Why VIVA HEALTH?

VIVA HEALTH, part of the renowned University of Alabama at Birmingham (UAB) Health System, is a health maintenance organization providing quality, accessible health care. Our employees are a part of the communities they serve and proudly partner with members on their healthcare journeys.

VIVA HEALTH has been recognized by Centers for Medicare & Medicaid Services (CMS) as a high-performing health plan and has been repeatedly ranked as one of the nation's Best Places to Work by Modern Healthcare.

  • Comprehensive Health, Vision, and Dental Coverage
  • 401(k) Savings Plan with company match and immediate vesting
  • Paid Time Off (PTO)
  • 9 Paid Holidays annually plus a Floating Holiday to use as you choose
  • Tuition Assistance
  • Flexible Spending Accounts
  • Community Service Time Off
  • Life Insurance and Disability Coverage
  • Employee Wellness Program
  • Training and Development Programs to develop new skills and reach career goals
  • Design, implement, and maintain secure CI/CD pipelines across applications, Application Programming Interfaces (APIs), and cloud platforms.
  • Develop and manage infrastructure as code with security-first principles. (Terraform, CloudFormation, ARM/Bicep)
  • Integrate automated security testing throughout the software development lifecycle. (SAST, DAST, dependency, and container scanning)
  • Embed secure development practices, threat modeling, and security review gates into engineering workflows.
  • Monitor, detect, and respond to security vulnerabilities and incidents including remediation and root-cause analysis.
  • Maintain observability for systems and security events through logging, monitoring, and alerting actions.
  • Support regulatory compliance and contribute to audits and control implementation. (HIPAA, HITECH, CMS)
  • Perform risk assessments and security architecture reviews for internal systems, cloud environments, and third-party vendors. Offer guidance, training, and promote security awareness across development and operations teams.
  • Stay current on evolving security threats, tool sets, frameworks, and cloud provider best practices. Recommend improvements and drive adoption.

REQUIRED QUALIFICATIONS:

  • Bachelor's Degree in Computer Science, Information Security, or related field; Work experience may substitute for education requirement
  • 4+ years’ experience in DevSecOps, site reliability engineering with a security focus or similar role
  • Strong experience with major cloud platforms (AWS, Azure) and cloud security best practices
  • Proven ability to build and manage CI/CD pipelines with integrated security controls (Jenkins, GitHub Actions, GitLab CI, Azure, DevOps)
  • Hands-on experience with Infrastructure as Code and configuration management (Terraform, CloudFormation, ARM/Bicep)
  • Proficiency with security tooling including SAST/DAST, dependency and container scanning, and cloud security posture management
  • Solid understanding of networking, IAM, encryption, key management, and secure architecture principles
  • Familiarity with healthcare regulations and frameworks (HIPAA, HITECH, CMS)
  • Strong communication and collaboration skills across engineering, security, compliance, and business teams

PREFERRED QUALIFICATIONS:

  • CSSLP, GSSP, Security+, SSCP
  • Experience with Kubernetes and container security
  • Familiarity with SRE and resilience practices

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Development Engineer
Information Security Development Engineer

Viva-Health • Birmingham (AL)

On-site
USD 110,000 - 160,000
Health Coverage
401(k) Plan
PTO
+1
Secure DevSecOps Engineer - CI/CD & Cloud Security
Secure DevSecOps Engineer - CI/CD & Cloud Security

Viva-Health • Birmingham (AL)

On-site
USD 110,000 - 160,000
Health Coverage
401(k) Plan
PTO
+1
Senior DevSecOps Engineer: Secure CI/CD & IaC
Senior DevSecOps Engineer: Secure CI/CD & IaC

Viva Health • Birmingham (AL)

On-site
USD 110,000 - 140,000
Health Insurance
401(k) Plan
Paid Time Off
+8
Cloud Security Engineer
Cloud Security Engineer

VIVA HEALTH • Birmingham (AL)

Hybrid
USD 90,000 - 130,000
Comprehensive Health, Vision, and Dental Coverage
401(k) Savings Plan
Paid Time Off (PTO)
+2
Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

Remote
USD 90,000 - 130,000
Security Engineer
Security Engineer

Birdi • Plymouth (MI)

Remote
USD 100,000 - 130,000
Security Engineer
Security Engineer

Healthmark Group • United States

Remote
USD 100,000 - 130,000
Network/Firewall Security Engineer - Information Tech (Onsite) (Days)
Network/Firewall Security Engineer - Information Tech (Onsite) (Days)

Tanner Health • Carrollton (GA)

On-site
USD 90,000 - 120,000
Information Security Engineer
Information Security Engineer

Vytalize Health • United States

On-site
USD 130,000 - 170,000
DevSecOps Engineer - Information Security
DevSecOps Engineer - Information Security

Elevance Health • Indianapolis (IN)

Hybrid
USD 120,000 - 180,000