About the Role
Secure, scale, and operate the infrastructure powering AI front desk services and CRM Software that are transforming how local governments and organizations provide service to their communities. Own security and infrastructure end-to-end, from threat modeling and compliance program management to CI/CD, observability, incident response, and hardening our AWS environment.
Responsibilities
- Own cloud security posture across AWS (ECS Fargate, Aurora PostgreSQL, SQS, CloudFront, IAM, WAF, GuardDuty, Security Hub) and harden it against evolving threats
- Drive compliance programs end-to-end: SOC 2 Type II, HIPAA, and path to StateRAMP / FedRAMP authorization, including evidence collection, policy authorship, and auditor management
- Design and operate CI/CD pipelines, IaC (Terraform/CDK), and deployment workflows that make the secure path the easy path
- Build and maintain infrastructure-as-code that codifies environments, enforces guardrails, and makes infrastructure changes auditable and repeatable
- Lead application security: threat modeling, secure code review, dependency and container scanning, secrets management, and remediation guidance for engineering teams
- Build observability and incident response capabilities, including logging, alerting, runbooks, on-call rotations, and post-incident reviews
- Manage identity and access at scale, including SSO/SAML, least-privilege IAM, and tenant isolation for multi-tenant architecture
- Respond to customer security questionnaires, support sales on security and compliance asks from government procurement teams, and represent security program externally
- Partner with engineering to embed security and reliability into the product
Requirements
- 4+ years of combined experience in security engineering and DevOps / infrastructure / SRE roles
- Hands-on production experience with AWS, Linux, containers (Docker/ECS/EKS), and infrastructure-as-code
- Working knowledge of at least one major compliance framework (SOC 2, HIPAA, FedRAMP, StateRAMP, ISO 27001), ideally having helped take an organization through audit or authorization
- Strong fundamentals in application security, cloud security, and identity (OAuth/OIDC, SAML, IAM)
- Comfortable writing code to automate security and ops workflows
- Experience in govtech, healthcare, fintech, or other regulated industries
- Familiarity with FedRAMP/StateRAMP 3PAO process
- CISSP, OSCP, or AWS Security certifications
Skills
- AWS
- Linux
- Docker
- ECS
- EKS
- Terraform
- CDK
- SOC 2
- HIPAA
- FedRAMP
- StateRAMP
- ISO 27001
- Application Security
- Cloud Security
- Identity Management
- OAuth
- OIDC
- SAML
- IAM
- CI/CD
- Infrastructure-as-Code
- Observability
- Incident Response
- Threat Modeling
- Secure Code Review
- Container Scanning
- Secrets Management
- SSO
Location
- Remote
Work Type
- Full-time
Experience Level
- 4+ years
About the Company
- Helping state and local governments deliver better service to their residents with modern, AI-powered tools.
- Partnered with over 200 government departments across cities, counties, and states to dramatically improve customer service.
- Service demands are growing and resources remain constrained.
