About the Role
Join our small, high-trust Infrastructure team as its second engineer, reporting to the Director of Infrastructure and partnering closely with our product engineering team. You will drive two key initiatives: building a cohesive AWS foundation with Terraform, Control Tower, and AFT, and owning end-to-end security engineering for our production PHI and Bedrock AI workloads. Just as important, you'll build the paved paths, self-service tooling, and guardrails that let our engineers ship quickly. AI is deeply embedded in how we work. We use it across coding, testing, and operations, not because of a mandate but because we've seen what it unlocks. We're looking for someone who already builds this way and is curious about what AI-augmented practice looks like in infrastructure and security work. We value fast decisions, open feedback, and empowered engineers.
Responsibilities
- Own the Terraform codebase, including module design, state strategy, drift detection, and plan review discipline.
- Manage the migration of CloudFormation/Serverless footprint to Terraform where it provides leverage without stalling product delivery.
- Oversee the AWS landing zone, including multi-account structure via Control Tower and AFT, account vending, customizations, service control policies, and OU design.
- Implement security engineering using Security Hub, GuardDuty, Inspector, and Config for detection tooling, including triage, tuning, and vulnerability lifecycle management.
- Coordinate penetration tests and own remediation efforts.
- Secure the commit-to-production path in GitHub Actions, focusing on least-privilege OIDC deployment roles, secrets scanning, SAST and dependency/container gates, branch protection, and artifact integrity.
- Develop paved-path tooling, self-service infrastructure, and secure defaults to enable product engineers.
- Manage disaster recovery and backup strategies, including RPO/RTO targets, Aurora point-in-time recovery, and regular DR testing for HIPAA compliance.
- Implement compliance as code for SOC 2 and HIPAA controls, including encryption, KMS, CloudTrail/Config coverage, and automated evidence collection.
- Govern identity and access, including IAM Identity Center, cross-account roles, SSO, access reviews, and deprovisioning.
- Manage network foundations such as VPC design, WAF, and Client VPN.
- Contribute to security architecture for Bedrock AI workloads, including access controls, guardrails, and PHI data boundaries.
- Participate in production incident response for reliability and security, and focus on recurrence prevention.
- Enhance observability and cost visibility through CloudWatch, alarms, dashboards, and tagging.
- Partner with application engineers on Lambda, Aurora PostgreSQL, and Bedrock workloads.
- Conduct lightweight threat modeling and security reviews of new features and third-party integrations involving PHI.
Requirements
- 5+ years in DevSecOps, security, platform, or infrastructure engineering, operating production systems.
- Demonstrated security ownership, including vulnerability management, remediation, and incident response.
- Deep Terraform proficiency, including module hierarchies, multi-environment state, drift and refactors, and critical plan review.
- Hands-on experience with AFT and Control Tower, including vending accounts and customizing the pipeline.
- Broad AWS knowledge, including IAM, Organizations, VPC, Lambda, RDS/Aurora, S3, KMS, CloudTrail, Config, Security Hub, GuardDuty, and Secrets Manager.
- Proficiency with GitHub Actions, including pipeline hardening and secrets management.
- Experience with SOC 2 Type II and HIPAA in a PHI-handling environment, including owning controls and producing evidence.
- Strong change and release discipline, with experience in deployment and rollback strategies in regulated environments.
- Ability to write code daily, take ambiguous problems to documented decisions, and explain security tradeoffs.
- Daily use of AI coding and automation tools, with an active exploration of their impact on infrastructure and security practices.
- Genuine interest in improving clinical trial access and health equity.
Skills
- Terraform
- AWS
- Control Tower
- AFT
- Security Engineering
- IAM
- Organizations
- VPC
- Lambda
- RDS/Aurora
- S3
- KMS
- CloudTrail
- Config
- Security Hub
- GuardDuty
- Secrets Manager
- GitHub Actions
- DevSecOps
- Vulnerability Management
- Incident Response
- Compliance Automation
- Python
- TypeScript
- LLM Security
Location
- San Francisco, CA
Work Type
- Hybrid
Experience Level
- 5+ years
Salary/Compensations
- $168,000 - $205,000
Benefits
- Comprehensive medical, dental, and vision coverage
- Disability, life, and supplemental insurance options
- Flexible paid time off
- Observed company holidays
- One-time home office stipend
- 401(k) program
- Pre-tax HSA and FSA options
- Commuter benefits
- Financial wellness resources
- Access to legal protection plans
- Pet wellness support
- Domestic partner coverage
About the Company
- Trial Library is an AI-native research platform with a mission to improve healthcare outcomes by expanding access to precision medicine.
- Trial Library is an AI-native enrollment and care navigation platform that accelerates access to precision medicine.
- In collaboration with biopharmaceutical manufacturers, payers, and health systems, Trial Library enables the delivery of clinical trials as a standard care option - improving patient access, advancing oncology outcomes, and reducing the total cost of care.
- Backed by leading healthcare venture capital firms, Trial Library’s platform is currently deployed in 840+ clinics and 3,000+ providers nationwide.
Equal Opportunity
- Trial Library, Inc. is an equal opportunity employer committed to building an inclusive workplace. We provide equal employment opportunities to all employees and applicants and prohibit discrimination and harassment of any kind without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, national origin, ancestry, age, disability, genetic information, marital status, veteran status, military status, medical condition, family or medical leave status, political affiliation, or any other characteristic protected by applicable federal, state, or local law.
- Trial Library, Inc. is committed to providing reasonable accommodations for qualified individuals with disabilities throughout the recruiting process. If you require assistance or accommodation, please contact jobs@triallibrary.com
