Full Time

DevOps Engineer, Security

Posted 1 month ago by Doximity
Application ends: June 30, 2023
Apply Now

Job Description

Time zones: EST (UTC -5), CST (UTC -6), MST (UTC -7), PST (UTC -8), AKST (UTC -9), HST (UTC -10), ART (UTC -3), UTC -4, UTC -4:30, UTC -3, UTC -2

Doximity is transforming the healthcare industry. Join our mission to help every physician be more productive and provide better care for their patients. As medicine’s largest network in the United States, there’s an elevated level of responsibility in everything we do. We don’t take that responsibility lightly and are committed to building diverse teams with an inclusive culture that can make a direct impact on the healthcare system.

One of Doximity’s core values is stretching ourselves. Even if you don’t check off all the boxes below we encourage you to apply. Doximity is full of exceptional people who bring their own unique experiences to work everyday and make us all better for it!

We are looking for an experienced DevOps engineer to join our growing Infrastructure and Application Security team. You will contribute and own Security efforts for our entire application and infrastructure stack as well as support and build products alongside our 300+ person engineering team used by millions of medical professionals. 

This role can be filled in our San Francisco Headquarters or remotely in the U.S.


How you’ll make an impact:

  • Help maintain our private security bug bounty program hosted onhackerone: this involves engaging security researchers, validating security finds, determining impact/risk, awarding bounties, and fixing or coordinating remediation efforts.
  • Develop, schedule, and execute automated security audits on infrastructure using industry standard security frameworks and tooling.
  • Help set good security posture; this includes: finding bad security habits and encapsulating good secure defaults into libraries/modules with tools such as ansible, chef, terraform, helm charts, ArgoCD, kubernetes, etc that other teams will leverage. 
  • Write and perform penetration tests for applications and infrastructure.
  • Active participation in design, implementation, and maintenance of the development, staging, and production infrastructure and application security.
  • Work on automating tasks using tools such as Terraform, Ansible, Chef (legacy), kubernetes, etc.
  • Analyze HTTP traffic to create and update WAF rules to reduce the effectiveness of malicious bots, scrappers, and attackers
  • Lead security/policy related audits such as SOC2 Type II.
  • Works with key stakeholders to document existing security policies and create new ones.
  • Remediate and write post-mortem reports on security-related issues.
  • Work with developers to deploy applications ready for production in a secure manner.
  • Perform Threat Hunting on a regular basis
  • Create security observability using a variety of tools such as SIEM, CSPM, IDS, etc
  • Hands-on maintenance on our Ruby on Rails and Go (Golang) applications.
  • Troubleshoot issues across the whole stack: hardware, software, and network.
  • Periodically audit and rotate access credentials.
  • Work with IT as an escalation point on behalf of sales and client services teams to answer application or infrastructure-related security questions and concerns that clients inquire about.


What we’re looking for:

  • A “Hacker Mindset”
  • Minimum of 5 years of Linux/UNIX systems engineer & administrator experience.
  • Minimum of 2 years of relevant web application or infrastructure security experience. It does not need to be a security-specific position. The most important thing is passion/desire for security.
  • Extensive AWS experience
  • Automation experience with configuration and resource management tools such as Terraform (preferred), Ansible, Chef, Puppet, or Cloudformation.
  • Proficient in bash shell scripting and one of Ruby, Python, or Golang.
  • Experience with CI and CD using tools such as Github Actions, Atlantis, Jenkins, circleci, rspec, serverspec, inspec, test kitchen, etc.
  • Ability to work in a proactive manner


Nice to haves

  • Experience writing application and/or security penetration tests with an open source framework.
  • Intermediate to advanced experience administering and securing an RDB.
  • Experience with Kubernetes (or other schedulers), Grafana, Prometheus.


Additional Role Expectations

  • You’ll be asked to maintain a minimum of 5 hours overlap with 9:30 to 5:30 PM Pacific time.
  • Participate in a 1-week on and 5 weeks off, 24/7 on-call rotation.
  • Travel to company offsites once/quarter is expected


Compensation

The US total compensation range for this full-time position is $135,000 – $190,000 (inclusive of salary + equity) Our ranges are determined by role and level. The range displayed on each job posting reflects the approximate total target compensation for the position across the US. Within the range, individual pay is determined by factors including relevant skills, experience, and education/training. Please note that the compensation listed does not include benefits.