Ellipsis Health · 3 months ago
DevSecOps Lead – Healthcare AI
Ellipsis Health is a healthcare technology company seeking an experienced DevSecOps Leader to foster a security-first culture within their engineering organization. The role focuses on establishing and leading DevSecOps practices, ensuring compliance with healthcare regulations, and securing the AI/ML product suite.
Artificial Intelligence (AI)Health CareInformation TechnologySoftware
Responsibilities
Establish DevSecOps: Architect, implement, and lead the company’s DevSecOps program, embedding security practices, automation, and tooling directly into the CI/CD pipeline for our core AI/ML platform
Ensure all development and operational practices adhere to healthcare regulations, including HIPAA, SOC2 and HITRUST, maintaining a continuous state of compliance
Define the long-term security strategy for our cloud-native infrastructure (e.g., Kubernetes, serverless) and MLOps environment, prioritizing security-by-design
Implement automated security testing tools (SAST, DAST, SCA, IAST) in pre-production environments
Secure cloud infrastructure (e.g., Terraform/CloudFormation) and container orchestration platforms (Kubernetes/Docker) through configuration hardening, policy enforcement, and drift detection
Design and manage secrets management solutions, key management services (KMS), data encryption at rest and in transit, and secure data access controls, particularly for sensitive Protected Health Information (PHI)
Collaborate with application development teams to advise on secure coding practices, API security, and vulnerability remediation
Conduct regular threat modeling exercises for new features and system architecture changes
Develop and maintain incident response plans for security events, leading the coordination and post-mortem analysis of security incidents
Respond to system outages and breaches, to coordinate prompt recovery of services and data
Oversee log aggregation, security information and event management (SIEM), pen testing and real-time vulnerability scanning
Ensure that our infrastructure remains highly available at scale for our customers and partners
Qualification
Required
8+ years of experience in Information Security, with 3+ years in a leadership role driving DevSecOps transformation
Deep practical experience securing cloud environments (preferably GCP) and modern infrastructure components (Containers, Kubernetes, Serverless)
Expertise in healthcare compliance standards (HIPAA/HITRUST) and demonstrable experience implementing controls required for certification/audit
Proficiency with CI/CD tools (e.g., GitLab CI, GitOps, etc.) and implementing security gates
Strong knowledge of networking, operating systems, identity and access management (IAM), and encryption technologies
Bachelor's degree in Computer Science, Information Security, or a related field
Preferred
Experience with MLOps security, including securing data pipelines, model registries, feature stores, and adversarial robustness testing for AI models
Security certifications such as CISSP, CISM, or relevant cloud security certifications (e.g., AWS Security Specialty, Google Cloud Professional Security Engineer)
Experience in a fast-paced, high-growth healthcare technology startup or scale-up environment
Benefits
401k that matches up to 4% of your salary
Health, vision, and dental insurance
Very flexible paid time off
Company
Ellipsis Health
AI Nursing Care Manager
H1B Sponsorship
Ellipsis Health has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (6)
2024 (1)
2023 (2)
2021 (1)
Funding
Current Stage
Early StageTotal Funding
$75.02MKey Investors
SJF VenturesKhosla Ventures
2025-06-12Series A· $45M
2021-06-15Series A· $26M
2021-01-13Seed
Recent News
2025-10-22
Company data provided by crunchbase