Back to all jobs

DevOps & Security Engineer at Zenara Health

WeWorkRemotely
Apply NowSign in to track
AI-enhanced for better readability

Zenara Health: DevOps & Security Engineer - AI-Native Healthcare SaaS

Headquarters: India
Source: weworkremotely

About the Company

Zenara Health is a mental healthcare organization driven by technology, aiming to improve the accessibility and quality of mental wellness services. By integrating AI-driven platforms with professional clinical care, we deliver personalized and effective mental health solutions, creating a smooth digital experience for both patients and providers. We operate as a startup, distinct from a mere department.

Why This Role Exists

This position serves as the company's foremost line of defense.

You will operate under the assumption that systems are constantly under threat, crafting infrastructure that is resilient, auditable, and inherently secure. You will be the most risk-aware individual in the startup — and that’s exactly what we require. While others concentrate on feature rollout, you will prioritize the security of patient data, regulatory compliance, and system integrity.

About the Role

If your understanding of DevOps is limited to "I occasionally execute kubectl apply," this position is likely not for you. This role is not suited for those who prioritize speed over safety or view security as an afterthought. At Zenara, safeguarding patient data and maintaining system integrity takes precedence over rapid deployment.

Our team is developing a platform that manages clinical data, operates AI workflows, and processes insurance billing within a HIPAA-regulated environment. You will be responsible for Zenara’s infrastructure, security posture, and compliance engineering from the ground up. You will have a dual mandate: ensure the stability and security of the platform while also building the necessary infrastructure for AI at scale.

What You Will Own

  • Cybersecurity & Threat Defense: Manage threat modeling, reduce attack surfaces, oversee intrusion detection, handle vulnerability management, and plan incident responses. You will be the final reviewer for infrastructure and security risks.
  • CI/CD and Deployment Automation: Design and implement CI/CD pipelines, establish deployment automation, manage environments, and set quality thresholds to eliminate chaotic releases.
  • Security Posture and HIPAA Compliance: Develop and uphold a HIPAA-compliant security posture, including access controls, secrets management, audit logs, and encryption standards.
  • Monitoring, Alerting, and Incident Response: Create monitoring and alerting capabilities, define service level objectives (SLOs), lead the on-call rotation, and develop runbooks.
  • AI Infrastructure Support: Address AI infrastructure needs, including model serving, GPU provisioning, and autoscaling for AI workloads.
  • Cloud Infrastructure Management: Oversee cloud infrastructure (AWS/Azure), focusing on cost optimization, reliability, disaster recovery, and capacity planning.
  • SOC 2 Readiness: Spearhead SOC 2 Type II preparedness, implementing controls, organizing evidence collection, and liaising with auditors.
  • Security Incident Response: Establish procedures, conduct regular security evaluations, and respond to incidents as they arise.

Your First 90 Days

  • Week 1-2: Immerse yourself in current infrastructure and security. Identify critical gaps and build rapport.
  • Month 1: Set up basic monitoring and alerting. Outline the CI/CD roadmap and conduct initial threat assessments.
  • Month 2-3: Develop CI/CD pipelines with security gates, implement secrets management, create runbooks, and initiate SOC 2 gap analysis.
  • Ongoing: Take full ownership of infrastructure and security, assertively manage risks, and ensure compliance.

Values & Vibe

  • You perceive infrastructure through the lens of security and reliability.
  • You possess an innate sense of paranoia, assuming systems are under threat.
  • You are hands-on (Terraform, security configs) but focused on building systemic reliability.
  • You are comfortable saying “no” when risks are unacceptable.

What Success Looks Like

  • Infrastructure is reliable and secure; the CEO no longer worries about outages or breaches.
  • CI/CD pipelines are routine, low-risk, and security-gated.
  • Cybersecurity posture is robust with minimized attack surfaces.
  • HIPAA compliance is systematic and audit-ready.
  • AI infrastructure supports production workloads reliably and cost-effectively.
  • A formal security review process is established to halt risky releases.
  • Incident response is documented and efficient.

Required Qualifications

  • 5-10 years of experience in DevOps, SRE, or Platform Engineering.
  • Strong security mindset: naturally cautious and detail-focused.
  • Familiarity with HIPAA, SOC 2, or healthcare compliance frameworks.
  • Proficient in AWS or Azure with infrastructure-as-code (Terraform, Pulumi, or CloudFormation).
  • CI/CD pipeline design and implementation (GitHub Actions, CircleCI, Jenkins, etc.).
  • Experience in container orchestration (Kubernetes, ECS, or equivalent).
  • Skills in cybersecurity: threat modeling, vulnerability assessment, and incident response.
  • Strong English communication skills for asynchronous work and documentation.
  • Experience in startup or high-growth environments.

Strongly Preferred

  • Experience in supporting ML/AI infrastructure (model serving, GPU clusters).
  • Security expertise in healthcare SaaS (handling PHI, encryption, access auditing).
  • Background in penetration testing or security audits.
  • Prior experience with SOC 2 or HITRUST certification processes.
  • Knowledge of observability and monitoring tools (Datadog, Prometheus, Grafana).

Nice to Have

  • Understanding of FHIR/HL7 healthcare data standards.
  • Production experience with Kubernetes.
  • Acquainted with multi-tenant SaaS security strategies.
  • Exposure to mental health or behavioral health sectors.
  • Experience with cloud infrastructure cost optimization.
  • Relevant security certifications (CISSP, CEH, or equivalent).

Schedule

  • Evening IST hours with 4–8 hours of daily overlap with US Pacific (9am–5pm PT).
  • On-call availability is expected during key security incidents.

Benefits

  • Salary between ₹22–35 LPA, based on skills and responsibilities.
  • Fully remote work options throughout India.
  • Provision for equipment allowance.
  • Acknowledgment of culturally significant local holidays (India).
  • Flexible paid leave options.
  • Direct and regular communication with the CEO.
  • Opportunity to build infrastructure and security practices from the ground up.

How to Apply

Apply via We Work Remotely

Similar jobs