DevSecOps Engineer
Mercor • Remote, USA
Education
Any
Type
hourly
Pay Rate (by country)
$50–$75/hr
Listed
30d ago
✅ Applying through this link supports our platform at no cost to you.
This position is hosted on an external talent platform. Please only apply for this position if it fits your skills and interests.
In our Talent Pool?
Apply through this link and we can vouch for you to Mercor. ? We vouch for Talent Pool members who apply through our referral link, when we believe they're a strong match. Not every applicant gets a vouch. Not in the pool yet? Set up your profile first.
Set up your profile →Mercor: our referral track record
We've referred 191 candidates to Mercor roles. 14% (27) were placed.
About this Role
From the Mercor listing
Join a digital health technology company's engineering team to help build and secure the cloud infrastructure behind software that connects hospitals, clinicians, and patients.
We are seeking a DevSecOps Engineer to help operate and secure cloud infrastructure for a leading digital health technology company. You'll work alongside senior engineers and an InfoSec team to maintain HIPAA-regulated AWS environments, automate secure delivery pipelines, and keep production systems observable and resilient.
Location requirements
1. Overview
We are seeking a DevSecOps Engineer to help operate and secure cloud infrastructure for a leading digital health technology company. You'll work alongside senior engineers and an InfoSec team to maintain HIPAA-regulated AWS environments, automate secure delivery pipelines, and keep production systems observable and resilient. This is a full-time W-2 employment position with Cincinnatus LLC, with the opportunity to be placed at a leading healthcare technology company as part of their extended workforce.
2. Key Responsibilities
Maintain AWS infrastructure as code using Terraform with modular, reusable patterns across VPC, EC2, ECS, EKS, IAM, S3, and SQS in HIPAA-regulated production. Partner with InfoSec to run and tune security scanning tools such as Semgrep, Checkov, and Lacework, and integrate them into delivery pipelines. Build automation in Python or Node.js to reduce manual toil and eliminate repetitive operational tasks. Implement self-scaling and self-healing configurations, and strengthen CI/CD pipelines. Monitor infrastructure with Prometheus, Grafana, and the LGTM stack; participate in on-call rotations and blameless post-mortems. Leverage AI-augmented engineering tools (e.g., GitHub Copilot, Claude) to author and review infrastructure.
- Maintain AWS infrastructure as code using Terraform with modular, reusable patterns across VPC, EC2, ECS, EKS, IAM, S3, and SQS in HIPAA-regulated production.
- Partner with InfoSec to run and tune security scanning tools such as Semgrep, Checkov, and Lacework, and integrate them into delivery pipelines.
- Build automation in Python or Node.js to reduce manual toil and eliminate repetitive operational tasks.
- Implement self-scaling and self-healing configurations, and strengthen CI/CD pipelines.
- Monitor infrastructure with Prometheus, Grafana, and the LGTM stack; participate in on-call rotations and blameless post-mortems.
- Leverage AI-augmented engineering tools (e.g., GitHub Copilot, Claude) to author and review infrastructure.
3. Core Qualifications
Hands-on AWS experience across VPC, EC2, ECS, IAM, S3, and SQS. Working knowledge of Terraform and infrastructure-as-code practices. Proficiency scripting in Python or Node.js. Solid understanding of VPC design and network security. Exposure to SAST, DAST, or CSPM tooling and to logging and monitoring systems. Applicants must be located in the United States with eligible work authorization (no sponsorship).
- Hands-on AWS experience across VPC, EC2, ECS, IAM, S3, and SQS.
- Working knowledge of Terraform and infrastructure-as-code practices.
- Proficiency scripting in Python or Node.js.
- Solid understanding of VPC design and network security.
- Exposure to SAST, DAST, or CSPM tooling and to logging and monitoring systems.
- Applicants must be located in the United States with eligible work authorization (no sponsorship).
Preferred Qualifications
HIPAA, SOC2, or PCI-DSS compliance experience. Kubernetes/EKS operation experience. GitOps awareness (ArgoCD or Flux). AWS certifications. CI/CD pipeline experience (GitHub Actions, Jenkins). About Cincinnatus LLC: Cincinnatus LLC is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for contingent and contract-based opportunities. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Equal Employment Opportunity: Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. We consider all qualified applicants without regard to legally protected characteristics and provide reasonable accommodations upon request.
- HIPAA, SOC2, or PCI-DSS compliance experience.
- Kubernetes/EKS operation experience.
- GitOps awareness (ArgoCD or Flux).
- AWS certifications.
- CI/CD pipeline experience (GitHub Actions, Jenkins).
Requirements
- Must be eligible to work in one of: Remote, USA
- Fluent proficiency in English (Written & Verbal)
- Reliable high-speed internet connection
- Bachelor's degree or equivalent professional experience
- Demonstrated expertise in STEM
Why This Role
No office, no fixed hours, no relocation. This DevSecOps Engineer role pays $62.5/hr fully remote, giving you access to STEM work that would otherwise be limited to a handful of major cities.
Skills & Categories
Explore other opportunities in related specializations:
Related Jobs
Browse All Jobs from Mercor
Discover more opportunities on Mercor that match your skills and interests.
View All Mercor Jobs →Verified Reviews
Community Reviews
Share your experience with Mercor
Help other candidates make better decisions by leaving a review.
Sign in to leave a reviewLeave your review
Frequently Asked Questions
Is Mercor for freelancers or full-time contractors?
Mercor places you with one client for a defined engagement, like 'Python Tutor for 3 months', rather than having you grab small tasks from a shared queue. Most roles function as steady contract work, not one-off gigs.
Does Mercor's application require an on-camera interview?
Yes, every applicant records a video interview with an AI interviewer that asks questions about your resume. Clients review that recording to judge communication skills before matching, so there's no way to apply without going on camera.
Does it cost money to apply to Mercor?
No, applying and joining Mercor is free. Mercor's revenue comes from a fee it charges the client on top of your hourly rate, not from applicants. Treat any request for payment to join as a red flag.
Is academic-niche AI training just data labeling?
No, it's closer to academic research. Expect to write or verify complex proofs, solve advanced equations, or check the logic behind a model's step-by-step reasoning. The goal is teaching AI systems to reason deeply within your specific field.
Do I need a PhD for academic-niche AI training roles?
For the top pay tiers, a PhD or current enrollment is usually expected. But the domain assessment is what actually decides it: if you can solve the problems, the degree becomes secondary.
Is academic-niche AI training a continuous job?
Usually not. Work runs in campaigns, like training a model specifically on quantum mechanics, that might last a few weeks. Treat it as a high-paying fellowship or grant rather than a permanent daily job.
What does STEM work look like for a DevSecOps Engineer?
Tasks here are scoped to STEM, not generic labeling. As a DevSecOps Engineer, expect to draw on real domain judgment (evaluating outputs, correcting errors, or providing expert reasoning specific to STEM) rather than following a one-size-fits-all rubric. If you don't have hands-on STEM background, this is likely not the right listing to start with.
What happens when I click Apply on this listing?
You'll be taken to Mercor's external site to complete your application there. This listing links through a referral, but the process is identical to applying directly; the link just routes you correctly. Create an account on their site and follow their onboarding steps.
Can I apply from outside USA?
This specific role is restricted to USA. If you are outside these locations, applying is unlikely to result in an offer even if you pass the assessment. Check the full job description for any VPN or tax-residency caveats.
How soon will I start working after applying to Mercor?
Not immediately. Mercor is a talent marketplace, not a task queue, so applying puts you in a pool of candidates. You start working only once a specific client, like a major AI lab, selects your profile, and that matching process can take weeks.