Information Security Development Engineer
Birmingham, - Onsite
Our client, a healthcare organization, is looking for an Information Security Development Engineer to embed security and automation throughout the software development lifecycle. You'll partner across engineering, infrastructure, and compliance teams to build secure CI/CD pipelines and strengthen the organization's overall security posture. This is a chance to shape how security gets built into every stage of delivery, not bolted on after the fact.
C2C is not an option with this job opening and all applicants should be able work for any US Employer without sponsorship. Sponsorship is not provided and this person will not need to require sponsorship in the future.
Benefits & Extras
- High-impact role influencing security architecture across the SDLC
- Cross-functional partnership with engineering, compliance, and operations
- Exposure to modern DevSecOps tooling and cloud security practices
- Opportunity to lead training and drive security awareness org-wide
- Recognized as a top employer in its industry
Compensation: $48-55/hour based on experience
What You'll Be Doing
- Design, implement, and maintain secure CI/CD pipelines across applications, APIs, and cloud platforms
- Develop and manage infrastructure as code with security-first principles
- Integrate automated security testing (SAST, DAST, dependency, container scanning) into the SDLC
- Embed threat modeling and security review gates into engineering workflows
- Monitor, detect, and respond to security vulnerabilities and incidents
- Support regulatory compliance and contribute to audits and control implementation
- Perform risk assessments and security architecture reviews across internal and vendor systems
What You'll Need to be Considered
- Experience with healthcare regulatory frameworks (HIPAA, HITECH, CMS)
- Hands-on experience with Infrastructure as Code tools (Terraform, CloudFormation, ARM/Bicep)
- Proficiency with SAST/DAST, dependency/container scanning, and cloud security posture management
- Solid understanding of IAM, encryption, key management, and secure architecture principles
- Relevant security certifications such as CSSLP, GSSP, Security+, or SSCP (preferred)
- Experience with Kubernetes and container security (preferred)
INDIT

