Live opening · Posted 2 days ago

Head of DevSecOps

Arintra · Bangalore
Instahyre 11-15 yrs
You are 2 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 2 days ago
CompanyArintra
LocationBangalore
Experience11-15 yrs
SourceInstahyre
Listed2 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
23 min from Instahyre publishing this role to us finding it
8 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
15,816 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

We are looking for a Head of Infrastructure, Security and Compliance who will own the reliability, security, and compliance posture of Arintra's technology platform end-to-end. This is a hands-on leadership role where you will both architect and execute, while building and mentoring a team. You will be the single accountable owner for GCP infrastructure, observability, HIPAA and SOC 2 compliance, IT and data security, and vendor management. You will work closely with the Founder/CEO, Engineering Leads, and Customer teams, and will represent our security posture to enterprise hospital customers.
The candidate will have responsibilities across the following functions:
Infrastructure and Platform:
Architect and manage Arintra's GCP environment: GKE, Cloud SQL (PostgreSQL), Pub/Sub, BigQuery, Cloud Run, VPC, IAM.
Own environment stability across dev, staging, and production; define and enforce deployment standards and isolation.
Lead cost optimisation initiatives: committed use discounts, rightsizing, BigQuery cost governance, idle resource management.
Build and maintain Infrastructure-as-Code practices using Terraform or equivalent.
Manage AI infrastructure, LLM serving pipelines, inference cost management, GPU/TPU provisioning where needed.
Own disaster recovery and business continuity planning, RTO/RPO definitions, and failover testing.
Observability and Reliability:
Own and mature Arintra's observability stack: Grafana, New Relic, Loki.
Define SLOs/SLAs across services and build alerting frameworks that distinguish tech alerts from business alerts.
Reduce MTTR by leading incident response, RCA culture, and post-mortem processes.
Build dashboards for real-time automation rate monitoring and system health visibility for both engineering and business stakeholders.
Own Arintra's security posture: network segmentation, IAM least privilege, secrets management, encryption at rest and in transit.
Define and enforce security policies for PHI/PII handling across all systems and teams.
Lead vulnerability management, penetration testing scheduling, and security incident response.
Ensure SMART on FHIR integrations meet security and data isolation requirements for EHR customers.
Drive security-as-code practices and shift-left security across the engineering SDLC.
Build security awareness across engineering and non-engineering teams and compliance.
Own HIPAA compliance end-to-end policies, controls, BAA management, and ongoing audit readiness.
Lead and complete SOC 2 Type II certification controls design, evidence collection, and gap remediation.
Manage audit cycles, internal and external, with hospital customers and third-party auditors.
Build and maintain a compliance calendar and controls monitoring framework
Evaluate and pursue HITRUST as the customer base grows into larger health systems.
IT and Vendor Management:
Own endpoint management, MDM, SSO/IdP (Google Workspace, Okta), and access lifecycle management for the org.
Manage external vendors' security tooling, cloud cost management, and compliance platforms.
Conduct vendor security reviews and maintain a third-party risk register.
Negotiate contracts and SLAs with infrastructure and security vendors.
Leadership and Team:
Hire, develop, and retain a high-performing infra and security team.
Define career paths and growth frameworks for ICs and leads on the team.
Communicate infrastructure roadmap, security posture, and compliance status to leadership and enterprise customers.
Partner with Engineering Leads on SDLC security integration and quality gates.
Requirements:
10+ years in infrastructure, DevOps, or cloud engineering with genuine production ownership, not just participation.
3+ years in a leadership or management capacity owning a team.
Deep hands-on GCP expertise in multi-environment production setup, cost reduction, and IaC.
Has led or co-led a SOC 2 Type II or HIPAA audit end-to-end, not just supported one.
Strong security fundamentals: IAM, network security, secrets management, PHI/PII data classification.
Demonstrated cost reduction outcomes: specific numbers and methods, not just frameworks.
Has built or significantly matured an observability stack from near-scratch.
Comfortable being both hands-on and strategic simultaneously; this is not a pure management role.
Strong Plus:
Experience at a healthcare tech or regulated-industry startup at Series A-C stage.
Familiarity with FHIR, EHR integrations, and PHI data classification in clinical systems; AI/ML infrastructure experience: model serving, LLM cost management, inference pipelines; HITRUST awareness or prior certification experience.
Certifications: GCP Professional Cloud Architect, CISSP, CISM, or equivalent.
Experience with our stack: Java, Python, GCP, PostgreSQL, Elasticsearch, Langfuse, OpenAI/Gemini APIs.
What Good Looks Like in 12 Months
Success Looks Like:
Infra Stability - Zero P0 incidents from infra causes; environment parity enforced across environments.
Cost - 15-25% reduction in cloud spend with documented methodology.
Compliance - SOC 2 Type II in progress or completed; HIPAA controls fully documented and tested.
Observability - SLOs defined for all critical services; alerting noise reduced by 50%+.
Security - Security policy rollout complete; first pen test completed and findings remediated.
Team - Infra team of 3-4 hired and onboarded with clear ownership and growth paths.

Experience
11-15 yrs

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App