Senior DevSecOps Engineer – Medical Devices
analogdevices · Bilisim Vadisi
Job description
About the role
The Health Solutions Business Unit at Analog Devices is seeking a Senior DevSecOps Engineer to support secure cloud‑native platforms for connected medical devices and digital health solutions. The role focuses on implementing secure software development practices, cloud security controls, and regulatory compliance throughout the product lifecycle.
Key responsibilities
- Implement and maintain security controls across AWS environments for SaMD and digital health solutions.
- Integrate security capabilities into CI/CD pipelines and SSDLC processes, including SAST, DAST, SCA, secrets scanning, container security scanning, and IaC validation.
- Manage software supply chain security activities such as SBOM generation, dependency management, artifact integrity validation, and vulnerability remediation.
- Configure identity and access management, encryption, key management, and secrets management across cloud and application environments.
- Design audit logging, monitoring, and security controls to support HIPAA compliance and healthcare data protection.
- Partner with engineering teams to identify, prioritize, and remediate security vulnerabilities.
- Support risk assessments, penetration testing, incident response, and operational security efforts.
- Build and maintain security automation to improve platform security, compliance, and efficiency.
Required profile
- Bachelor's, Master’s or Ph.D. in Cybersecurity, Computer Science, Software Engineering or related field.
- 7+ years of experience in DevSecOps, cloud security, or application security.
- Experience supporting healthcare or medical device software within quality and compliance frameworks.
- Hands‑on experience securing AWS cloud‑native applications and platforms.
- Strong analytical, problem‑solving, communication and collaboration skills.
Required skills
- AWS services (ECS, EKS, Lambda, RDS, S3, SQS, Cognito, IAM, KMS, CloudFormation).
- Infrastructure as Code (Terraform, CloudFormation, AWS CDK).
- CI/CD pipelines (GitHub Actions or similar).
- Security tooling: SAST, DAST, SCA, container security scanning, secrets detection, IaC security scanning, vulnerability management.
- Application security principles, secure coding, authentication, authorization, encryption, secrets and key management.
- Software supply chain security (SBOM, dependency management, artifact signing).
- Container orchestration (Kubernetes, ECS, EKS).
- HIPAA compliance, ISO 27001, SOC 2 frameworks.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Turkey.
Salaries by job title
- Avukat 41
- Grafik Tasarımcısı 37
- Satış Danışmanı 36
- Muhasebe Uzmanı 30
- Dijital Pazarlama Uzmanı 29
- Şantiye Şefi 28
- Resepsiyon Görevlisi 24
- Hemşire 24
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 12 hours ago
Expires 1 month from now
4 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
analogdevices
Bilisim Vadisi