What are the responsibilities and job description for the Information Security Development Engineer position at Viva Health?
Information Security Development Engineer
Location: Birmingham, AL
Job Summary
The Information Security Development Engineer will partner closely with software engineering, infrastructure, compliance, and operations teams to integrate security, risk management, and automation throughout the software development lifecycle (SDLC). This role will help design, build, and maintain secure continuous integration/continuous delivery (CI/CD) pipelines, infrastructure as code (IaC), monitoring, threat detection, and compliance controls, especially healthcare-specific such as Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH).
This individual plays a key role in proactively identifying and mitigating risks, improving our security posture, and enabling rapid, reliable delivery of software and infrastructure changes. This position will oversee and manage patching and maintaining throughout the life cycle of the software.
Why VIVA HEALTH?
VIVA HEALTH, part of the renowned University of Alabama at Birmingham (UAB) Health System, is a health maintenance organization providing quality, accessible health care. Our employees are a part of the communities they serve and proudly partner with members on their healthcare journeys.
VIVA HEALTH has been recognized by Centers for Medicare & Medicaid Services (CMS) as a high-performing health plan and has been repeatedly ranked as one of the nation's Best Places to Work by Modern Healthcare.
Benefits
- Comprehensive Health, Vision, and Dental Coverage
- 401(k) Savings Plan with company match and immediate vesting
- Paid Time Off (PTO)
- 9 Paid Holidays annually plus a Floating Holiday to use as you choose
- Tuition Assistance
- Flexible Spending Accounts
- Healthcare Reimbursement Account
- Paid Parental Leave
- Community Service Time Off
- Life Insurance and Disability Coverage
- Employee Wellness Program
- Training and Development Programs to develop new skills and reach career goals
- Employee Assistance Program
See more about the benefits of working at Viva Health - https://www.vivahealth.com/careers/benefits
Key Responsibilities
- Design, implement, and maintain secure CI/CD pipelines across applications, Application Programming Interfaces (APIs), and cloud platforms.
- Develop and manage infrastructure as code with security-first principles. (Terraform, CloudFormation, ARM/Bicep)
- Integrate automated security testing throughout the software development lifecycle. (SAST, DAST, dependency, and container scanning)
- Embed secure development practices, threat modeling, and security review gates into engineering workflows.
- Monitor, detect, and respond to security vulnerabilities and incidents including remediation and root-cause analysis.
- Maintain observability for systems and security events through logging, monitoring, and alerting actions.
- Support regulatory compliance and contribute to audits and control implementation. (HIPAA, HITECH, CMS)
- Perform risk assessments and security architecture reviews for internal systems, cloud environments, and third-party vendors. Offer guidance, training, and promote security awareness across development and operations teams.
- Stay current on evolving security threats, tool sets, frameworks, and cloud provider best practices. Recommend improvements and drive adoption.
REQUIRED QUALIFICATIONS:
- Bachelor's Degree in Computer Science, Information Security, or related field; Work experience may substitute for education requirement
- 4 years’ experience in DevSecOps, site reliability engineering with a security focus or similar role
- Strong experience with major cloud platforms (AWS, Azure) and cloud security best practices
- Proven ability to build and manage CI/CD pipelines with integrated security controls (Jenkins, GitHub Actions, GitLab CI, Azure, DevOps)
- Hands-on experience with Infrastructure as Code and configuration management (Terraform, CloudFormation, ARM/Bicep)
- Proficiency with security tooling including SAST/DAST, dependency and container scanning, and cloud security posture management
- Solid understanding of networking, IAM, encryption, key management, and secure architecture principles
- Familiarity with healthcare regulations and frameworks (HIPAA, HITECH, CMS)
- Strong communication and collaboration skills across engineering, security, compliance, and business teams
PREFERRED QUALIFICATIONS:
- CSSLP, GSSP, Security , SSCP
- Experience with Kubernetes and container security
- Familiarity with SRE and resilience practices