Imprivata

AppSec and DevSecOps Lead

Imprivata • $163K — $173K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, Engineering, or equivalent experience.
  • 7+ years in DevOps, cloud, software, application, or infrastructure security; 3+ years in DevSecOps or security engineering.
  • Experience integrating security into CI/CD and development workflows in cloud-native and traditional environments.
  • Proficiency with AWS, Azure, or Google Cloud; infrastructure as code; containers; Kubernetes; and CI/CD platforms like GitHub Actions or Jenkins.
  • Strong scripting or programming skills in Python, Go, JavaScript, Java, Bash, or similar languages.
  • Experience securing SaaS, on-premises, hybrid, and regulated environments, particularly in healthcare or financial services.
  • Familiarity with threat modeling methods and relevant security certifications.

Responsibilities

  • Execute DevSecOps strategy across products and environments, collaborating with various teams to drive adoption.
  • Establish security-by-design principles and reusable standards for secure software development.
  • Embed security scanning tools into CI/CD pipelines with tailored security gates.
  • Secure software supply-chain controls, including Git workflows and release artifacts.
  • Apply secure-by-default controls across cloud, networks, and APIs.
  • Utilize automation to manage security risks and ensure compliance with best practices.
  • Support incident response and post-incident reviews for security breaches.

Benefits

  • Top-notch work environment and developmental opportunities.
  • Competitive total rewards package.
  • Focus on employee engagement and having fun at work.
Full Job Description
Description

We are seeking an AppSec and DevSecOps Lead to join our team. This is a hybrid opportunity based out of our Waltham, MA office.

Job Summary

Imprivata is seeking an AppSec and DevSecOps Lead to operationalize DevSecOps across its product lines, engineering teams, and infrastructure. This role will embed security throughout the software and infrastructure lifecycle-from design and coding through testing, deployment, operations, and retirement.

The successful candidate will support cloud-native and traditional products deployed in customer-managed, on-premises, virtualized, and hybrid environments. The role combines hands-on engineering with organizational leadership to build secure automation, establish practical standards, and make secure delivery repeatable.

The position will support Imprivata's identity, authentication, access, patient identity, remote support, analytics, and integration solutions across cloud services, endpoints, medical and shared-use devices, APIs, virtual environments, legacy systems, and customer-managed deployments.

Duties and Responsibilities
  • Execute Imprivata's DevSecOps strategy across products, cloud, data centers, and traditional software, partnering with Engineering, Product, Platform, Quality, DevOps, SecOps, and GRC to drive adoption and clarify ownership.
  • Establish security-by-design, secure-by-default, policy-as-code, reusable standards, reference architectures, and minimum security requirements.
  • Embed SAST, DAST, SCA, secrets, container, IaC, API, and license scanning into CI/CD, with measurable, risk-based security gates tailored to products and deployment models.
  • Secure Git workflows, build systems, runners, identities, repositories, signing systems, credentials, release artifacts, SBOMs, provenance, and other software supply-chain controls.
  • Apply secure-by-default controls to cloud, networks, identity, platforms, containers, databases, APIs, serverless services, and service communications.
  • Use infrastructure-as-code, policy-as-code, and automation to address drift, excessive privileges, exposed services, and insecure network paths, while partnering on secrets, encryption, segmentation, logging, monitoring, resilience, testing, and remediation.
  • Address security for authentication, authorization, privileged access, sessions, tenant isolation, APIs, federation, mobile, endpoints, healthcare data, new services, acquisitions, and major releases.
  • Secure agentic AI and MCP servers, clients, code, and workflows through threat modeling, least privilege, authentication, authorization, tool validation, secure APIs, prompt-injection protection, data-loss prevention, sandboxing, isolation, monitoring, and human approval.
  • Operationalize findings from code, dependency, container, cloud, penetration testing, bug reports, and other tools by improving ownership, prioritization, remediation, exceptions, reporting, and monitoring with SecOps.
  • Support response to compromised credentials, malicious code, exposed secrets, supply-chain attacks, unauthorized deployments, and cloud compromise, including exercises and post-incident reviews.
  • Support NIST SSDF, NIST CSF, CIS Controls, OWASP, ISO 27001, SOC 2, and healthcare requirements; maintain control evidence; and use metrics, incidents, audits, assessments, and engineering feedback to drive continuous improvement.
  • Other duties as assigned and required.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience.
  • Seven or more years in DevOps, cloud, software, application, or infrastructure security, including three or more years of hands-on DevSecOps or security engineering experience.
  • Experience integrating security into CI/CD and development workflows across cloud-native and traditional environments.
  • Proficiency with AWS, Azure, or Google Cloud; infrastructure as code; containers; Kubernetes; Git; and CI/CD platforms such as GitHub Actions, GitLab, or Jenkins.
  • Experience with SAST, DAST, SCA, secrets detection, container security, IaC security, vulnerability management, and software supply-chain controls such as SBOMs, SLSA, Sigstore, artifact signing, or provenance.
  • Strong scripting or programming skills in Python, Go, JavaScript, Java, Bash, or comparable languages.
  • Working knowledge of IAM, least privilege, authentication, authorization, encryption, certificates, logging, secure network design, and policy-as-code.
  • Experience securing SaaS, on-premises, hybrid, virtualized, customer-managed, mobile, endpoint, API, microservice, serverless, or service-mesh environments.
  • Experience securing products in healthcare, financial services, government, or other regulated industries, including identity, privileged-access, authentication, or zero-trust solutions.
  • Experience integrating security tools with Jira, ServiceNow, GitHub, GitLab, SIEM, CNAPP, vulnerability-management, or GRC platforms.
  • Familiarity with STRIDE, PASTA, attack trees, or other threat-modeling methods, and relevant certifications such as CISSP, CCSP, CSSLP, AWS, Azure, Google Cloud, or Kubernetes security certifications.
  • Ability to explain technical risk to technical and nontechnical stakeholders, influence teams, and drive adoption without relying solely on authority.

This position offers a total compensation range of $163,000.00 to $173,000.00 (inclusive of base salary and variable compensation, such as bonuses and incentives). In addition, more information about Imprivata's benefit offerings can be found here. This range represents the high and low end of Imprivata's compensation range for this position. Actual compensation will vary and may be above or below the range based on various factors, such as a candidate's location, skills, experience, and qualifications.

At Imprivata, we have a top-notch work environment, developmental opportunities, a competitive total rewards package, and the desire to have fun. If you have the skills and qualifications as we have described above, we want to hear from you!

#LI-Hybrid #LI-ML1

About Imprivata

Imprivata is a healthcare IT security company that enables healthcare organizations to access, communicate, and transact patient information securely and conveniently. The company offers a range of products and services, including authentication and access management, secure communications, and patient engagement. Imprivata's solutions are used by over 1,000 healthcare organizations worldwide, including hospitals, clinics, and other healthcare providers. The company was founded in 2002 and is headquartered in Lexington, Massachusetts.
Learn more about Imprivata
Size
1,000 employees
Industry
Founded
2002

Similar Jobs

More Jobs at Imprivata

More Information Technology Jobs

Find similar AppSec and DevSecOps Lead jobs: