DevSecOps Engineer

Pathos

$180K — $200K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security engineering or DevSecOps with ownership of production security architecture
  • Proficient in Python and/or TypeScript for reading and writing production code
  • Extensive experience with cloud security, preferably GCP, including IAM design and network security
  • Hands-on experience securing CI/CD pipelines and infrastructure-as-code (Terraform or similar)
  • Practical knowledge in building or operating detection and incident response systems

Responsibilities

  • Design security architecture and threat models for systems using multiple AI agents
  • Create guardrails for agent-system interactions to limit excessive access
  • Develop secure CI/CD pipelines with integrated automated security testing
  • Implement monitoring and detection tools for anomalous AI agent behavior
  • Establish data governance and access controls aligned with HIPAA regulations
  • Manage cloud security posture across GCP, including IAM and encryption

Benefits

  • Opportunity to work in a fast-paced and innovative biotech environment
  • Collaborative team structure with minimal middle management
  • Direct impact on cutting-edge healthcare technology
  • Emphasis on building security into the development process, not just compliance
  • Engagement with highly sensitive and valuable patient data
Full Job Description
How We Build

Pathos does not operate like a traditional biotech. There is no middle management. There are no layers of approval. The company is designed, from the ground up, around small teams of 2-4 subject matter experts who each command hundreds of AI agents to do the work that used to require dozens of people.

Everyone builds. Everyone ships. Every function at Pathos - from clinical execution to asset selection to the foundation model itself - runs on this model. Our product velocity delivers meaningful outcomes in hours instead of weeks. This is not a future aspiration. It is how we operate today.

The people who thrive here are operators: deep experts who can specify what needs to happen, orchestrate AI agents to execute at scale, and make high-judgment calls that compound over time. If you have spent your career building and shipping AI systems at scale, this is the environment where that experience becomes a superpower.

About The Role

We handle some of the most sensitive data around: patient outcomes, clinical trial records, and the multimodal datasets behind our foundation model, all inside a company that runs on agents with broad, standing access to internal systems. That combination raises the stakes on security in a way most companies never have to think about.

The threat landscape is moving fast too. Capable AI models have lowered the skill floor for finding and exploiting vulnerabilities, so the volume and sophistication of attacks aimed at companies like ours keeps climbing. We need someone who takes that seriously, builds for it before it's a problem, and doesn't treat security as something you check off at the end of a project.

We're hiring a DevSecOps engineer to own security architecture and practice across our AI and data infrastructure: the pipelines, agent tooling, and internal systems that power our BD, clinical development, computational biology, and lab teams. This isn't a compliance-only role. You'll design the guardrails, then get in the code and build them yourself.

What You'll Build

  • Threat models and security architecture for a system built around large numbers of autonomous AI agents with access to internal tools, data, and MCP-style servers.
  • Guardrails, sandboxing, and permissioning for how agents talk to systems and each other, so they can act without excessive standing privileges.
  • Secure CI/CD pipelines, infrastructure-as-code review, and automated security testing (SAST/DAST, dependency and secret scanning) built into how we ship, not added on after.
  • Monitoring, detection, and incident response tooling tuned for AI-native infrastructure, including anomalous agent behavior, prompt injection attempts, and data exfiltration paths.
  • Data governance and access controls for a governed warehouse and knowledge graph holding patient-level and clinical trial data, aligned with HIPAA and relevant regulatory frameworks.
  • Cloud security posture across our GCP environment: IAM, network segmentation, encryption, audit logging.

Who You Are

You've owned security for a production system end to end, from architecture through detection and response, somewhere a breach would be a real problem, not a hypothetical one. You think like an attacker and build like an engineer: you don't just write policy, you ship the code and tooling that make the secure path the easy path. You've kept up with how much easier AI has made attacks to pull off, and you turn that into concrete engineering decisions instead of vague concern. You move quickly, take initiative, and want to be judged on systems that hold up under real pressure, not paperwork that satisfies an audit.

Must-haves

  • Roughly 6+ years in security engineering, DevSecOps, or something close, with real ownership of production security architecture.
  • Fluent in Python and/or TypeScript. You can read and write production code, not just configure tools.
  • Deep experience with cloud security (GCP preferred, AWS or Azure fine too), IAM design, network security, and secrets management.
  • Hands-on experience securing CI/CD pipelines and infrastructure-as-code (Terraform or similar).
  • Practical experience building or operating detection and incident response systems, not just reading dashboards someone else set up.
  • Comfortable working as an individual contributor with engineers. Once the security foundation is solid, you'll spend real time as a working engineer on the broader platform.

Bonus

  • Experience securing agentic AI systems, LLM-powered applications, or MCP-style tooling, including prompt injection defense and agent permissioning.
  • Experience in regulated environments handling patient or clinical trial data (HIPAA, GxP, or similar).
  • Certifications like OSCP, CISSP, or GCP/AWS security certs are a nice signal but not a requirement.

Location

This is a hybrid role, requiring 4 days per week onsite, in our NYC Headquarters.

The pay range for this role is:

180,000 - 200,000 USD per year (New York Office - ACLS East Tower)

Similar Jobs

More Jobs at Pathos

More Information Technology Jobs

Find similar DevSecOps Engineer jobs: