Job TitleYou'll be part of a fast growing, collaborative and rapid paced team. You'll secure, scale, and operate the infrastructure powering our AI front desk services and CRM Software that are transforming how local governments and organizations provide service to their communities.You will own security and infrastructure end-to-end, from threat modeling and compliance program management to CI/CD, observability, incident response, and hardening our AWS environment to meet the bar that state and local government data demands.Job ResponsibilitiesOwn our cloud security posture across AWS (ECS Fargate, Aurora PostgreSQL, SQS, CloudFront, IAM, WAF, GuardDuty, Security Hub) and harden it against evolving threatsDrive our compliance programs end-to-end: SOC 2 Type II, HIPAA, and our path to StateRAMP / FedRAMP authorization, including evidence collection, policy authorship, and auditor managementDesign and operate CI/CD pipelines, IaC (Terraform/CDK), and deployment workflows that make the secure path the easy pathBuild and maintain infrastructure-as-code that codifies our environments, enforces guardrails, and makes infrastructure changes auditable and repeatableLead application security: threat modeling, secure code review, dependency and container scanning, secrets management, and remediation guidance for engineering teamsBuild observability and incident response capabilities, including logging, alerting, runbooks, on-call rotations, and post-incident reviewsManage identity and access at scale, including SSO/SAML, least-privilege IAM, and tenant isolation for our multi-tenant architectureRespond to customer security questionnaires, support sales on security and compliance asks from government procurement teams, and represent our security program externallyPartner with engineering to embed security and reliability into the product, not bolt them on after the factExperience and Education4+ years of combined experience in security engineering and DevOps / infrastructure / SRE rolesHands-on production experience with AWS, Linux, containers (Docker/ECS/EKS), and infrastructure-as-codeWorking knowledge of at least one major compliance framework (SOC 2, HIPAA, FedRAMP, StateRAMP, ISO 27001), ideally having helped take an organization through audit or authorizationStrong fundamentals in application security, cloud security, and identity (OAuth/OIDC, SAML, IAM)Comfortable writing code to automate security and ops workflowsBonus: experience in govtech, healthcare, fintech, or other regulated industries; familiarity with FedRAMP/StateRAMP 3PAO process; CISSP, OSCP, or AWS Security certifications