
Senior DevSecOps Engineer - (DCFIL)
- DevSecOps
- DICOM
- AWS
- Kubernetes
- EKS
- Helm
- Kustomize
- Argo
- GitOps
- Load Balancing
- CI/CD
- Azure DevOps
- GitHub Actions
- GitHub
- Git
- Vulnerability Management
- IAM
- Secrets Management
- Zero Trust
- TLS
- OIDC
- JWT
- SQS
- CloudWatch
- OpenTelemetry
- Prometheus
- Grafana
- Fluent Bit
- IEC
- RBAC
- .NET
- Microservices
- WebAssembly
- MongoDB
- Devops
- IaC
- Terraform
- Incident Response
- ISO 27001
- OpenShift
- OpenStack
- CKA
- AWS Security Specialty
Job Title
Senior DevSecOps Engineer - (DCFIL)Job Description
About the role
We are looking for a hands-on Senior DevSecOps Engineer to own the security, reliability, delivery platform, and day-to-day operability of the Digital Customer First Innovation Lab (DCFIL). DCFIL is a cloud-native medical-imaging research platform that manages DICOM data, enables annotation and algorithm workflows, and maintains compliance-grade audit trails.
You will provide the DevSecOps capability that allows product teams to deliver safely and independently. You will build and operate secure AWS/Kubernetes foundations, improve engineering delivery and operational visibility, and make security controls practical for developers. This is a technical ownership role, not a people-management-only role.
What you will do
• Own the platform-level DevSecOps posture across development, test, and production environments, including operational readiness, availability, security, cost, and lifecycle management.
• Operate and evolve the Kubernetes platform: AWS EKS, Karpenter, Helm/Kustomize, Argo CD GitOps, ingress/load-balancing, pod autoscaling, disruption budgets, health probes, and resource governance.
• Own and evolve CI/CD engineering across Azure DevOps Pipelines and GitHub Actions, including the migration of pipelines and delivery controls to GitHub; manage Amazon ECR, image promotion, Git based environment promotion, and safe rollback/recovery practices.
• Build security into delivery and runtime: container and dependency scanning, SBOM and vulnerability management, image provenance, least-privilege IAM/IRSA, secrets management, certificate lifecycle management, and policy-as-code with Kyverno.
• Maintain the platform's zero-trust model: default-deny Kubernetes NetworkPolicies, explicit service-to service rules, secure ingress/egress, TLS configuration, and secure internal communications.
• Operate identity and access components in partnership with product teams, including Dex/OIDC federation, JWT validation patterns, role/claim security, session controls, and integration with enterprise identity providers.
• Manage AWS platform services used by DCFIL, particularly S3, DocumentDB, SQS/DLQs, ALB, ECR, Secrets Manager, CloudWatch/AWS health signals, and backup/recovery controls.
• Protect sensitive medical-imaging data by implementing sound controls for data access, encryption, retention/lifecycle, auditability, and separation of Quarantine Zone and Hospital Data ready datasets.
• Establish observability standards and dashboards using OpenTelemetry/OTLP, Prometheus, Grafana, Fluent Bit, structured logs, traces, and actionable alerting. Drive incident diagnosis and service reliability improvements.
• Lead patching and technology-lifecycle management for AWS services, AMIs/base images, Kubernetes add-ons, CI/CD dependencies, and infrastructure components; assess and remediate relevant security advisories. • Partner with software engineers and technical leads to define production-ready service templates, deployment standards, SLOs, capacity assumptions, failure testing, and secure-by-default patterns.
• Support quality and compliance evidence appropriate for a medical-imaging research platform, including traceable security controls, audit evidence, SOUP/dependency awareness, and IEC 62304 Class A engineering practices.
• Improve cloud cost visibility and drive pragmatic optimisation without compromising availability, security, or developer productivity.
• Contribute to DCFIL's portability direction by keeping service deployment patterns compatible with future sovereign-cloud Kubernetes environments, while operating AWS EKS as the current reference platform.
The platform you will work with
• AWS: EKS, S3, DocumentDB, SQS, ALB, ECR, IAM/IRSA, Secrets Manager, CloudWatch and related security services.
• Kubernetes and delivery: Argo CD, Helm, Kustomize, Karpenter, Crossplane, cert-manager, External Secrets Operator, Kyverno, Azure DevOps Pipelines, and GitHub Actions.
• Security and identity: Dex, OAuth 2.0/OIDC, JWT, RBAC, NetworkPolicies, TLS, secrets and certificate management.
• Observability: OpenTelemetry/OTLP, Prometheus, Grafana, Fluent Bit, distributed tracing and structured logging.
• Workloads: C++20 and .NET microservices, WebAssembly-based frontends, DICOMweb APIs, S3-backed binary data, and MongoDB-compatible data stores.
What you bring
• 5+ years of hands-on DevOps, platform engineering, SRE, cloud security, or DevSecOps experience, including production responsibility for Kubernetes-based systems.
• Strong practical experience with AWS and Amazon EKS, including networking, IAM, managed storage/queues, container registry, and multi-environment operations.
• Strong Kubernetes expertise: workload design, autoscaling, networking, ingress, RBAC, policies, troubleshooting, upgrades, and resource management.
• Experience with GitOps and infrastructure-as-code. Argo CD, Helm, Kustomize, Terraform, and Crossplane experience is highly relevant. • Experience migrating or operating CI/CD workflows in GitHub Actions, alongside Azure DevOps during a phased migration.
• Experience designing secure CI/CD pipelines and integrating vulnerability scanning, supply-chain controls, policy checks, and release governance. • Solid understanding of cloud and Kubernetes security: least privilege, IAM/IRSA, secrets, certificates, network segmentation, runtime hardening, and incident response.
• Practical experience with observability and operational diagnostics, including metrics, logs, traces, alerting, and root-cause analysis.
• Ability to work directly with developers: simplify platform complexity, set clear engineering standards, and solve real delivery problems.
• Strong written communication and an ownership mindset; able to turn operational risks into prioritised, actionable work.
Advantageous experience
• Healthcare, medical-imaging, DICOM/DICOMweb, or other regulated-data environments.
• Working knowledge of IEC 62304, ISO 27001, privacy/data-residency requirements, audit controls, or software-of-unknown-provenance management.
• Experience with DocumentDB/MongoDB-compatible stores, S3 data lakes, or event-driven systems using SQS.
• Experience supporting OpenShift, OpenStack, RKE2, or other sovereign/private-cloud Kubernetes environments.
• Relevant certifications such as CKA/CKS, AWS Solutions Architect, AWS Security Specialty, or equivalent demonstrated experience.
What success looks like
Within the first year, DCFIL has a clearly owned, repeatable, and secure delivery platform: reliable GitOps deployments; healthy, observable services; timely patching and vulnerability remediation; tested recovery paths; useful operational dashboards and alerts; clear cloud-cost accountability; and developers who can ship product changes safely with minimal platform friction.
How we work together
We believe that we are better together than apart. For our office-based teams, this means working in-person at least 3 days per week.
Onsite roles require full-time presence in the company’s facilities.
Field roles are most effectively done outside of the company’s main facilities, generally at the customers’ or suppliers’ locations.
Indicate if this role is an office/field/onsite role.
Â
About Philips
We are a health technology company. We built our entire company around the belief that every human matters, and we won't stop until everybody everywhere has access to the quality healthcare that we all deserve. Do the work of your life to help the lives of others.
• Learn more aboutour business.
• Discoverour rich and exciting history.
• Learn more aboutour purpose.
If you’re interested in this role and have many, but not all, of the experiences needed, we encourage you to apply. You may still be the right candidate for this or other opportunities at Philips. Learn more about our culture of impact with carehere.
#LI-Philin
Senior DevSecOps Engineer - (DCFIL) · Philips