A dynamic healthtech SaaS startup based in Saudi Arabia is seeking a DevSecOps Engineer to take full ownership of their Google Cloud Platform (GCP) infrastructure and platform security. As the first platform and security hire, you will establish and enforce the foundational conventions for how changes reach production, how clinics are provisioned with segregated data from day one, and how access controls are managed and audited. This role requires a hands-on engineer who thrives in an early-stage environment and is passionate about building secure, scalable, and compliant cloud infrastructure.

Key Responsibilities:
- Manage the path to production: Build and maintain a robust CI/CD pipeline that is the sole method for delivering code to clients. This includes merge requests, code reviews, automated testing, staged rollouts, and reliable rollback mechanisms. Ensure migrations are managed across environments and runners are hardened to eliminate dependency on specific individuals.
- Identity and access management: Implement a unified identity provider for GitLab, GCP, production data, and internal tools. Design role-based access controls tailored to engineering roles, conduct regular access reviews, and manage time-bound privilege elevations. Automate onboarding and offboarding processes to complete within an hour.
- Secrets, keys, and device security: Utilize Secret Manager, masked CI variables, and workload identity to avoid long-lived keys. Establish secret rotation policies with clear ownership. Define minimum security standards for personal devices and implement verification methods to ensure compliance. Secrets must never reside on local machines.
- Tenant operations: Automate client onboarding through pipelines that provision, configure, seed data, and enforce a built-in segregation model for deployment, data, and audit trails.
- Infrastructure as code: Manage the entire infrastructure using Terraform, enabling environments to be destroyed and recreated on demand. Enforce private data tiers, controlled egress, edge protection, and organizational policies that make secure defaults the norm.
- Audit and detection: Maintain tamper-evident, queryable audit logs that track system access and patient record views. Ensure logs are written to an immutable sink outside of direct control. Set up alerts for unauthorized activities.
- Observability and on-call: Implement distributed tracing across .NET and Python services to enable end-to-end visibility of clinical journeys. Define service-level objectives (SLOs) and alerting mechanisms that notify on broken workflows. Lead a blameless incident response process with actionable post-mortems.
- PostgreSQL and real-time operations: Manage connection pooling that scales with Cloud Run, configure replicas, failover strategies, and conduct restore drills. Support long-lived WebSocket sessions that persist throughout clinical appointments, even during scaling events.

Required Qualifications:
- Minimum 5 years of experience in DevSecOps or related roles.
- Proven experience managing production environments for multi-tenant B2B SaaS platforms with paying customers.
- Expertise in designing and enforcing least-privilege access models, including identity provider integration and role design.
- Deep knowledge of GCP services such as Cloud Run, Cloud SQL, VPC, IAM, Secret Manager, and workload identity.
- Hands-on experience with Terraform for infrastructure as code, including codifying existing estates.
- Extensive operational experience with GitLab, including CI/CD pipeline creation, runner hardening, and secrets management.
- Strong PostgreSQL skills covering pooling, replicas, failover, and disaster recovery.
- Proficiency in Python or C# sufficient to contribute code and manage merge requests independently.
- Ability to collaborate effectively within cross-functional teams.
- Excellent English communication skills.

Preferred Qualifications and Benefits:
- Experience in healthcare or other regulated SaaS environments.
- Familiarity with compliance standards such as HIPAA, NPHIES, PDPL, and ISO 27001.
- Knowledge of event streaming technologies like Kafka or Google Pub/Sub, anticipating migration to an event bus architecture.

This position is fully remote, offering the opportunity to shape the security and platform infrastructure of a cutting-edge healthtech startup. Candidates with a passion for secure cloud architecture and SaaS operations are encouraged to apply.

---

This opportunity is presented by HR Ways, a globally recognized technical recruitment firm partnering with over 300 employers worldwide, including leading SaaS companies and innovative startups. HR Ways operates across multiple regions including Dubai, Canada, the US, the UK, Pakistan, India, Saudi Arabia, Portugal, and Brazil. For more information about HR Ways and to explore other opportunities, please visit their official website.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Career Level:
Manager
Experience:
3 Years - 5 Years
Apply Before:
Sep 29, 2026
Posting Date:
Sep 23, 2026

HR Ways - Hiring Tech Talent

· 11-50 employees -

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium

Similar Job Titles

Senior Application Security Engineer

Naseeb Enterprise Inc, Karachi, Pakistan
Posted Oct 01, 2026

Senior Application Security Engineer

Naseeb Enterprise Inc, Karachi, Pakistan
Posted Oct 02, 2026

Senior Application Security Engineer

Naseeb Enterprise Inc, Karachi, Pakistan
Posted Oct 01, 2026

Senior Cyber Security Engineer

Naseeb Enterprise Inc, Lahore, Pakistan
Posted Oct 01, 2026
View All
I found a job on Rozee!