DevOps Engineer
Data Dimensions · Janesville, Wisconsin, United States
Software Development · 501-1,000 employees
About the role
You will own the reliability, security, and performance of the AWS production infrastructure while automating deployments and scaling microservices. Additionally, you will partner with engineering to implement infrastructure-as-code and maintain compliance with HIPAA standards.
What they look for
Requirements
The role requires extensive experience with AWS, Linux server administration, and containerization using Docker. Candidates must also possess strong skills in CI/CD pipeline management, database operations, and security practices relevant to PHI systems.
Full description
About the Role
We are seeking an experienced Infrastructure / DevOps Engineer to own and evolve the cloud infrastructure behind our HIPAA-compliant healthcare document processing platform. Our stack is AWS-native and PHI-handling, built on PHP 8.3 / Symfony, React, Aurora MySQL, and MongoDB. It is a distributed system composed of many microservices tied together by a central REST API that are each deployed and scaled independently. You will design, automate, secure, and troubleshoot the systems that keep a multi-tenant, compliance-sensitive platform running reliably.
The ideal candidate is deeply comfortable in Linux environments, thinks in automation and infrastructure-as-code, and treats security and compliance as first-class concerns rather than afterthoughts.
What You'll Do
- Own the reliability, performance, and security of our AWS production environment (EC2, ALB, Aurora MySQL, S3, ECS, CloudWatch, SNS, IAM, VPC).
- Design, build, and maintain CI/CD pipelines for PHP/Symfony and React applications, from commit through production promotion, including automated security gates (Aikido) that block vulnerable builds before they ship.
- Stand up and mature our infrastructure-as-code practice — provisioning and configuration currently managed directly, with room to own the migration to a codified, repeatable model.
- Build and tune centralized logging, monitoring, and alerting across CloudWatch and Datadog so issues surface before customers notice them; help drive our ongoing Datadog rollout.
- Manage container workloads (Docker on ECS), including our specialized FreeSWITCH fax/telephony containers.
- Own the infrastructure that our distributed system of independently scaled microservices runs on — per-service ECS auto-scaling, load balancing, and resource right-sizing for both horizontal and vertical scaling. Understand how the stateless services behave and partner closely with engineering on their scaling, deployment, and performance.
- Support database reliability and performance work across Aurora MySQL (read replicas, partitioning, query tuning) and MongoDB.
- Harden the platform against the threat classes relevant to PHI systems, and support ongoing penetration-test remediation.
- Manage secrets, keys, and access across environments (AWS, Symfony secrets vault, Docker secrets, Bitbucket).
- Partner with engineering to improve deployment safety, rollback, and multi-environment (Dev / UAT / Prod) parity.
Required Experience & Skills
- Linux server administration, with specific proficiency in Ubuntu 24.04 LTS.
- AWS cloud infrastructure — hands-on production experience with EC2, ALB/ELB, Aurora/RDS MySQL, S3, ECS, CloudWatch, IAM, VPC, and security groups.
- Docker — building, running, and troubleshooting containerized services in a production environment.
- CI/CD pipeline design and maintenance, specifically Bitbucket Pipelines — branching strategy, environment promotion, build/test/deploy stages, and pipeline troubleshooting.
- Bash scripting for automation, system administration, and pipeline support.
- Centralized logging and observability — configuration, aggregation, dashboards, and alerting in AWS CloudWatch and Datadog (we are actively rolling Datadog out; hands-on Datadog experience is a strong plus). Familiarity with ELK stack or Splunk also welcome.
- Web server operations — Apache and PHP-FPM configuration, tuning, and troubleshooting behind a load balancer.
- Database operations support — MySQL (Aurora/RDS) administration, backup/restore, and performance troubleshooting; exposure to MongoDB.
- Secrets and access management — SSH key lifecycle, API token management, and environment-scoped secrets.
- Distributed systems and stateless scaling — strong working understanding of a distributed system of many independently scaled, stateless microservices, and the ability to operate the infrastructure it runs on (auto-scaling policies, load balancing, externalized session/state such as Redis/S3, and resource right-sizing) while partnering with engineering on scaling and deployment.
- SFTP administration and secure file transfer — configuring, hardening, and troubleshooting SFTP servers and automated file exchange with external partners and EHR systems (chroot/jailing, key- and password-based auth, transfer automation, and monitoring).
Security & Compliance (Required)
- Working understanding of operating infrastructure that stores and transmits PHI under HIPAA — encryption at rest and in transit, audit logging, least-privilege access, and network isolation.
- Experience integrating and operating automated security scanning and CI/CD security gates — SAST/DAST, dependency (SCA), container, and IaC scanning, and secrets detection. We use Aikido; equivalent tooling (Snyk, Semgrep, Trivy, etc.) transfers.
- Familiarity with common web application vulnerability classes (IDOR, injection, host header injection, broken cryptography) and their infrastructure-level mitigations.
- Experience supporting audit, penetration-test remediation, or compliance activities.
Preferred / Nice to Have
- Infrastructure-as-code — Terraform and/or Ansible. You would help stand this up from our current state, so demonstrated experience codifying existing infrastructure is highly valued.
- ECS orchestration at scale; Kubernetes experience a plus if we expand orchestration.
- Jenkins or other CI/CD systems beyond Bitbucket Pipelines.
- AWS SNS / notification and messaging infrastructure.
- FreeSWITCH, SIP, or VoIP/telephony experience (we run containerized fax infrastructure).
- Exposure to healthcare / EHR integrations (HL7, NextGen, Athena, Greenway, or similar) or FedRAMP environments.
- PHP / Symfony deployment familiarity — cache management, secrets vault, multi-environment configuration.
- Aurora MySQL performance tuning (read replicas, partitioning, index strategy) and MongoDB queue patterns.
What Success Looks Like
In your first 6–12 months, you'll have codified our infrastructure, tightened our deployment and rollback story, matured our observability, and strengthened our compliance posture leaving us with a platform that is more repeatable, more secure, and easier to reason about than the one you inherited.