pathos
pathos~12h ago
New

DevSecOps Engineer

United StatesUnited States·New Yorkmid
CybersecurityDevSecOps Engineer
0 views0 saves0 applied

Quick Summary

Key Responsibilities

IAM, network segmentation, encryption, audit logging. Who You Are You've owned security for a production system end to end, from architecture through detection and response,

Technical Tools
CybersecurityDevSecOps Engineer

Drug development shouldn’t be guesswork, not when patients are waiting.

What We Offer

~1 min read

Pathos does not operate like a traditional biotech. There is no middle management. There are no layers of approval. The company is designed, from the ground up, around small teams of 2–4 subject matter experts who each command hundreds of AI agents to do the work that used to require dozens of people.

About the Role

~1 min read
  • Threat models and security architecture for a system built around large numbers of autonomous AI agents with access to internal tools, data, and MCP-style servers.
  • Guardrails, sandboxing, and permissioning for how agents talk to systems and each other, so they can act without excessive standing privileges.
  • Secure CI/CD pipelines, infrastructure-as-code review, and automated security testing (SAST/DAST, dependency and secret scanning) built into how we ship, not added on after.
  • Monitoring, detection, and incident response tooling tuned for AI-native infrastructure, including anomalous agent behavior, prompt injection attempts, and data exfiltration paths.
  • Data governance and access controls for a governed warehouse and knowledge graph holding patient-level and clinical trial data, aligned with HIPAA and relevant regulatory frameworks.
  • Cloud security posture across our GCP environment: IAM, network segmentation, encryption, audit logging.

You've owned security for a production system end to end, from architecture through detection and response, somewhere a breach would be a real problem, not a hypothetical one. You think like an attacker and build like an engineer: you don't just write policy, you ship the code and tooling that make the secure path the easy path. You've kept up with how much easier AI has made attacks to pull off, and you turn that into concrete engineering decisions instead of vague concern. You move quickly, take initiative, and want to be judged on systems that hold up under real pressure, not paperwork that satisfies an audit.

  • Roughly 6+ years in security engineering, DevSecOps, or something close, with real ownership of production security architecture.
  • Fluent in Python and/or TypeScript. You can read and write production code, not just configure tools.
  • Deep experience with cloud security (GCP preferred, AWS or Azure fine too), IAM design, network security, and secrets management.
  • Hands-on experience securing CI/CD pipelines and infrastructure-as-code (Terraform or similar).
  • Practical experience building or operating detection and incident response systems, not just reading dashboards someone else set up.
  • Comfortable working as an individual contributor with engineers. Once the security foundation is solid, you'll spend real time as a working engineer on the broader platform.

Nice to Have

~1 min read
  • Experience securing agentic AI systems, LLM-powered applications, or MCP-style tooling, including prompt injection defense and agent permissioning.
  • Experience in regulated environments handling patient or clinical trial data (HIPAA, GxP, or similar).
  • Certifications like OSCP, CISSP, or GCP/AWS security certs are a nice signal but not a requirement.

This is a hybrid role, requiring 4 days per week onsite, in our NYC Headquarters.


Location & Eligibility

Where is the job
New York, United States
On-site at the office
Who can apply
US

Listing Details

First seen
September 26, 2026
Last seen
September 27, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
57%
Scored at
September 27, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

pathosDevSecOps Engineer