• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Side Hustles

Side Hustles

Side Hustles For All

  • Best Side Hustles
    • Woman sitting on a pile of coins and working on a laptop surrounded by icons representing different side hustle ideas

      31 Best Side Hustles to Earn Extra Money in 2026

    • Bicycle courier delivering food for their side hustle.

      What Is a Side Hustle?

    • Remote worker sitting at his desk making money from home

      18 Ways to Make Money from Home (Online and Offline Jobs)

    • By Category
      • Arts & Crafts
      • Business Services
      • Caregiving
      • Creative Services
      • Digital Freelance Services
      • View All
    • By Lifestyle
      • I’m introverted
      • I’m a man
      • I’m a woman
      • I’m a stay-at-home mom
      • I’m unique
      • View All
    • By Profession
      • Artists & Creatives
      • Musicians
      • Nurses
      • Physicians
      • Teachers
      • View All
    • By Age Group
      • College Students
      • Teens
      • Age 50+
      • Seniors
      • View All
    • By Skills & Interests
      • Get Paid to Lose Weight
      • Get Paid to Play Games
      • Get Paid to Read
      • Get Paid to Sleep
      • Get Paid to Travel
      • View All
  • Best Gig Apps
    • Freelance worker popping out of a phone screen and considering gig apps on the App Store and Google Play

      Top 6 Gig Apps to Make Real Cash in 2026

    • Smartphone surrounded by the icons of different money-making apps

      Top 10 Best Money-Making Apps to Try in 2026

    • two teenagers using job apps on a phone and laptop

      19 Job Apps for Teens to Find Jobs and Make Money

    • By Gig Type
      • Cashback
      • Data Entry
      • Delivery
      • Games
      • Product Testing
      • View All
    • By Payment Method
      • Bingo Games that Pay to Cash App
      • Games that Pay Real Money
      • Games that Pay to Cash App
      • Games that Pay via PayPal
      • Surveys that Pay to Cash App
      • View All
    • By Benefits
      • $20 Signup Bonuses
      • $25 Signup Bonuses
      • $50 Signup Bonuses
      • Best Signup Bonuses
      • Instant Signup Bonuses
      • View All
    • By Skills & Interests
      • Driving
      • Losing Weight
      • Playing Games
      • Product Testing
      • Watching Ads
      • View All
  • Job Hunting
    • Freelance worker browsing a job post on a freelance job board.

      23 Job Boards You Can Use to Find Remote Work

    • Freelance writer sitting at her laptop working on a project

      15 Best Remote Jobs That Require No Paid Work Experience

    • Teenager sitting at laptop working an online job

      14 Online Jobs for Teens (With No Experience)

    • Freelancing
      • Freelance Writing Sites
      • Freelance Writing Job Boards
      • Freelance Writing Platforms
      • View More
    • Gig & Shift Work
      • Gig Work Apps
      • On-Demand Work Apps
      • Shift Work Apps
      • View More
    • GPT (Get Paid To)
      • Microtasking
      • Product Testing
      • Survey Taking
      • View More
    • Remote Working
      • Best Remote Job Boards
      • Top 15 Remote Jobs
      • View More
  • Job Board
    • Work Schedule
      • Part-Time Jobs
      • Per-Diem Jobs
      • Go Search
    • Work Environment
      • Hybrid Jobs
      • Remote Jobs
      • Go Search
    • Employment Type
      • Contractor Jobs
      • Internship Jobs
      • Temporary Jobs
      • Go Search
    • Job Title
      • Accounting Jobs
      • Data Entry Jobs
      • Nursing Jobs
      • Online Teaching Jobs
      • Software Engineer Jobs
      • Go Search
    • State
      • California Jobs
      • Florida Jobs
      • New York Jobs
      • Pennsylvania Jobs
      • Texas Jobs
      • Go Search
    • City
      • Chicago, IL
      • Houston, TX
      • Los Angeles, CA
      • New York City, NY
      • Phoenix, AZ
      • Go Search

Home Flexible Job Board DevSecOps Engineer

$115,000–165,000/yr 9d ago

DevSecOps Engineer

Boost your chances before you apply.

  • ✨ Apply 10x Faster Free

    It takes 30+ tailored applications to land jobs like this one. We'll help you get that done in 1 hour.

    No Credit Card Required

  • Proceed to Application Go directly to the company's job page to apply.
Logo

Gifthealth Inc

Columbus, OH, US

Full-time Permanent Remote

✨ Apply 10x Faster

Analyze your resume for missing keywords, then one-click optimize it. Don't be anything less than a 100% match candidate.

Free

No Credit Card Required

Summary

The DevSecOps Engineer will integrate security controls directly into CI/CD pipelines and development workflows to identify vulnerabilities early. They will partner with engineering teams to establish secure coding standards and automate security testing across infrastructure and applications.

Job Description

Description

About

At Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives.

Position Summary

We are seeking a DevSecOps Engineer to integrate security into the organization's software development and delivery processes. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.

This role partners closely with Software Engineering, Platform Engineering, DevOps, and Security teams to build security controls directly into CI/CD pipelines, development workflows, infrastructure-as-code, container environments, and application delivery processes. Rather than operating as a final security checkpoint, the DevSecOps Engineer helps engineering teams identify and address security issues earlier in the development lifecycle while building scalable security automation that allows teams to move quickly without sacrificing security.

Key Responsibilities

Secure Software Development:

  • Integrate security controls into the software development lifecycle.
  • Partner with engineering teams to establish practical secure development standards.
  • Help developers identify and remediate application security vulnerabilities.
  • Provide technical guidance on secure coding practices and common vulnerability classes.
  • Support security reviews for new applications, services, APIs, and major architectural changes.

CI/CD Security:

  • Design and implement automated security testing within CI/CD pipelines.
  • Implement and manage capabilities such as:
  • Static Application Security Testing (SAST)
  • Software Composition Analysis (SCA)
  • Secret scanning
  • Container image scanning
  • Infrastructure-as-Code scanning
  • Dependency and package vulnerability detection
  • Develop appropriate security gates for build and deployment pipelines.
  • Reduce alert fatigue by correlating and de-duplicating vulnerability signals across Dependabot, Vanta, and Tenable, escalating only when standard remediation timelines are at risk of being missed.
  • Work with engineering teams to ensure security controls minimize unnecessary friction.

Application and API Security:

  • Evaluate applications and APIs for common security weaknesses.
  • Help establish secure API authentication and authorization patterns.
  • Support threat modeling for applications and new engineering initiatives.
  • Assist engineering teams with remediation of application security findings.
  • Identify systemic security issues that can be addressed through reusable controls or engineering patterns.

Infrastructure-as-Code and Automation:

  • Review Terraform, CloudFormation, Kubernetes manifests, and similar infrastructure definitions for security risks.
  • Develop automated controls that detect insecure infrastructure configurations before deployment.
  • Create reusable secure infrastructure patterns and guardrails.
  • Build security automation using scripting, APIs, and cloud-native services.

Container and Kubernetes Security:

  • Help establish security standards for containers and Kubernetes environments.
  • Support container image security, workload configuration, secrets management, and runtime security.
  • Identify insecure deployment patterns and help engineering teams adopt safer alternatives.
  • Support the security review of the planned migration from Heroku to Render.com, including secrets handling, network posture, and changes to the deployment model.
  • Design a synthetic or de-identified data seeding strategy to enable Dynamic Application Security Testing (DAST) in staging without exposing PHI, currently a gap given the application's PHI-heavy data model.

Security Architecture and Engineering Partnership:

  • Participate in architecture and design reviews.
  • Translate security requirements into technical controls engineering teams can implement.
  • Work with Cloud Security and Security Operations to improve visibility into applications and workloads.
  • Help engineering teams understand and address security findings without becoming a bottleneck to delivery.
  • Metrics and Continuous Improvement:
  • Track application and pipeline security findings through remediation.
  • Measure vulnerability trends, remediation times, security coverage, and adoption of secure development practices.
  • Identify opportunities to replace manual reviews with automated preventative controls.

Qualifications

Education: Not specified as a requirement; we evaluate demonstrated hands-on experience.

Licensure/Certification: Not required. Relevant certifications in cloud, security, Kubernetes, or application security are a plus.

Experience: 3+ years of experience in DevOps, DevSecOps, application security, platform engineering, software engineering, or security engineering.

Knowledge, Skills, and Abilities:  

  • Experience with modern CI/CD systems and software delivery practices. Gifthealth's core application is a GitHub-hosted Rails repo using trunk-based development, with GitHub Advanced Security/CodeQL and Dependabot integrated into CI.
  • Experience with modern application hosting platforms. Gifthealth's core application runs on Heroku (migrating to Render.com), with Crunchy Data for managed Postgres and a Redis instance hosted in AWS. Direct AWS/Kubernetes experience is a plus but not the primary environment today.
  • Working knowledge of application security, API security, GitHub Advanced Security/CodeQL, dependency and vulnerability alert triage (e.g., Dependabot), CI/CD pipelines, Infrastructure-as-Code, secrets management, and software supply chain security.
  • Experience with scripting or programming using languages such as Python, Go, JavaScript, PowerShell, or Bash. Ruby experience is a strong plus, since GifthealthOS, the core application, is built on Ruby on Rails.
  • Experience with Git-based development workflows and the ability to work directly with developers and engineering teams.
  • Demonstrated application of the above Qualification
  • Preferred: experience with Terraform, Kubernetes, or container orchestration. Gifthealth's core application runs on Heroku today (migrating to Render.com), not Kubernetes.
  • Preferred: experience with Rails-specific security tooling such as Brakeman for SAST and bundler-audit or Dependabot for dependency scanning, given GifthealthOS's Ruby on Rails stack.
  • Preferred: experience implementing SAST, SCA, secrets scanning, or IaC security tools. Gifthealth uses GitHub Advanced Security/CodeQL for SAST and Dependabot for dependency scanning.
  • Preferred: familiarity with the OWASP Top 10 and common application vulnerability classes, cloud-native security services, and threat modeling methodologies.
  • Preferred: understanding of identity, authentication, authorization, and secrets management, and experience working within regulated environments.

Measures of Success

Success in this role includes:

  • Security testing becomes consistently integrated into engineering pipelines.
  • Security vulnerabilities are identified earlier in the development lifecycle.
  • Engineering teams have clear, usable guidance for resolving security findings.
  • Reusable security controls reduce reliance on manual security reviews.
  • Critical security issues can prevent unsafe deployments without creating excessive development friction.
  • Application and software supply chain risks are measurable and actively managed.
  • Secure development practices become part of normal engineering workflows.

Work Environment

Location: Not specified in the source job description; to be confirmed with the hiring manager.

Schedule: Full-time; standard business hours.

May require flexibility for security-critical deployment reviews or urgent remediation timelines.

Regular collaboration with Software Engineering, Platform Engineering, DevOps, and Security teams to ensure alignment.

Key Essential Functions

  • Must be able to work at a computer for extended periods
  • Must be able to communicate effectively, verbally and in writing, with engineering and security stakeholders
  • Must be able to handle and access sensitive security and system data in compliance with organizational data handling requirements
  • Must be able to respond to critical security or deployment issues outside standard working hours when required

Employment Classification

Status: Full-time
FLSA: Exempt 

Equal Employment Opportunity (EEO) Statement

Gifthealth is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. All employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, transgender status, national origin, age, disability, veteran status, or any other legally protected status.  

We celebrate diversity and are committed to creating an inclusive environment for all employees. If you do not meet every requirement but still feel you would be a great fit for this role, we encourage you to apply!

Disclaimer

This job description is intended to describe the general nature and level of work being performed. It is not intended to be an exhaustive list of all responsibilities, duties, or skills required of personnel. Gifthealth reserves the right to modify job duties or descriptions at any time.

About the company

Gifthealth Inc

Gifthealth unifies patient access, fulfillment, and support in one seamless, tech-plus-touch platform so patients start therapy faster, stay on it longer, and get the best price every time. As the modern hub alternative and pharmacy of record, our platform eliminates hand-offs and delays. For your brands, it means more patients start and stay on their prescribed therapies, backed by real-time insight across the full patient journey.

Founded

2020

Company size

1,001-5,000 employees

Industry

Technology, Information and Internet

Org type

Privately Held

Headquarters

Columbus, OH

Apply Now

About the company

Gifthealth Inc

Gifthealth unifies patient access, fulfillment, and support in one seamless, tech-plus-touch platform so patients start therapy faster, stay on it longer, and get the best price every time. As the modern hub alternative and pharmacy of record, our platform eliminates hand-offs and delays. For your brands, it means more patients start and stay on their prescribed therapies, backed by real-time insight across the full patient journey.

Founded

2020

Company size

1,001-5,000 employees

Industry

Technology, Information and Internet

Org type

Privately Held

Headquarters

Columbus, OH

Footer

sidehustles.com
Facebook Twitter Instagram LinkedIn Reddit TikTok YouTube

Show Me The Money

  • Side Hustle Basics
  • Side Hustle Job Board (Remote & Part-Time Jobs)
  • Gig App Reviews
  • Job Hunting
  • Manage Your Money
  • The Gig Apple: News & Events

Company

  • About Us
  • Contact Us
  • Become a Contributor
  • Advertising & Sponsorships
  • Partner With Us
  • Editorial Guidelines

Side Hustles © All rights reserved

  • Privacy Policy
  • Terms of Service

Thanks for using our free job board

Your review would mean a lot to us.

If you love that we're just giving away remote jobs for free with no paywall, please spread the word. (You will need to create an account on Trustpilot, for which we'll be eternally grateful.) Good luck out there!

Leave a Review Not yet. Send me to the job post.