Role Description Oxbridge Health runs healthcare data exchange, member-facing portals, and analytics platforms on AWS. Our infrastructure is a multi-account AWS Organization managed almost entirely as code—every environment, pipeline, and guardrail lives in a CDK repo and deploys through CodePipeline. PHI moves through our systems daily, so we operate under SOC 2 and HIPAA, and our security controls are automated rather than documented-and-hoped-for.
We're a small team with a large surface area. You'll own real systems end to end—not tickets handed down from an architecture group. If you like building the automation that makes compliance and access management boring, this is that job.
Responsibilities
Build and maintain our IaC estate: We run a fleet of TypeScript AWS CDK repos (one per platform: message bus, SFTP exchange, OpenSearch, org policies, and more) deploying via CodePipeline into a dozen+ accounts. You'll extend existing stacks, split monoliths apart cleanly, and bootstrap new accounts into the pattern.
Own production services: ECS Fargate behind ALBs, Aurora, Lambda, API Gateway, S3, AWS Transfer Family for partner SFTP, OpenSearch, DMS replication. Deploy, monitor, right-size, and debug them.
Make observability actually catch things: CloudWatch alarms, Synthetics canaries, VPC flow logs, CloudTrail, log retention and redaction policies. We care about the difference between an alarm that exists and an alarm that pages someone.
Automate security and compliance: Service Control Policies as guardrails, IAM Identity Center permission sets, Prowler-driven evidence collection into WORM storage for SOC 2, secret scanning and SAST in PR pipelines. You'll help move controls from "reviewed quarterly" to "enforced continuously."
Run access management as a product: Okta SSO/SAML, SCIM provisioning, our OpenVPN Access Server fleet, and the approval-gated automation that provisions VPN and AWS access from a Jira ticket or a chat command.
Build internal tooling: A lot of our ops surface is chat-native: Google Chat bots and webhooks that review PRs, report compliance drift, page on-call, and provision access. Several are LLM-backed on Amazon Bedrock. You'll ship these, not just consume them.