Infrastructure Engineer
Own the path from a merged pull request to a running production system that hospitals depend on.
Why this role exists
SecUnit's agents test the infrastructure of hospitals. Our own infrastructure has to be more reliable than theirs, and it has to be provably so: a customer's security team will ask how we deploy, how we handle their data, and what happens when something fails, and we answer with runbooks and evidence rather than reassurance. Today one person carries that. We want it to be your job.
What you'll be doing
- Own the deploy path. Every merge to main goes to production through one pipeline, every pull request gets an isolated stage with its own database and queues, and a second production deploy of the same commit must be a no-op. You keep that true as the system grows.
- Own the boring things that break at 3 AM: database migrations, the queue that delivers every email we send and its dead-letter queue, the hourly maintenance jobs, the secrets that gate a production deploy.
- Make failure legible. Correlation IDs on every request, logs that never contain patient data, dashboards that tell an on-call engineer what to do next.
- Keep our own house secure: least-privilege tokens for everything, audited access, and the controls behind our SOC 2 report living in code rather than in a spreadsheet.
- Write the runbooks. If it is not written down, it does not exist here.
Our infrastructure is code in the same TypeScript repository as the product, so you will read and review application changes too.
How we work
We are a small team and everyone ships to production. Every rule in our codebase says how it is enforced, and a change that alters behaviour comes with a test that fails without it. We prefer work a reviewer can verify from types, schemas and tests over work that needs a paragraph to explain. We are remote-first with a few hours of overlap with Tel Aviv. AI agents do a lot of our typing, so we hire for judgment and review, not volume.
What we need from you
- You have run production for a product with paying customers and been the person paged when it broke.
- You are comfortable owning a relational database's migration path.
- You can write and review TypeScript. You do not need to love it.
- You would rather delete a step than document it, and you document the ones that remain.
How hiring works
Apply with the form on this page; a resume and a few lines on why this role are enough. If it looks like a fit, you talk to the hiring manager, then spend a paid working session on a real problem from our backlog, then meet one of the founders. We tell you where you stand at each step, and the whole process takes two to three weeks.