Sobre a oportunidade
About the company What’s Promptly in a nutshell Promptly is building the first patient-centered global evidence network, offering real world data sharing and monetization capabilities. Together with a selected network of Partners, we generate new knowledge from harmonized datasets, augmented with the collection of longitudinal patient-reported data and patient-generated digital biomarkers within a secure and privacy-preserving environment. We answer the question – is this patient treatment the best it could possibly be? What’s our purpose We exist to empower every patient and every health organization on the planet with evidence on the outcomes of care! Why do we get up in the morning? Well, most healthcare professionals have chosen to work in healthcare driven by their desire to make a difference in patients’ lives. And so have we! We have chosen to follow this calling by addressing the biggest problem in healthcare: the lack of real-world evidence on the outcomes of care. For us, society denying patients better care due to lack of access to data is unethical, in a world where technology improved so many aspects of our world. Making the right evidence available to healthcare organizations to help prevent one lost life, one care complication, one failed treatment is the moral obligation that big tech companies have – it’s our Hippocratic Oath. At Promptly, everything we do is driven by our core purpose: to promote better healthcare at lower costs for patients every day, by making health outcomes available. About the role Promptly is building healthcare data infrastructure for real-world evidence, patient-reported outcomes, and AI-enabled healthcare products. We work with sensitive, fragmented, and regulated data across hospitals, partners, patients, and life sciences organizations. We are looking for a Senior Site Reliability Engineer, Infrastructure Security to strengthen the reliability and security of the infrastructure behind that platform. This is an SRE role with a strong security focus. You will work on the systems that run Promptly: Kubernetes, cloud and hybrid infrastructure, networking, CI/CD, observability, secrets, identity, access controls, deployment workflows, and incident response. Your job is to make our platform harder to break, easier to operate, and safer for teams to build on. We are not looking for someone who only writes policies or reviews tickets from the outside. We need an engineer who can stay close to production, understand how systems fail, improve security through better infrastructure, and help engineering teams adopt secure defaults without slowing useful work to a crawl. The right title for this role could also be Platform Security Engineer or Infrastructure Security Engineer. We are using SRE in the title because the work sits inside the team that owns production infrastructure, reliability, and operational quality. What you’ll do Design, build, and operate secure, reliable Kubernetes platforms across cloud, hybrid, and on-premise environments. Improve the security posture of Promptly’s infrastructure, including identity, access control, network boundaries, secrets management, workload isolation, auditability, and secure deployment patterns. Own reliability practices for critical systems, including SLOs, SLIs, incident response, post-incident analysis, and long-term remediation. Build secure platform defaults through Infrastructure as Code, GitOps, CI/CD, policy-as-code, hardened base images, reusable modules, and clear ownership boundaries. Partner with engineering teams to make security part of system design, deployment, observability, and operations from the start. Improve vulnerability management for infrastructure, containers, dependencies, cloud services, and Kubernetes workloads. Help the team prioritize what matters and fix it properly. Strengthen production access patterns, including least privilege, break-glass access, audit trails, service accounts, workload identity, and human access to sensitive systems. Improve observability and alerting for reliability and security signals across services, infrastructure, data pipelines, and customer-facing products. Help prepare Promptly for security reviews, customer assessments, regulated environments, and future certification work by building systems that produce useful evidence naturally. Lead or support incidents with calm judgment, clear communication, and focus on systemic fixes. Mentor engineers on secure infrastructure, operational readiness, Kubernetes, incident practices, and pragmatic risk reduction. How we build with AI At Promptly, AI-assisted development is part of how we work. We expect engineers to use coding agents, copilots, code search, AI-assisted debugging, and automated review to move faster through real engineering work. We expect engineers to use AI as part of a modern development workflow, with the same standards of craft, quality, and accountability we apply to any production system. Strong engineers know where AI accelerates the work, where it introduces risk, and where human judgment needs to lead. You own what you ship. You should be able to explain the design, inspect the diff, validate the behavior, check the security and privacy implications, debug failures, and operate the system in production. If you cannot understand it, test it, secure it, and maintain it, you should not merge it. Ownership, agency, and judgment Senior Site Reliability Engineers at Promptly are expected to own production outcomes, not only infrastructure tasks. For this role, production outcomes include reliability and security. You should be able to identify risks before they become incidents, understand the trade-offs behind platform decisions, and create practical paths to reduce risk without turning security into theatre or process for its own sake. Healthcare systems involve sensitive data, regulated environments, and real customer consequences. We need engineers who can move quickly when the system needs it, slow down when the risk deserves it, communicate clearly, and follow through until the platform is stronger than it was before. What this role is not This is not a pure compliance, governance, or audit role. Compliance matters, but the main lever is engineering. This is not a penetration-testing-only role. Offensive security experience is useful, but we need someone who can turn findings into better infrastructure, controls, automation, and operating practices. This is not a gatekeeper role. We want someone who raises the security bar by building good defaults, making the safe path the easy path, and helping teams understand real risk. What we’re looking for This role is grounded in SRE and infrastructure fundamentals: production operations, Kubernetes, distributed systems, networking, observability, automation, security, and incident judgment. Required 5+ years of experience in site reliability engineering, platform engineering, DevSecOps, security engineering, or similar production infrastructure roles. Strong production experience with Kubernetes, including cluster design, workload management, networking, ingress, RBAC, secrets, observability, and failure recovery. Advanced Kubernetes security experience, including Pod Security Standards, NetworkPolicies, admission controllers, policy engines for enforcing security and compliance rules, workload identity, runtime security, or multi-cluster management. Hands-on experience improving infrastructure security in production environments. You have worked with identity and access management, network controls, vulnerability management, secrets, TLS, audit logs, and secure deployment workflows. Experience with cloud security across AWS, Azure, GCP, VMware, or private infrastructure, including IAM, KMS, private networking, logging, and account or subscription structure. Strong Infrastructure as Code experience, especially with tools such as Terraform, Helm, or similar platform automation frameworks. Strong programming or scripting skills in Go, Python, Bash, or similar languages. You should be able to build internal tooling, automation, and operational workflows. Strong understanding of networking fundamentals, including DNS, service discovery, virtual networks, load balancing, ingress, TLS, routing, firewalls, and private connectivity. Experience with reliability practices such as SLOs, SLIs, incident response, postmortems, remediation plans, and operational readiness reviews. Experience designing secure CI/CD, deployment automation, and release workflows for production systems, including secrets handling, image and dependency scanning, and policy checks in pipelines. Good security judgment. You can separate real risks from noise, explain trade-offs clearly, and avoid both careless shortcuts and security theatre. High agency in ambiguous environments. You can create clarity, make trade-offs, and move work forward without needing every detail defined upfront. Strong communication skills during incidents, design discussions, risk reviews, and cross-team platform work. Preferred Experience with software supply-chain security, including container scanning, dependency scanning, SBOMs, artifact signing, provenance, hardened images, or secure build pipelines. Experience in healthcare, health technology, life sciences, fintech, enterprise SaaS, or another regulated environment. Experience supporting SOC 2, ISO 27001, GDPR, customer security reviews, vendor assessments, or similar trust and assurance work. Hands-on experience with observability tools such as Prometheus, Grafana, Loki, OpenTelemetry, Jaeger, Elasticsearch, or similar systems. Experience with GitOps workflows using tools such as Argo CD, Flux, or similar systems. Experience with data-intensive platforms or distributed data systems such as Kafka, Trino, Apache Iceberg, Spark, Airflow, or similar technologies. Experience building SRE or security tooling, deployment platforms, observability frameworks, incident automation, asset inventory, or risk dashboards. Relevant certifications, especially CKS, as well as CKA or other security certifications. How you’ll work You will work inside the infrastructure and platform area, close to the teams that ship product and operate customer-facing systems. Some weeks you may harden Kubernetes workloads, improve IAM boundaries, or fix a vulnerable deployment pattern. Other weeks you may support an incident, improve observability, review a production architecture, prepare evidence for a customer security review, or build automation that removes a repeated operational risk. You will work with engineering managers, product engineers, data teams, customer-facing teams, leadership, and external security or compliance partners. Your job is to help Promptly build systems that are secure enough for sensitive healthcare work and practical enough for engineers to use every day. You’ll be a strong fit if You care about production systems and the people who depend on them. You think security belongs in infrastructure design, deployment workflows, and operational practice, not only in a checklist at the end. You can debug across application, infrastructure, network, identity, and data layers. You know when to automate, when to simplify, and when to remove a fragile system entirely. You can move quickly during incidents without creating panic or noise. You care about observability, runbooks, tests, rollback paths, audit trails, and operational readiness. You are comfortable with regulated environments, sensitive data, and high-trust systems. You can make security feel like engineering help rather than bureaucracy. Why Promptly Promptly is working on one of the hardest and most important problems in healthcare: making outcomes data usable so patients, clinicians, healthcare organizations, and researchers can make better decisions. Security and reliability matter here because our systems support sensitive healthcare workflows, partner integrations, data operations, and evidence generation. The infrastructure you build will shape how safely and effectively Promptly can scale. Position Remote-first Full time What we offer Ownership & Growth Define and own a strategic global initiative from the ground up Shape the future of Promptly’s partner ecosystem and data network expansion Financial Benefits Competitive salary Annual performance bonus Equity compensation via our ESOP (open to all team members) Annual training allowance Private health insurance Home-office equipment allowance Non-Financial Benefits Equal opportunity and inclusive environment Flexible work schedule and vacation policy Corporate events and international team gatherings What is the recruiting process like Initial Interview — Meet your future manager and/or team members to get to know each other and understand the scope of the role. Technical & Strategic Assessment — Work on a short case related to partner management or program design. Final Interview (if needed) — Deep-dive discussion to align on expectations and vision. Offer Stage — We’ll share the offer and welcome you to the team! Our Culture & Values Empathy — Ownership — Responsibility — Teamwork — Excellence If you embrace these values, you will thrive at Promptly. We are a purpose-driven company where everyone acts as an owner, committed to improving healthcare through data, technology, and collaboration. Data Privacy Your personal data will be processed for the purposes of managing Promptly’s recruitment related activities which includes setting up and conducting interviews and tests for applicants, assess and review such candidates and similar activities needed in the recruitment and hiring process. Your personal data will be shared with Proef, a provider engaged by Promptly to help us manage our recruitment and hiring process. For more information about how Promptly processes personal data and information about your rights etc., please see Promptly’s/ Proef’s Privacy Policy (link to: Policy for management of application (proef.com)). Privacy notice for applicants Promptly - Software Solutions for Health Measures, S.A. (“Promptly”) is the controller of the personal data contained in your application. We process that data to manage our recruitment activities: reviewing applications, organising and conducting interviews, tests and assessments, evaluating candidates, communicating with you throughout the process and, where an offer is made, preparing your hiring. We do so on the basis of the steps taken at your request prior to entering into a contract, and of our legitimate interest in selecting suitable candidates for the role. Your data is accessible only to the members of the Promptly team involved in the selection process and to service providers that support the tools we use to manage it, acting on our instructions and bound by confidentiality and data protection obligations. We do not use your data for purposes unrelated to recruitment, we do not share it with third parties for their own purposes, and we do not take decisions about you based solely on automated processing. If you are not selected, we keep your application for up to 12 months so that we may contact you about future openings that match your profile. You may ask us to delete it at any time, and we will do so. You have the right to access, rectify, erase, restrict and port your personal data, and to object to its processing. To exercise these rights, or to ask any question about how we handle your data, write to dpo@promptlyhealth.com. You may also lodge a complaint with the Portuguese supervisory authority (Comissão Nacional de Proteção de Dados - CNPD). Applicant declaration By submitting this application, I confirm that the information provided by me, and in any documents attached to it, is true and complete to the best of my knowledge, and that I have not omitted any material fact. I confirm that I have disclosed any previous employment or engagement with Promptly. I accept that if any of the information provided is false or incorrect, my application may be rejected, any offer of employment may be withdrawn and, where employment has already begun, this may constitute grounds for disciplinary action, including termination, in accordance with applicable law.
Tecnologias
- Terraform
- Python
- Go
- Kubernetes
- AWS
- Kafka
A candidatura abre fora do Tech Jobs.
A Tech Jobs não cobra para participar de processos seletivos. Desconfie de solicitações de pagamento ou dados sensíveis.