DevOps Engineer
وصف الوظيفة
𝗗𝗲𝘃𝗢𝗽𝘀 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿
𝗦𝗮𝗻𝗲𝗱 𝗛𝗲𝗮𝗹𝘁𝗵 | Riyadh, Saudi Arabia Full-time | On-site / Hybrid | Mid to Senior Level
━━━━━━━━━━━━━━━━━━━━
𝗔𝗯𝗼𝘂𝘁 𝗦𝗮𝗻𝗲𝗱 𝗛𝗲𝗮𝗹𝘁𝗵
Saned Health is a Saudi healthcare information systems company building the digital backbone for hospitals and care providers across the Kingdom. Our products include a full Hospital Information System (HIS), a referral management portal, population health management tools, and integrations with national platforms such as NPHIES.
Our work directly supports clinicians, payers, and patients across Saudi Arabia's healthcare ecosystem.
━━━━━━━━━━━━━━━━━━━━
𝗧𝗵𝗲 𝗥𝗼𝗹𝗲
We are looking for a hands-on DevOps Engineer to own the reliability, security, and delivery infrastructure behind our healthcare platforms. You will work across our HIS, web portals, mobile backends, and data services, building the pipelines, environments, and security guardrails that allow our engineering teams to ship safely and continuously in a regulated healthcare environment.
This is a high-trust role. You will operate the systems that handle protected health information (PHI) under CBAHI, NPHIES, and NCA Essential Cybersecurity Controls (ECC) requirements. We need someone who treats security, auditability, and uptime as first-class concerns, not afterthoughts.
━━━━━━━━━━━━━━━━━━━━
𝗪𝗵𝗮𝘁 𝗬𝗼𝘂'𝗹𝗹 𝗗𝗼
𝗖𝗜/𝗖𝗗 𝗮𝗻𝗱 𝗗𝗲𝗹𝗶𝘃𝗲𝗿𝘆
- Build and maintain CI/CD pipelines for backend services, web frontends, mobile apps, and data services across multiple language stacks
- Manage release workflows across dev, staging, UAT, and production environments with proper approval gates
- Containerize applications using Docker and orchestrate deployments across our self-hosted and cloud infrastructure
- Maintain Infrastructure-as-Code (Ansible, Terraform, or equivalent) for repeatable, auditable environments
- Install, configure, and manage Linux servers (Ubuntu/RHEL) hosting application servers, databases, message brokers, reverse proxies, and caching layers
- Deploy and manage monitoring and management agents across the fleet
- Apply OS security hardening baselines aligned with CIS benchmarks and NCA ECC controls
- Implement and schedule security patch updates with documented change windows
- Provision administrative-level user accounts in line with least-privilege and approval policy
- Provide responsive support for immediate operational tasks and incidents
- Install, configure, and operate backup systems and agents for databases, application servers, and configuration
- Define and document data backup, retention, and recovery requirements aligned with healthcare data protection standards
- Run regular restore drills and document recovery time and recovery point objectives (RTO/RPO)
- Define and document network and perimeter security requirements in collaboration with the security lead
- Implement secure network configurations across production, staging, and corporate environments
- Configure and manage firewall policies, including rule reviews and change documentation
- Validate network segmentation between PHI-bearing, internal, and public-facing environments
- Implement and operate secure VPN access for remote engineering and partner users
- Monitor security vulnerability alerts (CVEs, vendor advisories, internal scanners) and drive remediation
- Implement Identity and Access Management (IAM) requirements across systems, including SSO, MFA, and access reviews
- Maintain audit logs and evidence trails to support CBAHI, JCI, and NPHIES audits
- Partner with the security function on incident response, including detection, containment, and post-mortems
- Operate centralized logging, metrics, and alerting (e.g., Prometheus, Grafana, ELK/OpenSearch, Sentry)
- Tune database and application performance in collaboration with engineering teams
- Lead postmortems and drive systemic reliability improvements
𝗪𝗵𝗮𝘁 𝗪𝗲'𝗿𝗲 𝗟𝗼𝗼𝗸𝗶𝗻𝗴 𝗙𝗼𝗿
𝗥𝗲𝗾𝘂𝗶𝗿𝗲𝗱
- 3+ years in a DevOps, SRE, or Systems Engineering role running production Linux workloads
- Strong Linux administration skills (Ubuntu/RHEL): networking, systemd, cron, SSH hardening, log management
- CI/CD experience with GitLab CI, GitHub Actions, Jenkins, or equivalent — not just using pipelines, but designing them
- Containers: solid Docker fundamentals; comfortable writing Dockerfiles and managing container lifecycles
- Infrastructure-as-Code using Ansible, Terraform, or similar
- PostgreSQL operations: backups, replication, monitoring, basic tuning
- Networking fundamentals: TCP/IP, DNS, TLS, VPN, firewall rule design, network segmentation
- Security mindset: you know what hardening means and have applied it; you don't open ports without thinking
- Scripting: proficient in Bash and Python
- Source control: confident with Git workflows, branching strategies, and code review etiquette
- Experience operating large open-source business or healthcare platforms in production
- Event streaming platforms (Kafka or similar): consumer groups, partitioning, monitoring, DLQs
- Experience working under healthcare or financial compliance regimes (CBAHI, JCI, HIPAA, NPHIES, PCI, NCA ECC)
- Familiarity with Nginx as a reverse proxy and WAF integrations
- Cloud experience (AWS, Azure, or GCP) alongside on-premise / hybrid environments
- Self-hosted developer platforms (Git hosting, issue tracking, CI runners)
- Arabic language skills
𝗛𝗼𝘄 𝗬𝗼𝘂 𝗪𝗼𝗿𝗸
- You document. Tribal knowledge is a liability — runbooks, RACI, and change records are part of the deliverable.
- You communicate calmly during incidents and write postmortems without blame.
- You push back when something is unsafe, and you propose alternatives.
- You understand that in healthcare, "move fast and break things" is the wrong phrase.
𝗪𝗵𝗮𝘁 𝗪𝗲 𝗢𝗳𝗳𝗲𝗿
- A meaningful mission — your work directly supports clinicians and patients across Saudi Arabia
- Modern engineering practices and a team that takes code review and architecture seriously
- Direct ownership of infrastructure decisions — not buried under five layers of management
- Competitive salary, benefits, and learning budget
- Visibility on certification paths (AWS, Kubernetes, security certifications) supported by the company
¿Te interesa este puesto?