# DevSecOps Engineer at Pathos

- Company: Pathos
- What the company does: Drug development shouldn’t be guesswork, not when patients are waiting. Pathos is building a next-generation biotech with AI at the core. Not as a feature, but as the operating system for how medicines get developed. Backed by NEA.
- Company website: https://pathos.com/
- Type: Startups
- Level: Mid level
- Location: New York, NY
- Work setup: On-site
- Pay: $180K to $200K base salary per year (USD)
- Posted: 2026-08-12
- Apply by: 2026-10-08
- Apply: https://ats.rippling.com/pathos/jobs/efe610d6-50b0-4807-935b-1d25be21422b
- Page: https://www.1752.vc/careers/jobs/pathos-devsecops-engineer/

## About the role

We handle some of the most sensitive data around: patient outcomes, clinical trial records, and the multimodal datasets behind our foundation model, all inside a company that runs on agents with broad, standing access to internal systems. That combination raises the stakes on security in a way most companies never have to think about.

## What they're looking for

- Threat models and security architecture for a system built around large numbers of autonomous AI agents with access to internal tools, data, and MCP-style servers
- Guardrails, sandboxing, and permissioning for how agents talk to systems and each other, so they can act without excessive standing privileges
- Secure CI/CD pipelines, infrastructure-as-code review, and automated security testing (SAST/DAST, dependency and secret scanning) built into how we ship, not added on after
- Monitoring, detection, and incident response tooling tuned for AI-native infrastructure, including anomalous agent behavior, prompt injection attempts, and data exfiltration paths
- Data governance and access controls for a governed warehouse and knowledge graph holding patient-level and clinical trial data, aligned with HIPAA and relevant regulatory frameworks
- Cloud security posture across our GCP environment: IAM, network segmentation, encryption, audit logging

Tags: Engineering
