As a Senior DevSecOps & AI Security Engineer, you'll own the technical implementation of security initiatives across cloud infrastructure, software delivery pipelines, and AI-enabled development environments.
- Design and implement security architectures that enable the safe adoption of Generative AI, AI coding assistants, LLMs, and autonomous AI agents.
- Define and enforce security guardrails for AI systems capable of executing code, accessing enterprise resources, interacting with APIs, and handling sensitive information.
- Assess and mitigate AI-specific risks, including:
- Data Exfiltration
- Model Supply Chain Risks
- AI Agent Abuse
- LLM Security Vulnerabilities
- Sensitive Data Exposure
- Support the secure integration of externally developed AI services and platforms into enterprise environments.
- Collaborate with engineering and data teams to ensure AI solutions are designed with security, privacy, and compliance by default.
- Design, implement, and continuously improve security controls across modern cloud-native infrastructure.
- Embed automated security controls into CI/CD pipelines, Infrastructure as Code (IaC), and software delivery workflows.
- Promote DevSecOps best practices by integrating security into every stage of the software development lifecycle.
- Continuously assess cloud environments to identify vulnerabilities, misconfigurations, and opportunities for security improvement.
- Own and administer enterprise security platforms, ensuring they are correctly configured, monitored, and continuously optimized.
- Implement automated security monitoring, vulnerability management, endpoint protection, cloud security posture management, and zero-trust networking.
- Build internal automation tools that improve operational efficiency and reduce manual security processes.
- Develop security scripts and integrations using Python and other automation technologies.
- Secure developer platforms, CI/CD pipelines, source code repositories, build systems, and internal engineering tooling.
- Define least-privilege access models for cloud resources, AI systems, and development environments.
- Strengthen identity, authentication, authorization, and audit capabilities across engineering platforms.
- Ensure traceability, logging, and security monitoring for AI workloads and cloud-native applications.
Collaboration & Security Leadership
- Partner with Software Engineers, DevOps Engineers, Platform Teams, Data Scientists, Architects, and Security professionals to build secure engineering practices.
- Translate governance and compliance requirements into practical, automated technical controls.
- Support security reviews, architecture discussions, and technology evaluations from a security engineering perspective.
- Represent the technical security function during internal and external audits by presenting security controls, technical evidence, and implementation practices.
- Champion a security-first engineering culture without compromising developer productivity or innovation.
Required Experience
Strong background in Software Engineering, Platform Engineering, DevOps, or Cloud Engineering, followed by experience in Cybersecurity or Security Engineering.
Hands-on experience securing modern cloud-native infrastructure and containerized environments.
Experience implementing DevSecOps practices and integrating security into CI/CD pipelines.
Strong understanding of Infrastructure as Code (IaC) and cloud automation principles.
Experience administering enterprise security platforms covering areas such as:
- Cloud Security Posture Management (CNAPP)
- Security Information & Event Management (SIEM)
- Zero Trust Networking
Strong scripting and automation skills using Python.
Excellent communication skills with the ability to collaborate across engineering, security, and business teams.
Security
- DevSecOps
- Zero Trust Architecture
- Vulnerability Management
- Identity & Access Management (IAM)
- Least Privilege
- Security Automation
- Security Monitoring
- Compliance & Audit
AI Security
- Generative AI
- Agentic AI
- AI Coding Assistants
- AI Governance
- AI Supply Chain Security
- Secure AI Adoption
- Cloud-Native Applications
- Containers
- Infrastructure as Code (IaC)
Automation
- Python
- Security Automation
- Infrastructure Automation
Security Platforms (Ideally)
- Wiz
- CrowdStrike
- Google SecOps
- Tailscale
Nice to Have
Experience securing AI workloads, machine learning platforms, or enterprise data pipelines.
Knowledge of container security and Kubernetes security best practices.
Experience implementing cloud-native security architectures.
Familiarity with secure software supply chain practices (SBOM, SAST, DAST, dependency scanning, secrets management).
Experience working in highly regulated industries where security, privacy, and compliance are business-critical.