DevSecOps Architect

Hard Rock International

Town of Florida, Northern (NY, KY)

Hybrid

USD 140,000 - 200,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Seminole Hard Rock Support Services seeks a senior DevSecOps Architect to embed security into every stage of the Secure Software Development Lifecycle (S-SDLC), championing automated security controls, governance, and compliance across CI/CD pipelines, cloud infrastructure, and application delivery.

This role reports to the Director II of Cybersecurity Architecture, Engineering & IAM and requires deep technical security acumen and hands-on tooling.

Qualifications

  • 8–10+ years of combined experience in cybersecurity, software engineering, DevOps/platform engineering, or cloud architecture.
  • At least 4+ years focused on DevSecOps, application security, or security engineering in enterprise environments.
  • Hands-on experience with Python, Go, PowerShell, or similar languages.
  • Strong software development proficiency across IaaS, PaaS, serverless, and containerized environments on Azure and/or AWS.
  • Experience with CI/CD platforms: GitHub Actions, Azure DevOps, GitLab CI, Jenkins.
  • Experience with SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection.
  • Familiarity with PCI-DSS, SOX, tribal gaming regulations, GLBA; certifications preferred.

Responsibilities

  • Design and implement an enterprise DevSecOps architecture embedding security controls, automated testing, and compliance validation into every phase of the software development lifecycle, from code commit through production deployment.
  • Define and maintain secure coding standards, application security reference architectures, and security design patterns that development teams adopt as foundational building blocks.
  • Architect threat modeling frameworks and processes that enable development teams to proactively identify and mitigate security risks during design and development phases, before code is written.
  • Establish and govern security gate criteria within CI/CD pipelines, ensuring that code, container images, infrastructure-as-code templates, and third-party dependencies meet security and compliance thresholds before promotion to production.
  • Own the security architecture review process for new applications, platforms, and major system changes, providing timely, actionable guidance that accelerates delivery rather than blocking it.
  • Pipeline Engineering & Automation: design, build, and maintain secure CI/CD pipelines integrating automated security tooling across static and dynamic testing, SCA, container scanning, and IaC scanning.
  • Develop and maintain custom pipeline integrations and policy-as-code frameworks using Python, Go, PowerShell, or similar languages, enforcing security controls programmatically at scale.
  • Implement automated compliance-as-code solutions that continuously validate configurations against PCI-DSS, SOX, tribal gaming regulations, and internal policies.
  • Engineer automated remediation workflows that detect, alert, and resolve misconfigurations and vulnerabilities, reducing MTTR across the portfolio.
  • Build developer-facing security tooling and integrations that surface security findings within developer workflows (IDE plugins, PR gates, ticketing integrations).
  • Cloud & Infrastructure Security: enforce guardrails across cloud environments (Azure, AWS, Google Cloud), including network segmentation, IAM, encryption, logging, and monitoring.
  • Design and implement secure infrastructure-as-code templates and modules (Terraform, Ansible, ARM/Bicep, CloudFormation) as hardened baselines.
  • Oversee container and Kubernetes security architecture including image hardening, runtime protections, network policies, and secrets management.
  • Collaborate with cloud engineering, infrastructure, and platform teams to ensure zero-trust compliant deployments.
  • Define CSPM standards and guardrails to prevent insecure configurations from reaching production.
  • Application Security & Vulnerability Management: lead reviews, testing coordination, and remediation to prevent vulnerabilities from reaching production.
  • Evaluate and manage tooling across SAST, DAST, SCA, container and cloud posture domains, ensuring continuous coverage.
  • Drive secure software supply chain practices including SBOM, artifact signing, and dependency governance.
  • Establish vulnerability management SLAs and a program to drive remediation in sprints.
  • Lead red team coordination and penetration testing engagements to inform architectural improvements.
  • Culture & Enablement: foster a DevSecOps culture through training, enablement, and embedded security practices.
  • Mentor and guide security engineers, developers, and operators to raise security proficiency.

Skills

DevSecOps
CI/CD pipelines
Python
Go
PowerShell
Cloud security
Kubernetes security
Threat modeling

Tools

Terraform
Ansible
CloudFormation
GitHub Actions
Azure DevOps
Jenkins

Job description

Our team members are the key to our company’s success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits

Job Description:

At Seminole Hard Rock Support Services, we are on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. As the DevSecOps Architect, you will define, build, and champion the integration of security into every stage of the Secure Software Development Lifecycle (S-SDLC), embedding automated security controls, governance, and compliance into CI/CD pipelines, cloud infrastructure, and application delivery processes across the enterprise. Reporting to the Director II of Cybersecurity Architecture, Engineering & IAM, this role requires a deeply technical, security-minded architect and engineer who bridges the worlds of software development, cloud operations, and cybersecurity. You will design and implement secure-by-default development frameworks, automate security testing and compliance enforcement, and drive a cultural shift toward shared security ownership, ensuring that every application and infrastructure deployment across all Seminole Hard Rock business units is built secure from the ground up. This is a shift-left architecture role. The ideal candidate does not sit at the end of the pipeline reviewing what others have built, they embed themselves into the engineering lifecycle, define the standards developers work within, and build the tooling and automation that makes security the path of least resistance. You architect at scale, write production-grade code, and measure your impact in vulnerabilities prevented, not just discovered.

Responsibilities
  • Security Architecture & Secure SDLC Design and implement an enterprise DevSecOps architecture that embeds security controls, automated testing, and compliance validation into every phase of the software development lifecycle, from code commit through production deployment
  • Define and maintain secure coding standards, application security reference architectures, and security design patterns that development teams adopt as foundational building blocks, not optional guidelines
  • Architect threat modeling frameworks and processes that enable development teams to proactively identify and mitigate security risks during design and development phases, before code is written
  • Establish and govern security gate criteria within CI/CD pipelines, ensuring that code, container images, infrastructure-as-code templates, and third-party dependencies meet security and compliance thresholds before promotion to production
  • Own the security architecture review process for new applications, platforms, and major system changes, providing timely, actionable guidance that accelerates delivery rather than blocking it
  • Pipeline Engineering & Automation Design, build, and maintain secure CI/CD pipelines integrating automated security tooling across the full spectrum: static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container scanning, infrastructure-as-code (IaC) scanning, and secrets detection
  • Develop and maintain custom pipeline integrations, security automation scripts, and policy-as-code frameworks using Python, PowerShell, Go, or similar languages, enforcing security controls programmatically at scale
  • Implement automated compliance-as-code solutions that continuously validate infrastructure and application configurations against regulatory requirements (PCI-DSS, SOX, tribal gaming regulations) and internal security policies, eliminating manual evidence collection
  • Engineer automated remediation workflows that detect, alert, and resolve common security misconfigurations and vulnerabilities without manual intervention, reducing mean time to remediate across the portfolio
  • Build developer-facing security tooling and integrations that surface security findings directly within developer workflows (IDE plugins, pull request gates, ticketing integrations), making security feedback immediate and actionable
  • Cloud & Infrastructure Security Architect and enforce security guardrails across cloud environments (Azure, AWS, Google Cloud), including network segmentation, identity and access policies, encryption standards, logging configurations, and monitoring baselines
  • Design and implement secure infrastructure-as-code (Terraform, Ansible, ARM/Bicep, CloudFormation) templates and modules that serve as hardened, reusable baselines for all cloud and on-premises deployments
  • Oversee container and Kubernetes security architecture, including image hardening, runtime protection, network policies, secrets management, and admission control policies
  • Collaborate with cloud engineering, infrastructure, and platform teams to ensure IaaS, PaaS, and serverless workloads across Linux and Windows environments are deployed and operated in accordance with zero-trust principles and enterprise security standards
  • Define and maintain cloud security posture management (CSPM) standards, continuously monitoring for drift and enforcing guardrails that prevent insecure configurations from reaching production
  • Application Security & Vulnerability Management Lead the application security program in partnership with development teams — conducting architecture reviews, code reviews, and penetration testing coordination to identify and remediate vulnerabilities before they reach production
  • Evaluate, implement, and manage application security tooling across SAST, DAST, SCA, container, and cloud posture domains, ensuring comprehensive, continuous coverage across the full application and infrastructure portfolio
  • Drive adoption of secure software supply chain practices, including software bill of materials (SBOM) generation, dependency management, artifact signing, provenance verification, and third-party component vetting
  • Establish a vulnerability management lifecycle with defined SLAs, risk-based prioritization, and integration into development sprints — ensuring findings are remediated by development teams, not just reported by security
  • Lead red team coordination and penetration testing engagements, translating findings into architectural improvements and developer education, not just remediation tickets
  • Culture, Enablement & Continuous Improvement Champion a DevSecOps culture of shared security responsibility across development, operations, and security teams, breaking down silos and fostering collaboration through training, enablement, and embedded security practices
  • Develop and deliver security training programs, workshops, secure coding guidelines, and self-service tooling that empower developers to build securely and independently — without requiring security team involvement for every decision
  • Establish DevSecOps metrics and KPIs (mean time to remediate, vulnerability escape rate, pipeline security coverage, compliance drift, developer security adoption) to measure program effectiveness and drive continuous improvement
  • Research, prototype, and evaluate emerging DevSecOps capabilities, including AI-powered security testing, LLM/generative AI security controls, and intelligent vulnerability prioritization, piloting innovations that deliver measurable security outcomes
  • Mentor and provide technical guidance to security engineers, developers, and operations staff, raising the security proficiency and awareness of the broader technology organization
  • Stay at the forefront of DevSecOps, application security, cloud-native security, and AI-powered security testing trends, continuously identifying opportunities to adopt emerging technologies and practices for competitive advantage
Qualifications & Experience

8–10+ years of combined experience in cybersecurity, software engineering, DevOps/platform engineering, or cloud architecture, with at least 4+ years focused on DevSecOps, application security, or security engineering in enterprise environments Demonstrated success designing and implementing enterprise DevSecOps programs, including secure CI/CD pipelines, automated security testing, and policy-as-code frameworks at scale hands-on experience with Python, Go, PowerShell, or similar languages, with the ability to build custom security tooling, pipeline integrations, and automation frameworks from scratch Strong software development proficiency, hands-on experience architecting and securing workloads in IaaS, PaaS, serverless, and containerized (Docker, Kubernetes) environments on Azure and/or AWS across Linux and Windows Deep infrastructure expertise Extensive experience with CI/CD platforms (GitHub Actions, Azure DevOps, GitLab CI, Jenkins) and infrastructure-as-code tools (Terraform, Ansible, ARM/Bicep, CloudFormation) Strong working knowledge of application security testing tools and practices: SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection, and the vulnerability management lifecycle end-to-end Deep understanding of cloud security architecture, zero-trust principles, identity and access management, network security, and data protection across hybrid and multi-cloud environments Experience with secure software supply chain practices: SBOM, artifact signing, dependency governance, and third-party risk management Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required Relevant certifications preferred: CISSP, CISM, CSSLP, GWEB, Microsoft SC-series, Azure Solutions Architect/DevOps Engineer, AWS Security Specialty/DevOps Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent

Professional Skills

Translate complex security requirements into practical, developer-friendly architectures, tooling, and automated controls that integrate seamlessly into existing development and operations workflows, without creating friction Operate as a hands-on technical leader who architects solutions and personally writes, reviews, and ships high-quality code and automation, not a delegator or reviewer only Influence and drive cultural change across engineering and operations organizations, building trust, credibility, and shared ownership of security outcomes without relying on authority Collaborate effectively across cross-functional teams, bridging cybersecurity, software development, DevOps, cloud engineering, compliance, and business stakeholders to deliver integrated, secure delivery capabilities Communicate complex technical and security concepts clearly to both technical and non-technical audiences, including executive presentations, architecture reviews, and developer-facing documentation Thrive in an Agile, fast-paced environment that values innovation, rapid iteration, and measurable security outcomes over process and bureaucracy Demonstrate a passion for shifting security left, empowering developers and building a resilient, secure-by-default engineering culture that protects the enterprise while enabling speed and innovation

Thank you for choosing us as your employer of choice! If you are ready for an exciting opportunity working in a creative environment where you can bring your authentic self to work, we want to connect with you! If you're unable to find a position that matches your interest, please tell us a little about yourself, and we'll recommend jobs that match your interests. Be Iconic represents the roots of our culture. The Seminole Tribe of Florida remains the only unconquered tribe in the United States of America. The Tribe established Seminole Gaming in 1979, when it opened the first high-stakes bingo hall in the United States. Building on its rich heritage of courageous and groundbreaking achievements, the Seminole Tribe of Florida acquired Hard Rock International in March 2007—the first transaction of its kind by a Native American tribe. Today, Hard Rock International remains one of the most globally recognized companies in the world, with Hard Rock Hotel, Casino, Cafe and Rock Shop® venues in over 74 countries. With the continued growth of Seminole Gaming and Hard Rock International, Seminole Hard Rock Support Services was created to support all of our brands and lines of business. With the largest global footprint in the hospitality industry for over 50 years, our number-one job is to bring fun and excitement to our team members and our guests!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Architect
DevSecOps Architect

180 Seminole Hard Rock Support Services • United States

Hybrid
USD 150,000 - 190,000
Cybersecurity Automation Engineer III
Cybersecurity Automation Engineer III

180 Seminole Hard Rock Support Services • United States

On-site
USD 140,000 - 190,000
Benefits package
Devops Engineer III
Devops Engineer III

Hard Rock Hotel Cancun • Town of Florida (NY), Northern (KY)

Hybrid
USD 150,000 - 210,000
Cyber Compliance Analyst III
Cyber Compliance Analyst III

180 Seminole Hard Rock Support Services • United States

On-site
USD 90,000 - 140,000
Benefits package
Cyber Compliance Analyst III
Cyber Compliance Analyst III

Hard Rock International • Town of Florida (NY), Northern (KY)

Hybrid
USD 120,000 - 180,000
Manager, Security Architecture and IAM
Manager, Security Architecture and IAM

180 Seminole Hard Rock Support Services • United States

On-site
USD 140,000 - 190,000
Scrum Master III
Scrum Master III

Hard Rock International • Town of Florida (NY), Northern (KY)

Hybrid
USD 95,000 - 135,000
Scrum Master III
Scrum Master III

180 Seminole Hard Rock Support Services • United States

On-site
USD 120,000 - 150,000
Backend Engineer III
Backend Engineer III

Hard Rock Hotel Cancun • Northern (KY)

Hybrid
USD 120,000 - 170,000
Competitive salary and benefits
Data Engineer III
Data Engineer III

Hard Rock Hotel Cancun • Northern (KY)

Hybrid
USD 120,000 - 170,000
Comprehensive benefits