Get more replies from employers
Send a job-specific resume in minutes.
Seminole Hard Rock Support Services seeks a senior DevSecOps Architect to embed security into every stage of the Secure Software Development Lifecycle (S-SDLC), championing automated security controls, governance, and compliance across CI/CD pipelines, cloud infrastructure, and application delivery.
This role reports to the Director II of Cybersecurity Architecture, Engineering & IAM and requires deep technical security acumen and hands-on tooling.
Our team members are the key to our company’s success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits
At Seminole Hard Rock Support Services, we are on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. As the DevSecOps Architect, you will define, build, and champion the integration of security into every stage of the Secure Software Development Lifecycle (S-SDLC), embedding automated security controls, governance, and compliance into CI/CD pipelines, cloud infrastructure, and application delivery processes across the enterprise. Reporting to the Director II of Cybersecurity Architecture, Engineering & IAM, this role requires a deeply technical, security-minded architect and engineer who bridges the worlds of software development, cloud operations, and cybersecurity. You will design and implement secure-by-default development frameworks, automate security testing and compliance enforcement, and drive a cultural shift toward shared security ownership, ensuring that every application and infrastructure deployment across all Seminole Hard Rock business units is built secure from the ground up. This is a shift-left architecture role. The ideal candidate does not sit at the end of the pipeline reviewing what others have built, they embed themselves into the engineering lifecycle, define the standards developers work within, and build the tooling and automation that makes security the path of least resistance. You architect at scale, write production-grade code, and measure your impact in vulnerabilities prevented, not just discovered.
8–10+ years of combined experience in cybersecurity, software engineering, DevOps/platform engineering, or cloud architecture, with at least 4+ years focused on DevSecOps, application security, or security engineering in enterprise environments Demonstrated success designing and implementing enterprise DevSecOps programs, including secure CI/CD pipelines, automated security testing, and policy-as-code frameworks at scale hands-on experience with Python, Go, PowerShell, or similar languages, with the ability to build custom security tooling, pipeline integrations, and automation frameworks from scratch Strong software development proficiency, hands-on experience architecting and securing workloads in IaaS, PaaS, serverless, and containerized (Docker, Kubernetes) environments on Azure and/or AWS across Linux and Windows Deep infrastructure expertise Extensive experience with CI/CD platforms (GitHub Actions, Azure DevOps, GitLab CI, Jenkins) and infrastructure-as-code tools (Terraform, Ansible, ARM/Bicep, CloudFormation) Strong working knowledge of application security testing tools and practices: SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection, and the vulnerability management lifecycle end-to-end Deep understanding of cloud security architecture, zero-trust principles, identity and access management, network security, and data protection across hybrid and multi-cloud environments Experience with secure software supply chain practices: SBOM, artifact signing, dependency governance, and third-party risk management Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required Relevant certifications preferred: CISSP, CISM, CSSLP, GWEB, Microsoft SC-series, Azure Solutions Architect/DevOps Engineer, AWS Security Specialty/DevOps Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent
Translate complex security requirements into practical, developer-friendly architectures, tooling, and automated controls that integrate seamlessly into existing development and operations workflows, without creating friction Operate as a hands-on technical leader who architects solutions and personally writes, reviews, and ships high-quality code and automation, not a delegator or reviewer only Influence and drive cultural change across engineering and operations organizations, building trust, credibility, and shared ownership of security outcomes without relying on authority Collaborate effectively across cross-functional teams, bridging cybersecurity, software development, DevOps, cloud engineering, compliance, and business stakeholders to deliver integrated, secure delivery capabilities Communicate complex technical and security concepts clearly to both technical and non-technical audiences, including executive presentations, architecture reviews, and developer-facing documentation Thrive in an Agile, fast-paced environment that values innovation, rapid iteration, and measurable security outcomes over process and bureaucracy Demonstrate a passion for shifting security left, empowering developers and building a resilient, secure-by-default engineering culture that protects the enterprise while enabling speed and innovation
Thank you for choosing us as your employer of choice! If you are ready for an exciting opportunity working in a creative environment where you can bring your authentic self to work, we want to connect with you! If you're unable to find a position that matches your interest, please tell us a little about yourself, and we'll recommend jobs that match your interests. Be Iconic represents the roots of our culture. The Seminole Tribe of Florida remains the only unconquered tribe in the United States of America. The Tribe established Seminole Gaming in 1979, when it opened the first high-stakes bingo hall in the United States. Building on its rich heritage of courageous and groundbreaking achievements, the Seminole Tribe of Florida acquired Hard Rock International in March 2007—the first transaction of its kind by a Native American tribe. Today, Hard Rock International remains one of the most globally recognized companies in the world, with Hard Rock Hotel, Casino, Cafe and Rock Shop® venues in over 74 countries. With the continued growth of Seminole Gaming and Hard Rock International, Seminole Hard Rock Support Services was created to support all of our brands and lines of business. With the largest global footprint in the hospitality industry for over 50 years, our number-one job is to bring fun and excitement to our team members and our guests!