DevSecOps Architect: Build Secure, Scalable SDLC

180 Seminole Hard Rock Support Services

United States

Hybrid

USD 150,000 - 190,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

180 Seminole Hard Rock Support Services in the United States seeks a DevSecOps Architect to embed security into every stage of the Secure SDLC, from code commit to production deployment. You will design secure-by-default frameworks and automate testing and compliance across CI/CD, cloud, and application delivery.

This hands-on leader writes production-grade code, builds tooling, and enforces guardrails for IaC, containers, and cloud platforms, while promoting zero-trust and a culture of shared

Responsibilities

  • Security Architecture & Secure SDLC Design and implement an enterprise DevSecOps architecture embedding security controls, automated testing, and compliance validation into every phase of the software development lifecycle, from code commit through production deployment
  • Define and maintain secure coding standards, application security reference architectures, and security design patterns that development teams adopt as foundational building blocks, not optional guidelines
  • Architect threat modeling frameworks and processes that enable development teams to proactively identify and mitigate security risks during design and development phases, before code is written
  • Establish and govern security gate criteria within CI/CD pipelines, ensuring that code, container images, infrastructure-as-code templates, and third-party dependencies meet security and compliance thresholds before promotion to production
  • Own the security architecture review process for new applications, platforms, and major system changes, providing timely, actionable guidance that accelerates delivery rather than blocking it
  • Pipeline Engineering & Automation Design, build, and maintain secure CI/CD pipelines integrating automated security tooling across the full spectrum: static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container scanning, infrastructure-as-code (IaC) scanning, and secrets detection
  • Develop and maintain custom pipeline integrations, security automation scripts, and policy-as-code frameworks using Python, PowerShell, Go, or similar languages, enforcing security controls programmatically at scale
  • Implement automated compliance-as-code solutions that continuously validate infrastructure and application configurations against regulatory requirements (PCI-DSS, SOX, tribal gaming regulations) and internal security policies, eliminating manual evidence collection
  • Engineer automated remediation workflows that detect, alert, and resolve common security misconfigurations and vulnerabilities without manual intervention, reducing mean time to remediate across the portfolio
  • Build developer-facing security tooling and integrations that surface security findings directly within developer workflows (IDE plugins, pull request gates, ticketing integrations), making security feedback immediate and actionable
  • Cloud & Infrastructure Security Architect and enforce security guardrails across cloud environments (Azure, AWS, Google Cloud), including network segmentation, identity and access policies, encryption standards, logging configurations, and monitoring baselines
  • Design and implement secure infrastructure-as-code (Terraform, Ansible, ARM/Bicep, CloudFormation) templates and modules that serve as hardened, reusable baselines for all cloud and on-premises deployments
  • Oversee container and Kubernetes security architecture, including image hardening, runtime protection, network policies, secrets management, and admission control policies
  • Collaborate with cloud engineering, infrastructure, and platform teams to ensure IaaS, PaaS, and serverless workloads across Linux and Windows environments are deployed and operated in accordance with zero-trust principles and enterprise security standards
  • Define and maintain cloud security posture management (CSPM) standards, continuously monitoring for drift and enforcing guardrails that prevent insecure configurations from reaching production
  • Application Security & Vulnerability Management Lead the application security program in partnership with development teams — conducting architecture reviews, code reviews, and penetration testing coordination to identify and remediate vulnerabilities before they reach production
  • Evaluate, implement, and manage application security tooling across SAST, DAST, SCA, container, and cloud posture domains, ensuring comprehensive, continuous coverage across the full application and infrastructure portfolio
  • Drive adoption of secure software supply chain practices, including software bill of materials (SBOM) generation, dependency management, artifact signing, provenance verification, and third-party component vetting
  • Establish a vulnerability management lifecycle with defined SLAs, risk-based prioritization, and integration into development sprints — ensuring findings are remediated by development teams, not just reported by security
  • Lead red team coordination and penetration testing engagements, translating findings into architectural improvements and developer education, not just remediation tickets
  • Culture, Enablement & Continuous Improvement Champion a DevSecOps culture of shared security responsibility across development, operations, and security teams, breaking down silos and fostering collaboration through training, enablement, and embedded security practices
  • Develop and deliver security training programs, workshops, secure coding guidelines, and self-service tooling that empower developers to build securely and independently — without requiring security team involvement for every decision
  • Establish DevSecOps metrics and KPIs (mean time to remediate, vulnerability escape rate, pipeline security coverage, compliance drift, developer security adoption) to measure program effectiveness and drive continuous improvement
  • Research, prototype, and evaluate emerging DevSecOps capabilities, including AI-powered security testing, LLM/generative AI security controls, and intelligent vulnerability prioritization, piloting innovations that deliver measurable security outcomes
  • Mentor and provide technical guidance to security engineers, developers, and operations staff, raising the security proficiency and awareness of the broader technology organization
  • Stay at the forefront of DevSecOps, application security, cloud-native security, and AI-powered security testing trends, continuously identifying opportunities to adopt emerging technologies and practices for competitive advantage

Job description

180 Seminole Hard Rock Support Services in the United States seeks a DevSecOps Architect to embed security into every stage of the Secure SDLC, from code commit to production deployment. You will design secure-by-default frameworks and automate testing and compliance across CI/CD, cloud, and application delivery.

This hands-on leader writes production-grade code, builds tooling, and enforces guardrails for IaC, containers, and cloud platforms, while promoting zero-trust and a culture of shared

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Architect: Secure, Scalable SDLC Leader
DevSecOps Architect: Secure, Scalable SDLC Leader

Hard Rock International • Town of Florida (NY), Northern (KY)

Hybrid
USD 140,000 - 200,000
DevSecOps Architect: Secure SDLC & Cloud Automation Lead
DevSecOps Architect: Secure SDLC & Cloud Automation Lead

Seminole Hard Rock • United States

On-site
USD 150,000 - 210,000
DevSecOps Architect
DevSecOps Architect

Seminole Hard Rock • United States

On-site
USD 150,000 - 210,000
Senior Azure DevOps Engineer: Cloud Automation & Security
Senior Azure DevOps Engineer: Cloud Automation & Security

Seminole Hard Rock Support Services • Town of Florida (NY)

On-site
USD 140,000 - 180,000
Senior Azure DevOps Engineer & Cloud Automation Lead
Senior Azure DevOps Engineer & Cloud Automation Lead

Seminole Hard Rock Support Services • Florida

On-site
USD 120,000 - 180,000
Senior Cybersecurity Automation Engineer
Senior Cybersecurity Automation Engineer

180 Seminole Hard Rock Support Services • United States

On-site
USD 140,000 - 190,000
Benefits package
Senior DevSecOps Architect: Secure SDLC & Cloud Security
Senior DevSecOps Architect: Secure SDLC & Cloud Security

Compunnel, Inc. • Lansing (MI)

On-site
USD 160,000 - 230,000
Senior DevSecOps Architect
Senior DevSecOps Architect

Compunnel, Inc. • Lansing (MI)

On-site
USD 160,000 - 230,000
Senior DevSecOps Engineer: Automate, Secure & Scale
Senior DevSecOps Engineer: Automate, Secure & Scale

Scientific Research Corporation • Orlando (FL)

On-site
USD 110,000 - 140,000
Remote DevSecOps Engineer - Cloud Security & Compliance
Remote DevSecOps Engineer - Cloud Security & Compliance

NETFORCE Group • Kansas City (MO), Northern (KY)

Hybrid
USD 100,000 - 170,000
Fully remote work
US time zone alignment
English lessons
+2