DevSecOps Architect: Secure, Scalable SDLC Leader

Hard Rock International

Town of Florida, Northern (NY, KY)

Hybrid

USD 140,000 - 200,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Seminole Hard Rock Support Services seeks a senior DevSecOps Architect to embed security into every stage of the Secure Software Development Lifecycle (S-SDLC), championing automated security controls, governance, and compliance across CI/CD pipelines, cloud infrastructure, and application delivery.

This role reports to the Director II of Cybersecurity Architecture, Engineering & IAM and requires deep technical security acumen and hands-on tooling.

Qualifications

  • 8–10+ years of combined experience in cybersecurity, software engineering, DevOps/platform engineering, or cloud architecture.
  • At least 4+ years focused on DevSecOps, application security, or security engineering in enterprise environments.
  • Hands-on experience with Python, Go, PowerShell, or similar languages.
  • Strong software development proficiency across IaaS, PaaS, serverless, and containerized environments on Azure and/or AWS.
  • Experience with CI/CD platforms: GitHub Actions, Azure DevOps, GitLab CI, Jenkins.
  • Experience with SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection.
  • Familiarity with PCI-DSS, SOX, tribal gaming regulations, GLBA; certifications preferred.

Responsibilities

  • Design and implement an enterprise DevSecOps architecture embedding security controls, automated testing, and compliance validation into every phase of the software development lifecycle, from code commit through production deployment.
  • Define and maintain secure coding standards, application security reference architectures, and security design patterns that development teams adopt as foundational building blocks.
  • Architect threat modeling frameworks and processes that enable development teams to proactively identify and mitigate security risks during design and development phases, before code is written.
  • Establish and govern security gate criteria within CI/CD pipelines, ensuring that code, container images, infrastructure-as-code templates, and third-party dependencies meet security and compliance thresholds before promotion to production.
  • Own the security architecture review process for new applications, platforms, and major system changes, providing timely, actionable guidance that accelerates delivery rather than blocking it.
  • Pipeline Engineering & Automation: design, build, and maintain secure CI/CD pipelines integrating automated security tooling across static and dynamic testing, SCA, container scanning, and IaC scanning.
  • Develop and maintain custom pipeline integrations and policy-as-code frameworks using Python, Go, PowerShell, or similar languages, enforcing security controls programmatically at scale.
  • Implement automated compliance-as-code solutions that continuously validate configurations against PCI-DSS, SOX, tribal gaming regulations, and internal policies.
  • Engineer automated remediation workflows that detect, alert, and resolve misconfigurations and vulnerabilities, reducing MTTR across the portfolio.
  • Build developer-facing security tooling and integrations that surface security findings within developer workflows (IDE plugins, PR gates, ticketing integrations).
  • Cloud & Infrastructure Security: enforce guardrails across cloud environments (Azure, AWS, Google Cloud), including network segmentation, IAM, encryption, logging, and monitoring.
  • Design and implement secure infrastructure-as-code templates and modules (Terraform, Ansible, ARM/Bicep, CloudFormation) as hardened baselines.
  • Oversee container and Kubernetes security architecture including image hardening, runtime protections, network policies, and secrets management.
  • Collaborate with cloud engineering, infrastructure, and platform teams to ensure zero-trust compliant deployments.
  • Define CSPM standards and guardrails to prevent insecure configurations from reaching production.
  • Application Security & Vulnerability Management: lead reviews, testing coordination, and remediation to prevent vulnerabilities from reaching production.
  • Evaluate and manage tooling across SAST, DAST, SCA, container and cloud posture domains, ensuring continuous coverage.
  • Drive secure software supply chain practices including SBOM, artifact signing, and dependency governance.
  • Establish vulnerability management SLAs and a program to drive remediation in sprints.
  • Lead red team coordination and penetration testing engagements to inform architectural improvements.
  • Culture & Enablement: foster a DevSecOps culture through training, enablement, and embedded security practices.
  • Mentor and guide security engineers, developers, and operators to raise security proficiency.

Skills

DevSecOps
CI/CD pipelines
Python
Go
PowerShell
Cloud security
Kubernetes security
Threat modeling

Tools

Terraform
Ansible
CloudFormation
GitHub Actions
Azure DevOps
Jenkins

Job description

Seminole Hard Rock Support Services seeks a senior DevSecOps Architect to embed security into every stage of the Secure Software Development Lifecycle (S-SDLC), championing automated security controls, governance, and compliance across CI/CD pipelines, cloud infrastructure, and application delivery.

This role reports to the Director II of Cybersecurity Architecture, Engineering & IAM and requires deep technical security acumen and hands-on tooling.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Architect: Secure SDLC & Cloud Automation Lead
DevSecOps Architect: Secure SDLC & Cloud Automation Lead

Seminole Hard Rock • United States

On-site
USD 150,000 - 210,000
DevSecOps Architect: Build Secure, Scalable SDLC
DevSecOps Architect: Build Secure, Scalable SDLC

180 Seminole Hard Rock Support Services • United States

Hybrid
USD 150,000 - 190,000
DevSecOps Architect
DevSecOps Architect

Seminole Hard Rock • United States

On-site
USD 150,000 - 210,000
Senior Azure DevOps Engineer: Cloud Automation & Security
Senior Azure DevOps Engineer: Cloud Automation & Security

Seminole Hard Rock Support Services • Town of Florida (NY)

On-site
USD 140,000 - 180,000
Senior Cybersecurity Automation Engineer
Senior Cybersecurity Automation Engineer

180 Seminole Hard Rock Support Services • United States

On-site
USD 140,000 - 190,000
Benefits package
Senior Azure DevOps Engineer & Cloud Automation Lead
Senior Azure DevOps Engineer & Cloud Automation Lead

Seminole Hard Rock Support Services • Florida

On-site
USD 120,000 - 180,000
Senior DevSecOps Architect
Senior DevSecOps Architect

Compunnel, Inc. • Lansing (MI)

On-site
USD 160,000 - 230,000
Lead DevSecOps Engineer
Lead DevSecOps Engineer

Electrosoft • Arlington (VA)

On-site
USD 130,000 - 190,000
Senior DevSecOps Architect: Secure SDLC & Cloud Security
Senior DevSecOps Architect: Secure SDLC & Cloud Security

Compunnel, Inc. • Lansing (MI)

On-site
USD 160,000 - 230,000
Cyber Governance & Compliance Analyst III
Cyber Governance & Compliance Analyst III

Seminole Hard Rock • United States

On-site
USD 90,000 - 130,000