DevSecOps Engineer (TypeScript & Agentic AI)

OpenTalent

United States

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Arize AI is hiring a DevSecOps Engineer to weave security into every pipeline, with a TypeScript-heavy stack including Node.js services and Next.js frontends. You will design guardrails for agentic AI workflows and collaborate across teams to embed security as a developer experience.

You’ll lead threat modeling, implement SAST/DAST/ IaC scans, and mentor engineers on secure patterns. A senior, collaborative culture supports experimentation and rapid iteration.

Qualifications

  • 4+ years in DevSecOps, application security, or platform security.
  • Strong TS and Node.js knowledge.
  • Experience securing cloud infra, containers, and Kubernetes.
  • Familiar with CI/CD tooling and IaC (Terraform, Pulumi).
  • Hands-on with agentic AI systems (LLM tool use, function calls, agent frameworks).
  • Collaborative mindset with pairing and feedback.
  • Comfort with ambiguity as security playbooks for agents evolve.

Responsibilities

  • Design and implement guardrails for agentic AI workflows.
  • Build internal tooling in TypeScript: SDKs, CLI tools, GitHub Actions, linters, dashboards.
  • Threat-model new features, esp. LLM integrations and agent calls.
  • Integrate SAST/DAST/SCA and IaC scanning into PR workflows.
  • Lead incident response and produce blameless postmortems.
  • Partner with AI/ML team on responsible deployment and telemetry needs.
  • Mentor engineers on secure coding patterns and AI safety.

Skills

TypeScript
Node.js
DevSecOps
CI/CD
Collaboration
Mentoring
Threat modeling

Tools

GitHub Actions
Terraform
Kubernetes
Pulumi
LangGraph

Job description

About Arize AI

AI is rapidly transforming the world. As generative AI reshapes industries, teams need powerful ways to monitor, troubleshoot, and optimize their AI systems. That's where we come in. Arize AI is the leading AI & Agent Engineering observability and evaluation platform, empowering AI engineers to ship high-performing, reliable agents and applications. From first prototype to production scale, Arize AX unifies build, test, and run in a single workspace- so teams can ship faster with confidence.

The Opportunity

We're hiring a DevSecOps Engineer to embed security into how we ship software - not as a gate at the end, but as a capability woven through every pipeline, repo, and runtime. You'll work across a TypeScript-heavy stack (Node.js services, Next.js frontends, internal platform tools) and play a central role in how we securely design, deploy, and operate agentic AI systems - autonomous and semi-autonomous AI agents that take real actions on behalf of users and engineers. This role is deeply collaborative. You'll spend more time pairing with other departments. If you believe security is best delivered as developer experience, you'll feel at home. We're a small, senior team that prioritizes collaboration over hierarchy and enablement over enforcement. Security at our company isn't a department people avoid - it's a function people pull into their work because we make it useful. Expect a lot of pairing, frequent design reviews, and a culture where asking "is this secure?" early is celebrated, not punished. We believe the next generation of software will be co-built with AI agents. We want a teammate who is excited to figure out, alongside us, what it means to make that future safe.

What You'll Do:
  • Design and implement guardrails for agentic AI workflows - including tool-use sandboxing, prompt-injection defenses, MCP server hardening, secret scoping for agents, and runtime policy enforcement.
  • Build internal tooling in TypeScript: SDKs, CLI utilities, GitHub Actions, custom linters, and developer-facing dashboards that make the secure path the easy path.
  • Threat-model new features alongside product engineers, especially those involving LLM integrations, autonomous agents, or third-party tool calls.
  • Integrate and tune SAST, DAST, SCA, secret scanning, and IaC scanning (Terraform, Kubernetes manifests, Helm) into pull-request workflows with low-friction feedback loops.
  • Lead incident response for security events, coordinating cross-functionally and producing blameless postmortems that improve our systems, not assign blame.
  • Partner with the AI/ML team on responsible deployment of agents - defining what "trusted action" means, what telemetry we need, and how we contain blast radius when an agent misbehaves.
  • Mentor engineers across the org on secure coding patterns in TypeScript and on the unique risks of building with LLMs and agent frameworks.
What We're Looking For
  • 4+ years of hands-on experience in DevSecOps, application security, or platform security roles.
  • Strong working knowledge of TypeScript and the Node.js ecosystem.
  • Practical experience securing cloud infrastructure (AWS, GCP, or Azure), containers, and Kubernetes.
  • Fluency with modern CI/CD tooling (GitHub Actions, or similar) and IaC (Terraform, Pulumi).
  • Genuine curiosity about - and ideally hands-on experience with agentic AI systems: LLM tool use, function calling, MCP, agent frameworks (LangGraph, OpenAI Agents SDK, Anthropic SDK, etc.), and the emerging security patterns around them.
  • A collaboration-first mindset. You write clearly, give feedback kindly, and would rather pair on a problem than throw a Jira ticket over the wall.
  • Comfort with ambiguity - the security playbook for agentic systems is being written in real time, and you want to help write it.
Bonus Points
  • Experience with prompt-injection research, LLM red-teaming, or AI safety/evals work.
  • Contributions to open-source, especially in the TypeScript or AI or Security ecosystems.
  • Familiarity with SOC 2, ISO 27001, or similar compliance frameworks - and opinions on how to satisfy them without crushing engineering velocity.
  • Background in incident response or detection engineering at a fast-moving company.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer for Agentic AI Security & CI/CD
DevSecOps Engineer for Agentic AI Security & CI/CD

OpenTalent • United States

On-site
USD 140,000 - 190,000
AI Engineer
AI Engineer

Valsoft Corporation • Northern (KY)

Hybrid
USD 120,000 - 180,000
Security Engineer, Agent Security
Security Engineer, Agent Security

Coinscapture • Northern (KY)

Hybrid
USD 180,000 - 240,000
Chief Information Security Officer (CISO) - Austin
Chief Information Security Officer (CISO) - Austin

Human Agency • United States

On-site
USD 150,000 - 200,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Human Agency • Boston (MA)

On-site
USD 150,000 - 250,000
Chief Information Security Officer (CISO) - St Louis
Chief Information Security Officer (CISO) - St Louis

Human Agency • United States

On-site
USD 150,000 - 200,000
Senior AI Engineer, Security Infrastructure
Senior AI Engineer, Security Infrastructure

Jobtailor • Pennsylvania

On-site
USD 180,000 - 260,000
AI Engineer
AI Engineer

Aslan • Washington

On-site
USD 150,000 - 210,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Virginia (MN)

Hybrid
USD 120,000 - 160,000
Hybrid work model
Competitive benefits package
Principal DevSecOps Engineer
Principal DevSecOps Engineer

Agentic Defense Solutions, Inc. • Tysons (VA)

On-site
USD 170,000 - 210,000