Director of DevOps/SecOps

Service Core

Denver (CO)

On-site

USD 190,000 - 225,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Open time-off policy
Healthcare, dental and vision insurance
401(k) with match
Company-provided hardware
Bi-weekly lunch stipend for remote employees

Job summary

Service Core in Denver is searching for a Director of DevOps/SecOps to enhance our security posture in cloud platforms. This role focuses on operational safety, AI governance, and driving compliance across AWS and GCP environments.

The ideal candidate will have extensive experience in DevOps, strong leadership skills, and a commitment to establishing security-first engineering practices. A competitive salary range of $190k–$225k is offered along with comprehensive benefits.

Qualifications

  • 10+ years of experience in DevOps, SecOps, or a combined DevSecOps role.
  • 3+ years in a leadership or management capacity with direct reports.
  • Deep hands-on experience with AWS security components.

Responsibilities

  • Own and continuously improve security posture across AWS and GCP.
  • Lead threat modeling, vulnerability management, and incident response.
  • Drive SOC 2 Type II compliance and manage vendor security reviews.

Skills

DevOps experience
SecOps expertise
AWS Security
GCP Security
AI tool governance

Education

Relevant certifications (CISSP, AWS Security Specialty)

Tools

AWS services
GCP services
Docker

Job description

Director of DevOps/SecOps

ServiceCore is a leading field service software platform built for the portable sanitation and roll‑off industries. We provide two SaaS products—ServiceCore for liquid waste operators and Docket for solid waste haulers—serving thousands of operators across North America.

About the role

We’re looking for a Director of Dev/SecOps to own the security posture and operational foundation across ServiceCore’s entire cloud environment. The role is security‑first, operating across AWS (ServiceCore) and GCP/Firebase (Docket), and includes AI tool governance.

What you’ll do
AI Tool Governance & Security
  • Partner with the AI Council and Engineering Directors to build an AI tool evaluation framework—defining the security, privacy, and compliance criteria for new AI tools.
  • Govern multi‑LLM provider relationships—review data processing agreements, audit data retention policies, and ensure contractual protections for customer data.
  • Establish and enforce policies around data flow through AI services: PII boundaries, source code confidentiality rules, and customer data handling for coding assistants, LLM APIs, and agentic tools.
  • Secure MCP‑connected agents with least‑privilege access models, audit trails, and data egress controls.
  • Define secure patterns for integrating LLM capabilities into products—including prompt injection defenses, output validation, model access controls, and logging/observability.
  • Build and maintain an AI tool inventory with risk classifications and lead periodic reviews.
  • Partner with engineering and product to help obtain AI productivity benefits while managing risk.
Security Leadership
  • Own and continuously improve security posture across AWS and GCP/Firebase.
  • Lead threat modeling, vulnerability management, and security incident response programs.
  • Establish and enforce security policies, standards, and controls across the SDLC.
  • Champion a security‑first engineering culture.
  • Manage relationships with external auditors, penetration testers, and compliance bodies.
Compliance & Risk
  • Drive SOC 2 Type II compliance and own evidence collection across both platforms.
  • Manage PCI‑DSS considerations across payment processor integrations.
  • Build and maintain a risk register and prioritize risks to leadership.
  • Own third‑party vendor security reviews for 20+ integration partners, including AI vendors.
  • Monitor regulatory developments relevant to SaaS, AI, and the industries we serve.
DevOps & Platform Engineering
  • Secure CI/CD pipelines across both cloud environments—secrets management, dependency scanning, SAST/DAST.
  • Lead infrastructure‑as‑code strategy and embed security guardrails by default.
  • Own cloud security architecture.
  • Secure Cloudflare CDN/WAF configuration, DDoS posture, and DNS hygiene.
  • Drive incident response readiness—runbooks, on‑call processes, post‑mortems, and SLA accountability.
Team & Cross‑Functional Leadership
  • Hire, develop, and lead a DevSecOps team.
  • Collaborate with engineering leads on architectural decisions with security implications.
  • Report to senior leadership on security metrics, risk posture, compliance status, and AI tool governance.
  • Serve as the internal expert and educator on security and AI risk topics.
What you’ll bring
  • 10+ years of experience in DevOps, SecOps, or a combined DevSecOps role.
  • 3+ years in a leadership or management capacity with direct reports.
  • Deep hands‑on experience with AWS security—including IAM, VPC, ECS, Lambda, SQS, RDS, DynamoDB, Secrets Manager, CloudWatch, CloudFormation.
  • Meaningful experience with GCP and/or Firebase—including Firestore security rules, Cloud Functions security, GCP IAM, and service account management.
  • Experience owning or significantly contributing to SOC 2 Type II audits.
  • Strong background in securing CI/CD pipelines and containerized workloads (Docker, ECS, or EKS).
  • Demonstrated experience governing third‑party integrations and API security at scale.
  • Working knowledge of SAST, DAST, SCA, dependency scanning, and secrets management tooling.
  • Real point of view on AI tool security—understanding risks of coding assistants, LLM APIs, MCP‑connected agents, and AI in developer workflows.
  • Ability to communicate risk and security concepts clearly to non‑technical audiences and executives.
  • Background in SaaS with understanding of multi‑tenant security architecture.
Nice to have
  • Relevant certifications: CISSP, AWS Security Specialty, Google Professional Cloud Security Engineer, CCSP, or equivalent.
  • Experience with PCI‑DSS compliance in a SaaS context.
  • Familiarity with Cloudflare security features: WAF, Zero Trust, Workers, DDoS protection.
  • Experience securing PHP legacy applications alongside modern microservices.
  • Hands‑on experience with vector database security (e.g., Qdrant) or AI/ML pipeline security.
  • Experience defining data governance policies for AI tools in a software engineering organization.
  • Background building DevSecOps functions from scratch at a growth‑stage company.
Benefits & Compensation
  • Base Salary: $190,000–$225,000 (dependent on experience)
  • 14 company holidays plus an open time‑off policy.
  • Healthcare, dental and vision insurance with generous employer contributions.
  • 401(k) with match.
  • Regular lunches and a fully‑stocked kitchen (if in Denver).
  • Bi‑weekly Grubhub lunch stipend for remote employees.
  • Company‑provided hardware of your choice/configuration.
  • Strong company culture aligned with core values: Love our Customers, Be Real, Give a Shit, Deliver Results, and Keep it Fun.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff+ Security Engineer, Core Command
Staff+ Security Engineer, Core Command

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare programs
Medical/Vision/Dental coverage
HSA with employer contributions
+7
Director of DevSecOps & AI Security
Director of DevSecOps & AI Security

Service Core • Denver (CO)

On-site
USD 190,000 - 225,000
Open time-off policy
Healthcare, dental and vision insurance
401(k) with match
+2
Staff+ Security Engineer, Developer Tools
Staff+ Security Engineer, Developer Tools

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare coverage
Mental health support
Parental leave
+3
Data Security Engineer
Data Security Engineer

General Intuition & Medal • New York (NY)

On-site
USD 100,000 - 150,000
Competitive salary and equity
Comprehensive medical, dental, and vision coverage
401(k)
+4
Security Engineer
Security Engineer

DataVisor • Mountain View (CA)

Hybrid
USD 120,000 - 150,000
Medical, dental, vision insurance
401(k) retirement savings plan
Discretionary PTO + holidays
+1
Director of IT, Infrastructure & Security
Director of IT, Infrastructure & Security

FieldAI • Irvine (CA)

On-site
USD 120,000 - 160,000
DevSecOps Engineer
DevSecOps Engineer

Open Select Rec • United States

Hybrid
USD 180,000 - 200,000
Hybrid work model
Equity
Technical excellence opportunities
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2
DevOps, MLOps & Security Engineering Lead - San Jose, CA
DevOps, MLOps & Security Engineering Lead - San Jose, CA

KlearNow.ai • California (MO)

Hybrid
USD 140,000 - 165,000
Comprehensive medical, dental, and vision insurance
Equity participation
Flexible time off
AI Security Engineer
AI Security Engineer

tms • Chicago (IL)

Hybrid
USD 110,000 - 140,000
Generous medical, dental, vision benefits
401(k) with company match
Tuition reimbursement
+2