Senior AI DevSecOps Engineer

Jobtailor

Kansas

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an senior information security leader to develop and implement enterprise security policies and tools. You will design DevSecOps, embed secure controls in CI/CD, and optimize CNAPP platforms to improve cloud security and workload protection.

You will lead vulnerability management and risk-based prioritization across engineering teams. You will collaborate across application, cloud, and platform teams to reduce MTTR, enforce secure coding standards, and model threats.

Qualifications

  • BS/BA in information technology or related field.
  • 8+ years in systems administration and security.
  • Access management and network security technologies.
  • Experience with multiple technical and business disciplines.
  • Broad experience to plan and design highly complex systems.
  • Preferred: DevSecOps, Application Security, Cloud Security or related fields.
  • Hands-on experience integrating security into CI/CD at scale.
  • Experience with CNAPP platforms Wiz/Prisma Cloud.
  • Strong knowledge of Application Security (SAST, DAST, SCA).
  • Security certifications preferred (CISSP/CSSLP/CCSP).

Responsibilities

  • Develops, recommends, and implements enterprise information security policies and standards.
  • Lead the design and integration of DevSecOps across the enterprise.
  • Drive secure-by-design practices across CI/CD pipelines and cloud platforms.
  • Partner with engineering, cloud, and platform teams to embed automated security controls.
  • Lead the design and implementation of DevSecOps solutions in CI/CD (GitHub, GitLab, Jenkins).
  • Define and implement secure SDLC practices, including automated testing and threat modeling.
  • Own and optimize CNAPP platforms (Wiz, Prisma Cloud) for cloud security posture.
  • Drive vulnerability management strategy and integrate into developer workflows.
  • Integrate AppSec tools (SAST, DAST, SCA, container scanning) for scalable pipelines.
  • Establish guardrails for AI-generated code security and mitigate risks.
  • Embed security controls into AI-enabled apps and APIs addressing AI risks.
  • Partner with engineering to reduce vulnerability backlog and MTTR.
  • Define KPIs and reporting for security posture and risk reduction.
  • Serve as advisor for complex security and integration challenges.
  • Leads architecture support and risk assessment methodologies for security products.

Skills

DevSecOps
Application Security
Cloud Security
CI/CD Security
Scripting
IaC
AI Security
Vulnerability Mgmt
Threat Modeling
Security in SDLC

Education

BS/BA in Information Technology or related field

Tools

Snyk
Checkmarx
Veracode
SonarQube
CNAPP Wiz Prisma Cloud

Job description

Responsibilities
  • Develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures and other elements of an infrastructure necessary to support information security in compliance with established company policies, regulatory requirements, and generally accepted information security controls.
  • Lead the design and integration of DevSecOps, Application Security and Vulnerability Management capabilities across our enterprise.
  • Drive secure-by-design practices across CI/CD pipelines, cloud-native platforms, and modern development workflows—including AI-assisted coding environments.
  • Partner closely with application engineering, cloud, and platform teams to embed scalable, automated security controls that reduce risk while enabling developer velocity.
  • Lead the design and implementation of DevSecOps solutions integrated into CI/CD pipelines (GitHub, GitLab, Jenkins)
  • Define and implement secure SDLC practices, including automated testing, threat modeling, and secure coding standards.
  • Own and optimize CNAPP platforms (e.g., Wiz, Prisma Cloud) to improve cloud security posture and workload protection.
  • Drive vulnerability management strategy, including risk-based prioritization and integration into developer workflows.
  • Integrate and tune AppSec tools (SAST, DAST, SCA, container scanning) for scalable pipeline adoption.
  • Establish guardrails for AI-generated code security, including validation of outputs and mitigation of risks such as insecure code patterns and data exposure.
  • Embed security controls into AI-enabled applications and APIs, addressing emerging risks (e.g., prompt injection, model misuse).
  • Partner with engineering teams to reduce vulnerability backlog and MTTR.
  • Define KPIs and reporting for security posture, pipeline coverage, and risk reduction.
  • Serve as a technical advisor and escalation point for complex security and integration challenges.
  • Leads system and network architecture support for information and network security technologies; Leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations; Leads the development of requirements, system architecture, and software design of security products and services; Develops security incident response plans and strategies.
Requirements
  • Requires BS/BA in information Technology or related field of study
  • minimum of 8 years experience in systems administration and security aspects of information systems
  • access management and network security technologies
  • experience with multiple technical and business disciplines
  • broad-based experience to plan and design highly complex systems
  • any combination of education and experience, which would provide an equivalent background.
  • Preferred Skills: Experience in DevSecOps, Application Security, Cloud Security, or related fields
  • Hands-on experience integrating security into CI/CD pipelines at scale
  • Experience with CNAPP platforms (e.g., Wiz, Prisma Cloud)
  • Strong knowledge of Application Security (SAST, DAST, SCA, API security)
  • Cloud Security (AWS, Azure, or GCP)
  • Containers & Kubernetes security
  • Vulnerability management and risk prioritization
  • Experience with automation, scripting, and infrastructure-as-code (IaC)
  • Experience securing AI/LLM-enabled applications or AI-assisted development workflows
  • Familiarity with AI security risks (e.g., OWASP Top 10 for LLMs, prompt injection, data leakage)
  • Experience with tools such as Snyk, Checkmarx, Veracode, SonarQube
  • Strong understanding of DevOps and Agile practices
  • Security certifications (e.g., CISSP, CCSP, CSSLP) preferred
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer – Information Security
DevSecOps Engineer – Information Security

Jobtailor • Town of Florida (NY)

On-site
USD 150,000 - 190,000
Manager - Application & AI Security
Manager - Application & AI Security

Prosum • Scottsdale (AZ)

On-site
USD 140,000 - 190,000
Senior Security AI Engineer
Senior Security AI Engineer

Imperial PFS • Kansas City (MO)

On-site
USD 130,000 - 160,000
IT Security Analyst
IT Security Analyst

Fortegra • Jacksonville (FL)

On-site
USD 85,000 - 120,000
Principal Engineer – Secure AI
Principal Engineer – Secure AI

Jobtailor • Brooklyn Park (MN)

On-site
USD 150,000 - 230,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Lead Application Security Engineer – AI
Lead Application Security Engineer – AI

Talentrix AI • Charlotte (NC)

On-site
USD 150,000 - 230,000
Staff Cyber Security Engineer – AI Product Security
Staff Cyber Security Engineer – AI Product Security

Jobtailor • New York (NY)

On-site
USD 150,000 - 210,000
Senior Lead AI Security Engineer
Senior Lead AI Security Engineer

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 120,000 - 150,000
DevOps, MLOps & Security Engineering Lead
DevOps, MLOps & Security Engineering Lead

Jobtailor • San Jose (CA)

On-site
USD 180,000 - 240,000