Job Description
Job Title: Senior DevSecOps Engineer Location-Type: Hybrid - Danboro, PA Start Date:ASAP Duration: Permanent Compensation Range: $140,000 - $160,000/yr Benefits: Health, Dental, Vision, 401K, PTO, Tuition Reimbursement Visa Sponsorship: Not eligible for visa sponsorship Job Description:This hands-on architect-level role is responsible for building and operating the security architecture that enables the client's engineering teams to ship code safely at high velocity, with a critical focus on securing a growing AI-powered application portfolio. Job Summary•Design and implement automated security scanning (SAST, SCA, DAST) embedded directly into CI/CD pipelines to maintain high deployment velocity without sacrificing security coverage •Continuously assess, harden, and elevate the security posture of the client's AWS cloud infrastructure across customer-facing and internal enterprise systems •Build event-driven, policy-as-code automation to detect and auto-remediate common security issues in near real-time, replacing manual audit processes •Define the security architecture for AI-powered applications, including data access controls, model governance, prompt safety, and auditability for agentic systems •Own the end-to-end vulnerability management lifecycle, including triage, prioritization, tracking, and automated remediation of vulnerabilities and cloud misconfigurations •Collaborate with infrastructure, AI engineering, and IS teams to integrate threat response practices across the full technology stack •Define and lead security incident response playbooks, root-cause analyses, and post-incident reviews to drive systemic improvements Minimum Requirements:• 8+ years of experience in cloud security, DevSecOps, or security engineering • Deep expertise in AWS security services, including IAM, Security Hub, GuardDuty, Config, KMS, VPC design, and CloudTrail • Proven experience integrating automated security tooling (SAST, SCA, DAST) into modern CI/CD pipelines without degrading deployment velocity • Hands-on experience with infrastructure-as-code and policy-as-code using Terraform or AWS CDK • Strong scripting and automation skills in Python, Go, or Bash, with the ability to build custom security tools and integrate systems programmatically • Experience securing containerized workloads including Docker, Kubernetes, and ECS/EKS deployments • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field Preferred Qualifications:• Experience defining security architecture for AI/LLM-powered systems, including prompt injection protections, model access controls, output validation, and auditability for agentic applications • Hands-on experience operationalizing CrowdStrike and Zscaler in an enterprise environment • Familiarity with Model Context Protocol (MCP) and emerging security considerations for tool-use in agentic AI systems • Relevant certifications: AWS Security Specialty, CISSP, CCSP, or equivalent • Experience contributing to or leading security programs in support of SOC 2, ISO 27001, or similar compliance frameworks • Background working in a global organization with multi-region cloud deployments