Remotery

Gen AI Security, DevSecOps Engineer

atNBARemoteUS flagNew JerseyFull-timeDevOps & Site Reliability Engineer (SRE)SeniorLead$145k – $165k/year

Posted Jul 15

This is a fully remote position, open to applicants in New Jersey.

📋 Description

• Secure CI/CD pipelines at scale across the organization's CI/CD platforms by utilizing standardized security templates and automated policy enforcement, incorporating static analysis (SAST), software composition analysis (SCA), container security, infrastructure as code (IaC), and secrets scanning, with the capability to break builds on critical and high severity findings.

• Manage the enterprise SAST and SCA platform, including scan engine infrastructure, query tuning, severity calibration, and finding triage; maintain a knowledge base on exploitability to distinguish true positives from false positives, ensuring rapid and frictionless security processes.

• Develop automated compliance tools that identify necessary scans, validate pipeline configurations, and highlight coverage gaps; conduct audits of pipeline posture across platforms and work directly with engineering teams for remediation.

• Facilitate secure SDLC practices and security gates (SAST, SCA, container, IaC, DAST), threat modeling, SBOM generation, and dependency verification; collaborate with DAST and penetration testing functions, and respond to bug bounty findings.

• Design and implement the enterprise security operations platform along with automation that orchestrates DevSecOps workflows (scan state changes, triage, exemptions, intake, notifications), including AI-assisted vulnerability triage with proper guardrails, audit trails, and human oversight.

• Define and report on security risk metrics, lead security audits and assessments, manage supply chain and CVE incident responses across the organization, and mentor junior team members.

• Oversee security reviews of Generative AI applications, agentic workflows, and AI developer tools submitted through the enterprise AI intake process, evaluating them against OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, NIST AI RMF, MITRE ATLAS, and NBA Gen AI security policies and standards.

• Author and maintain NBA Generative AI security policies and standards, which include controls for AI data protection, model and prompt security, agentic AI, MCP (Model Context Protocol) integration, and AI developer tooling.

• Assess and onboard Gen AI security tools such as runtime guardrails, AI red teaming, browser and DLP controls, and MCP governance, while designing and managing runtime AI security controls integrated into application pipelines.

• Govern enterprise security over AI developer tooling and the MCP server approval workflow; collaborate with Enterprise Gen AI, Cloud Infrastructure, GRC, Legal, and Privacy functions to align AI security controls with broader AI governance.

• Manage and operate the enterprise cloud security platform across a large multi-cloud environment (cloud posture, container, and IaC scanning); identify, prioritize, and drive remediation of misconfigurations and vulnerabilities as per defined SLAs with infrastructure and application teams.

• Oversee the configuration of cloud security scanning policies and service account governance (scope, least privilege, credential rotation), lead platform lifecycle initiatives, and conduct technical security configuration assessments of cloud platforms.

• Maintain the Kubernetes security posture across a large cluster footprint, including admission control, RBAC, namespace isolation, network policies, and Pod Security Standards, and execute admission controller enforcement programs to transition policies from audit to block in staged, communicated rollouts with exception and rollback processes.

• Design and implement automated credential rotation across cloud identity and key management services (cross-account role assumption, grace periods, owner notifications) and lead the initiative to replace static access keys with OAuth 2.0, OIDC, and role-based authentication.

• Oversee the secrets lifecycle across cloud and pipeline secret stores, ensuring detection, alerting, and automated rotation, and create reporting that highlights aging and non-compliant secrets.


⛳️ Requirements

• Bachelor's degree in a technical field (or equivalent practical experience).

• At least seven years of experience in IT (with a minimum of five years in information security).

• Practical experience in administering and integrating modern security tools across the DevSecOps toolset, including SAST, SCA, DAST, container security, IaC, and secrets scanning.

• Direct experience in designing and securing CI/CD pipelines on modern CI/CD platforms.

• Strong programming and scripting skills, capable of building integrations, automation, and tools against platform APIs.

• Solid hands-on experience in cloud security across at least one major cloud provider, covering identity and access management, secrets management, network security, and posture management, guided by frameworks such as CIS Benchmarks, Cloud Security Alliance, and the NIST SP 800-53 and 800-190/800-204 series.

• Working knowledge of Kubernetes and container security, including RBAC, admission control, namespace isolation, network policies, and Pod Security Standards.

• Familiarity with AI and LLM security frameworks (OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, NIST AI RMF, MITRE ATLAS) and the controls to mitigate Generative AI risks such as prompt injection, sensitive data exposure, and excessive agency (preferred).

• Understanding of governance related to cloud and AI computing in terms of risk, exposure, impact, and policy; experience in writing architectural plans, standards, and guidelines for enterprise platforms.

• One or more industry-recognized security certifications, such as GIAC (GCSA), a cloud security certification (CCSP, CCSK, or equivalent), or an application or offensive certification (CEH, OSCP, or CySA+).


🏝️ Benefits

• Medical coverage.

• Dental insurance.

• Vision coverage.

• Life and AD&D insurance.

• Short-term and long-term disability.

• Fertility and family-forming assistance.

• Wellbeing allowance.

• Educational assistance.

• Mental health coaching and therapy.

• Tax-advantaged accounts such as HSA and healthcare/dependent care FSAs.

• A 401(k) retirement plan.

• Time off benefits, including vacation, sick leave, and personal days.

People also viewed

The CodestJul 26

DevOps Engineer

PL flagPoland OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
IRIUMJul 26

Ingeniero/a Cloud DevOps

ES flagSpain OnlyFull-timeDevOps & Site Reliability Engineer (SRE)€33k – €40k/year
ApplyView job
SólidesJul 26

Senior DevOps Engineer

BR flagBrazil OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
ResilincJul 25

Junior/Senior Site Reliability Engineer – Night Shift

IN flagIndia OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
Verity GroupJul 25

Senior SRE / DevOps Engineer

Anywhere in the WorldFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
HOESSLER & HOESSLERJul 25

DevOps Software Engineer – Career Ambitions

DE flagGermany OnlyFull-timeDevOps & Site Reliability Engineer (SRE)€65k – €75k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers