DevSecOps Architect – CI/CD & Application Security
$125,000–$165,000 year
On-site · London, England, United Kingdom or New York City, New York, United States
Job Summary
DevSecOps Architect enables secure software delivery by embedding AppSec and cloud security into CI/CD pipelines and developer workflows. Responsibilities include designing, implementing, and operating automated security guardrails across source code, build, and deployment pipelines; embedding automated AppSec checks across code, dependencies, builds, and deployment; defining secure CI/CD reference architectures; partnering with engineering to minimize friction; developing reusable pipeline templates, policy controls, and automation to scale AppSec; securing pipeline infrastructure and credentials against build manipulation and leakage; integrating security findings with security monitoring; responding to security findings; aligning pipeline controls with cloud security best practices; embedding AI/ML/GenAI security controls within pipelines; enforcing secure usage patterns for LLMs and AI services; safeguarding AI-related secrets and API access; monitoring risks from AI/ML components; contributing to AI risk governance and auditability; staying current on AI security threats; authoring documentation and training for secure CI/CD/AppSec adoption; evaluating emerging threats and improving controls.
Required Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent experience
- 3–6 years of experience in DevSecOps, Application Security, or Platform Security roles
- Strong hands-on experience securing CI/CD pipelines using GitHub, Jenkins, and Azure DevOps
- Solid understanding of application security concepts (secure coding, dependency risk, pipeline hardening, secrets management)
- Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle
Desired Qualifications
- Experience with policy-as-code and automated security governance
- Knowledge of Kubernetes, container security, and cloud-native architectures
- Experience integrating AppSec signals into enterprise security platforms
- Experience with AI/ML and Generative AI concepts, including LLMs
- Experience securing CI/CD pipelines using GitHub, Jenkins, and Azure DevOps
- Foundational understanding of AI/ML and Responsible AI governance frameworks
- Experience implementing shift-left AppSec controls in modern SDLCs
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.