Nadia Bakhurji Architectural & Engineering Consultants (NBA)
Gen AI Security, DevSecOps Engineer
Location
New Jersey
Posted
10 days ago
Salary
$145K - $165K / year
Seniority
Lead
Job Description
Gen AI Security, DevSecOps Engineer
NBA
• Secure CI/CD pipelines at scale across the organization's CI/CD platforms with standardized security templates and automated policy enforcement, embedding static analysis (SAST), software composition analysis (SCA), container, infrastructure as code (IaC), and secrets scanning, with break build enforcement on critical and high severity findings • Administer the enterprise SAST and SCA platform (scan engine infrastructure, query tuning, severity calibration, finding triage) and maintain the exploitability knowledge base that distinguishes true positives from false positives to keep security fast and low friction • Build automated compliance tooling that detects required scans, validates pipeline configuration, and flags coverage gaps; audit pipeline posture across platforms and drive remediation directly with engineering teams • Support secure SDLC practices and security gates (SAST, SCA, container, IaC, DAST), threat modeling, SBOM generation, and dependency verification; coordinate with the DAST and penetration testing functions and act on bug bounty findings • Design and build the enterprise security operations platform and the automation that orchestrates DevSecOps workflows (scan state changes, triage, exemptions, intake, notifications), including AI-assisted vulnerability triage with appropriate guardrails, audit trails, and human oversight • Define and report security risk metrics, lead security audits and assessments, conduct supply chain and CVE incident response across the estate, and mentor junior team members • Lead security reviews of Generative AI applications, agentic workflows, and AI developer tools submitted through the enterprise AI intake process, assessing against OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, NIST AI RMF, MITRE ATLAS, and NBA Gen AI security policy and standards • Author and maintain NBA Generative AI security policy and standards, including controls for AI data protection, model and prompt security, agentic AI, MCP (Model Context Protocol) integration, and AI developer tooling • Evaluate and onboard Gen AI security tooling such as runtime guardrails, AI red teaming, browser and DLP controls, and MCP governance, and design and operate runtime AI security controls integrated into application pipelines and runtime • Govern enterprise security over AI developer tooling and the MCP server approval workflow, and partner with the Enterprise Gen AI, Cloud Infrastructure, GRC, Legal, and Privacy functions to align AI security controls with broader AI governance • Administer and operate the enterprise cloud security platform across a large multi-cloud estate (cloud posture, container, and IaC scanning); detect, prioritize, and drive remediation of misconfigurations and vulnerabilities against defined SLAs with infrastructure and application teams • Own cloud security scanning policy configuration and service account governance (scope, least privilege, credential rotation), lead platform lifecycle work, and perform technical security configuration assessments of cloud platforms • Own the Kubernetes security posture across a large cluster footprint, including admission control, RBAC, namespace isolation, network policies, and Pod Security Standards, and execute admission controller enforcement programs that move policies from audit to block in staged, owner-communicated rollouts with exception and rollback processes • Design and operate automated credential rotation across cloud identity and key management services (cross-account role assumption, grace periods, owner notifications) and lead the initiative to eliminate static access keys in favor of OAuth 2.0, OIDC, and role-based authentication • Manage the secrets lifecycle across cloud and pipeline secret stores with detection, alerting, and automated rotation, and build reporting that surfaces aging and non-compliant secrets
Job Requirements
- Bachelor's degree in a technical discipline (or equivalent work experience)
- Minimum of seven years in IT (a minimum of five years in information security)
- Hands-on experience administering and integrating modern security tooling across the DevSecOps toolset, including SAST, SCA, DAST, container, IaC, and secrets scanning
- Hands-on experience designing and securing CI/CD pipelines on modern CI/CD platforms
- Strong programming and scripting ability, with the ability to build integrations, automation, and tooling against platform APIs
- Solid hands-on implementation of cloud security across at least one major cloud provider, including identity and access management, secrets management, network security, and posture management, guided by frameworks such as CIS Benchmarks, Cloud Security Alliance, and the NIST SP 800-53 and 800-190/800-204 series
- Working knowledge of Kubernetes and container security, including RBAC, admission control, namespace isolation, network policies, and Pod Security Standards
- Familiarity with AI and LLM security frameworks (OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, NIST AI RMF, MITRE ATLAS) and the controls that mitigate Generative AI risks such as prompt injection, sensitive data disclosure, and excessive agency (preferred)
- Understanding of governance applied to cloud and AI computing in terms of risk, exposure, impact, and policy; experience writing architectural plans, standards, and guidelines for enterprise platforms
- One or more industry security certifications, such as GIAC (GCSA), a cloud security certification (CCSP, CCSK, or a cloud provider security certification), or an application or offensive certification (CEH, OSCP, or CySA+)
Benefits
- medical
- dental
- vision
- life/AD&D insurance
- short- and long-term disability
- fertility and family-forming assistance
- wellbeing allowance
- educational assistance
- mental health coaching/therapy
- tax advantaged accounts such as HSA and healthcare/dependent care FSAs
- a 401(k) retirement plan
- time off benefits that include vacation, sick time, and personal days
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
DevOps Engineer
MerativeA data and software partner for health and government social services, with tech and expertise to drive real progress.
• Perform product development in accordance with Merge’s methodology and practices; • Perform software module requirement analysis, design, and test design • Prepare software module specifications, designs, test descriptions and estimates • Implement software modules and unit tests as assigned and conduct appropriate module testing • Conduct appropriate verification and validation activities • Detect, report, investigate, and fix product defects as appropriate; • Participate in the review of product engineering artifacts (e.g., specifications, designs, test descriptions, implementations, tests, records, reports, etc) • Design, develop, and recommend next generation platforms for cloud and on-premise deployments • Develop deployment systems for a variety of interdependent applications running on Linux and Kubernetes • Establish and maintain continuous integration and continuous delivery (CI/CD) pipelines to automate the build, test, and deployment of applications • Assist in the preparation and review of product, engineering, and management plans and reports (e.g., program and project plans) as required • Prepare updates to system specifications, designs, test descriptions, hazard analysis, verification and validation test procedures, and related documentation supporting software development to known standards • Mentor team members and peer review product artifacts including requirement specifications, design specifications, code, etc. • Engage actively in design and code reviews of work items completed by the team in conjunction with the Team Lead and/or architect • Interface with customer(s) and Merge staff to gather product requirements, present technical aspects of the product, and understand problems with the product
Senior Site Reliability Engineer
DiscogsThe world's leading music discovery and record collecting platform empowered by a community of obsessed music fans.
• Owning tasks and larger projects from planning to production rollout • Learning new technologies and building expertise with the goal of teaching and mentoring others; mentoring with the goal of force-multiplying through docs and tools • Maintaining organization cloud presence in AWS • Automating and deploying infrastructure configurations using Infrastructure as Code (IAC) • Mentoring engineering squads on Platform best practices for Kubernetes, MySQL, Kafka, and other software development lifecycle areas • Assisting engineering squads with capacity planning, on-call preparation, and production readiness • Writing documentation and runbooks that contribute to the engineering organization’s knowledge base • Implementing monitoring and alerting systems with Discogs observability tools • Working in a containerized, orchestrated environment • Participating in on-call rotation, responding to incidents, and troubleshooting data and other operations issues • Contributing to the reliability and design patterns of our Kafka CDC and event workflows • Contributing to agentic AI best practices and tooling, including skills, agents, and safety
Staff Software Engineer, Dev Ops
CongaConga delivers the most scalable revenue lifecycle management solution to help companies crush operational complexity.
• Serve as a senior technical leader responsible for designing, building, and evolving the infrastructure, automation, and cloud platform capabilities that power Conga’s revenue lifecycle management solutions • Partner closely with Engineering, Product, Security, and Operations teams to establish scalable DevOps practices, accelerate software delivery, and improve platform reliability across our global SaaS ecosystem • Influence architectural decisions, drive modernization initiatives, and champion best practices that improve developer productivity, system scalability, and operational excellence • Help shape the future of our engineering platform by designing highly available cloud infrastructure, advancing automation capabilities, and enabling best-in-class development experiences. • Design, implement, and optimize enterprise-scale CI/CD pipelines that accelerate software delivery • Establish automation strategies that improve deployment consistency, quality, and release velocity • Architect, build, and maintain highly available cloud environments across AWS and Microsoft Azure. • Develop Infrastructure-as-Code solutions using technologies such as Terraform and CloudFormation • Champion Site Reliability Engineering (SRE) principles and reliability-focused engineering practices.
Senior Software Engineer, Dev Ops
CongaConga delivers the most scalable revenue lifecycle management solution to help companies crush operational complexity.
• Design, implement, and maintain scalable CI/CD pipelines that automate software build, testing, deployment, and release processes. • Drive continuous improvement initiatives that increase deployment efficiency, reliability, and developer productivity. • Partner with engineering teams to establish DevOps best practices across the software development lifecycle. • Champion automation-first approaches that reduce manual effort and improve operational consistency. • Design and support highly available, secure, and scalable cloud infrastructure across AWS and Microsoft Azure environments. • Develop and maintain Infrastructure-as-Code (IaC) solutions using tools such as Terraform and CloudFormation. • Optimize platform performance, cost efficiency, and operational resilience across production and non-production environments. • Partner with engineering teams to build and maintain cloud-native architectures that support growth and scale. • Design, deploy, and manage containerized workloads utilizing Docker and Kubernetes. • Establish deployment standards and operational best practices for Kubernetes-based environments. • Support container orchestration, monitoring, scaling, and lifecycle management initiatives. • Drive platform modernization efforts through the adoption of cloud-native technologies. • Implement and maintain infrastructure and application security best practices, including encryption, access controls, network security, and vulnerability management. • Design solutions that support fault tolerance, disaster recovery, and business continuity objectives. • Collaborate with teams to improve observability, monitoring, alerting, and incident response capabilities. • Proactively identify risks and implement solutions that improve system reliability and uptime. • Collaborate with software engineers, architects, and product teams to support scalable application development and deployment strategies. • Provide technical guidance on infrastructure architecture, cloud adoption, and operational best practices. • Participate in architectural reviews and contribute to long-term platform strategy discussions. • Foster a culture of continuous learning, innovation, and engineering excellence.



