Lead DevSecOps Engineer
Lawrence Harvey · New York, NY
قدّم وتابع مع أبلاي إيدجLawrence Harvey is seeking a highly technical DevSecOps Lead to define and scale security engineering practices across a modern cloud-native financial services company. This individual will drive the security strategy for developer platforms, software delivery pipelines, cloud infrastructure, and emerging AI capabilities while building automation that enables engineering teams to move quickly without compromising security.Key ResponsibilitiesLead the technical vision and architecture for DevSecOps across the engineering organization, ensuring security is embedded throughout developer platforms, shared services, and infrastructure.Design, implement, and continuously improve secure CI/CD practices, including hardened build pipelines, software supply chain protections, artifact integrity, SBOM generation, dependency management, and automated security validation within developer workflows.Develop cloud security guardrails across AWS environments by implementing scalable identity controls, account governance, encryption standards, secrets management, and reusable Infrastructure-as-Code modules that promote secure engineering by default.Own the security architecture of Kubernetes-based platforms, including workload identity, admission controls, network segmentation, runtime protections, image governance, and multi-tenant security.Define security standards for AI-enabled infrastructure, including model access controls, secure data handling, AI workload protection, prompt security, and software supply chain considerations as AI platforms continue to mature.Build scalable vulnerability management capabilities through automation, intelligent prioritization, and streamlined remediation workflows that integrate directly into engineering processes.Establish enterprise-wide secrets management standards, including credential issuance, rotation, lifecycle management, and secure runtime delivery.Collaborate closely with Information Security, Application Security, Governance, Risk & Compliance, and Incident Response teams to translate security requirements into practical engineering solutionsRequired Qualifications10+ years of experience in Security Engineering, Platform Engineering, DevSecOps, or a closely related discipline, including at least 5 years focused on cloud or application security.Demonstrated success building internal security platforms, automation, or developer tooling that achieved widespread engineering adoption.Deep understanding of modern CI/CD security and software supply chain best practices, including artifact signing, SBOM generation, build provenance, dependency management, container security, and secure deployment pipelines.Strong expertise securing AWS environments, including IAM, Service Control Policies, workload identities, encryption services, secrets management platforms, and Infrastructure-as-Code using Terraform.Preferred QualificationsExperience securing AI or machine learning platforms, including model security, prompt injection defenses, retrieval-augmented generation (RAG) security, AI agents, or AI supply chain protections.Previous experience working within high-growth technology organizations where engineers are expected to own projects from design through production.Note: this role is FULLY onsite in New York City and cannot transfer or sponsor new visas.