DevSecOps Architect

Posted An Hour Ago
Be an Early Applicant
Headquarters, AZ, USA
In-Office
Expert/Leader
Food • Gaming • Travel • Hospitality
The Role
Design and lead enterprise DevSecOps architecture, embedding security, compliance, and automated testing throughout software delivery. Build secure CI/CD pipelines, policy-as-code, infrastructure-as-code baselines, cloud and Kubernetes guardrails, vulnerability remediation workflows, and developer-facing security tooling. Lead application security, threat modeling, supply-chain security, penetration testing coordination, compliance automation, training, metrics, and continuous improvement across hybrid and multi-cloud environments. Mentor technical teams and champion shared security ownership.
Summary Generated by Built In

Our team members are the key to our company’s success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status.  To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits

Job Description:

At Seminole Hard Rock Support Services, we are on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. As the DevSecOps Architect, you will define, build, and champion the integration of security into every stage of the Secure Software Development Lifecycle (S-SDLC), embedding automated security controls, governance, and compliance into CI/CD pipelines, cloud infrastructure, and application delivery processes across the enterprise.

Reporting to the Director II of Cybersecurity Architecture, Engineering & IAM, this role requires a deeply technical, security-minded architect and engineer who bridges the worlds of software development, cloud operations, and cybersecurity. You will design and implement secure-by-default development frameworks, automate security testing and compliance enforcement, and drive a cultural shift toward shared security ownership, ensuring that every application and infrastructure deployment across all Seminole Hard Rock business units is built secure from the ground up.

This is a shift-left architecture role. The ideal candidate does not sit at the end of the pipeline reviewing what others have built, they embed themselves into the engineering lifecycle, define the standards developers work within, and build the tooling and automation that makes security the path of least resistance. You architect at scale, write production-grade code, and measure your impact in vulnerabilities prevented, not just discovered.

Responsibilities

Security Architecture & Secure SDLC

  • Design and implement an enterprise DevSecOps architecture that embeds security controls, automated testing, and compliance validation into every phase of the software development lifecycle, from code commit through production deployment
  • Define and maintain secure coding standards, application security reference architectures, and security design patterns that development teams adopt as foundational building blocks, not optional guidelines
  • Architect threat modeling frameworks and processes that enable development teams to proactively identify and mitigate security risks during design and development phases, before code is written
  • Establish and govern security gate criteria within CI/CD pipelines, ensuring that code, container images, infrastructure-as-code templates, and third-party dependencies meet security and compliance thresholds before promotion to production
  • Own the security architecture review process for new applications, platforms, and major system changes, providing timely, actionable guidance that accelerates delivery rather than blocking it

Pipeline Engineering & Automation

  • Design, build, and maintain secure CI/CD pipelines integrating automated security tooling across the full spectrum: static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container scanning, infrastructure-as-code (IaC) scanning, and secrets detection
  • Develop and maintain custom pipeline integrations, security automation scripts, and policy-as-code frameworks using Python, PowerShell, Go, or similar languages, enforcing security controls programmatically at scale
  • Implement automated compliance-as-code solutions that continuously validate infrastructure and application configurations against regulatory requirements (PCI-DSS, SOX, tribal gaming regulations) and internal security policies, eliminating manual evidence collection
  • Engineer automated remediation workflows that detect, alert, and resolve common security misconfigurations and vulnerabilities without manual intervention, reducing mean time to remediate across the portfolio
  • Build developer-facing security tooling and integrations that surface security findings directly within developer workflows (IDE plugins, pull request gates, ticketing integrations), making security feedback immediate and actionable

Cloud & Infrastructure Security

  • Architect and enforce security guardrails across cloud environments (Azure, AWS, Google Cloud), including network segmentation, identity and access policies, encryption standards, logging configurations, and monitoring baselines
  • Design and implement secure infrastructure-as-code (Terraform, Ansible, ARM/Bicep, CloudFormation) templates and modules that serve as hardened, reusable baselines for all cloud and on-premises deployments
  • Oversee container and Kubernetes security architecture, including image hardening, runtime protection, network policies, secrets management, and admission control policies
  • Collaborate with cloud engineering, infrastructure, and platform teams to ensure IaaS, PaaS, and serverless workloads across Linux and Windows environments are deployed and operated in accordance with zero-trust principles and enterprise security standards
  • Define and maintain cloud security posture management (CSPM) standards, continuously monitoring for drift and enforcing guardrails that prevent insecure configurations from reaching production

Application Security & Vulnerability Management

  • Lead the application security program in partnership with development teams — conducting architecture reviews, code reviews, and penetration testing coordination to identify and remediate vulnerabilities before they reach production
  • Evaluate, implement, and manage application security tooling across SAST, DAST, SCA, container, and cloud posture domains, ensuring comprehensive, continuous coverage across the full application and infrastructure portfolio
  • Drive adoption of secure software supply chain practices, including software bill of materials (SBOM) generation, dependency management, artifact signing, provenance verification, and third-party component vetting
  • Establish a vulnerability management lifecycle with defined SLAs, risk-based prioritization, and integration into development sprints — ensuring findings are remediated by development teams, not just reported by security
  • Lead red team coordination and penetration testing engagements, translating findings into architectural improvements and developer education, not just remediation tickets

Culture, Enablement & Continuous Improvement

  • Champion a DevSecOps culture of shared security responsibility across development, operations, and security teams, breaking down silos and fostering collaboration through training, enablement, and embedded security practices
  • Develop and deliver security training programs, workshops, secure coding guidelines, and self-service tooling that empower developers to build securely and independently — without requiring security team involvement for every decision
  • Establish DevSecOps metrics and KPIs (mean time to remediate, vulnerability escape rate, pipeline security coverage, compliance drift, developer security adoption) to measure program effectiveness and drive continuous improvement
  • Research, prototype, and evaluate emerging DevSecOps capabilities, including AI-powered security testing, LLM/generative AI security controls, and intelligent vulnerability prioritization, piloting innovations that deliver measurable security outcomes
  • Mentor and provide technical guidance to security engineers, developers, and operations staff, raising the security proficiency and awareness of the broader technology organization
  • Stay at the forefront of DevSecOps, application security, cloud-native security, and AI-powered security testing trends, continuously identifying opportunities to adopt emerging technologies and practices for competitive advantage

Qualifications & Experience

  • 8–10+ years of combined experience in cybersecurity, software engineering, DevOps/platform engineering, or cloud architecture, with at least 4+ years focused on DevSecOps, application security, or security engineering in enterprise environments
  • Demonstrated success designing and implementing enterprise DevSecOps programs, including secure CI/CD pipelines, automated security testing, and policy-as-code frameworks at scale
  • hands-on experience with Python, Go, PowerShell, or similar languages, with the ability to build custom security tooling, pipeline integrations, and automation frameworks from scratch Strong software development proficiency,
  • hands-on experience architecting and securing workloads in IaaS, PaaS, serverless, and containerized (Docker, Kubernetes) environments on Azure and/or AWS across Linux and Windows Deep infrastructure expertise
  • Extensive experience with CI/CD platforms (GitHub Actions, Azure DevOps, GitLab CI, Jenkins) and infrastructure-as-code tools (Terraform, Ansible, ARM/Bicep, CloudFormation)
  • Strong working knowledge of application security testing tools and practices: SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection, and the vulnerability management lifecycle end-to-end
  • Deep understanding of cloud security architecture, zero-trust principles, identity and access management, network security, and data protection across hybrid and multi-cloud environments
  • Experience with secure software supply chain practices: SBOM, artifact signing, dependency governance, and third-party risk management
  • Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required
  • Relevant certifications preferred: CISSP, CISM, CSSLP, GWEB, Microsoft SC-series, Azure Solutions Architect/DevOps Engineer, AWS Security Specialty/DevOps Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent

Professional Skills

  • Translate complex security requirements into practical, developer-friendly architectures, tooling, and automated controls that integrate seamlessly into existing development and operations workflows, without creating friction
  • Operate as a hands-on technical leader who architects solutions and personally writes, reviews, and ships high-quality code and automation, not a delegator or reviewer only
  • Influence and drive cultural change across engineering and operations organizations, building trust, credibility, and shared ownership of security outcomes without relying on authority
  • Collaborate effectively across cross-functional teams, bridging cybersecurity, software development, DevOps, cloud engineering, compliance, and business stakeholders to deliver integrated, secure delivery capabilities
  • Communicate complex technical and security concepts clearly to both technical and non-technical audiences, including executive presentations, architecture reviews, and developer-facing documentation
  • Thrive in an Agile, fast-paced environment that values innovation, rapid iteration, and measurable security outcomes over process and bureaucracy
  • Demonstrate a passion for shifting security left, empowering developers and building a resilient, secure-by-default engineering culture that protects the enterprise while enabling speed and innovation

Skills Required

  • 8-10+ years of combined experience in cybersecurity, software engineering, DevOps/platform engineering, or cloud architecture, including at least 4+ years focused on DevSecOps, application security, or security engineering in enterprise environments
  • Experience designing and implementing enterprise DevSecOps programs, secure CI/CD pipelines, automated security testing, and policy-as-code frameworks at scale
  • Hands-on Python, Go, PowerShell, or similar programming experience for building custom security tooling, pipeline integrations, and automation frameworks
  • Experience architecting and securing IaaS, PaaS, serverless, and containerized environments on Azure and/or AWS across Linux and Windows
  • Extensive experience with GitHub Actions, Azure DevOps, GitLab CI, Jenkins, Terraform, Ansible, ARM/Bicep, and CloudFormation
  • Strong knowledge of SAST, DAST, SCA, container scanning, IaC scanning, secrets detection, and end-to-end vulnerability management
  • Deep understanding of cloud security architecture, zero-trust principles, IAM, network security, and data protection across hybrid and multi-cloud environments
  • Experience with SBOM, artifact signing, dependency governance, and third-party risk management
  • Familiarity with PCI-DSS, SOX, tribal gaming regulations, and GLBA
  • Relevant certifications such as CISSP, CISM, CSSLP, GWEB, Microsoft SC-series, Azure Solutions Architect or DevOps Engineer, AWS Security Specialty or DevOps Engineer, or CKS

Seminole Hard Rock Entertainment, Inc. Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Seminole Hard Rock Entertainment, Inc. and has not been reviewed or approved by Seminole Hard Rock Entertainment, Inc..

  • Pay Growth & Progression The company implemented substantial wage increases across many job classifications and highlights periodic raises tied to evaluations. Feedback suggests these structural pay actions have lifted base rates for a broad segment of roles.
  • Healthcare Strength Competitive medical, dental, and vision coverage is paired with wellness programs and tax-advantaged accounts to support team members and their families. These offerings indicate a focus on health and wellbeing beyond basic coverage.
  • Wellbeing & Lifestyle Benefits Free shift meals, broad brand discounts, tuition reimbursement, and development programs expand total rewards beyond base pay. Weekly pay, recognition efforts, and commuter assistance at many sites further bolster everyday value.

Seminole Hard Rock Entertainment, Inc. Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
20,000 Employees
Year Founded: 2004

What We Do

Seminole Hard Rock Entertainment, Inc. is a global leader in the gaming and hospitality industry, owning and operating a portfolio of luxury casino hotels and entertainment venues. The company provides a wide array of services, including world-class gambling, upscale lodging, fine dining, and premier convention spaces, focusing on delivering extraordinary guest experiences through its diverse locations and the iconic Hard Rock brand.

Similar Jobs

The Aerospace Corporation Logo The Aerospace Corporation

Architect

Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Hybrid
Phoenix, AZ, USA
4600 Employees

Chewy Logo Chewy

Veterinary Technician III

eCommerce • Healthtech • Pet • Retail • Pharmaceutical
Hybrid
Chandler, AZ, USA
17800 Employees

Samsara Logo Samsara

Third-Party Risk Management Analyst

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
111K-167K Annually

The Aerospace Corporation Logo The Aerospace Corporation

Data Engineer

Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Hybrid
Phoenix, AZ, USA
4600 Employees

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Fairly Even Thumbnail
Hardware • Robotics • Sales • Software • Hospitality
New York, NY
30 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account