{"id":2184364,"url":"https://alion.io/job/inspyr-solutions-website-devsecops-architect","title":"DevSecOps Architect","company":{"id":3872763,"name":"INSPYR Solutions","domain":"inspyrsolutions.com","url":"https://alion.io/company/inspyr-solutions","size_band":null,"is_staffing_agency":true,"employer_type":"agency","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":{"grade":"B","score":75,"open_postings":127,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":26,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":["Hollywood, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":180000,"max":185000,"currency":"USD","period":"year","gross":null,"usd_annual":185000},"salary_estimate":null,"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Ansible","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Azure DevOps","optional":false},{"name":"Bicep","optional":false},{"name":"CI/CD","optional":false},{"name":"CloudFormation","optional":false},{"name":"Docker","optional":false},{"name":"GCP","optional":false},{"name":"GitHub Actions","optional":false},{"name":"GitLab CI","optional":false},{"name":"Go","optional":false},{"name":"IAM","optional":false},{"name":"Jenkins","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"PCI DSS","optional":false},{"name":"Platform Engineering","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"SBOM","optional":false},{"name":"Shift-Left","optional":false},{"name":"Shift-Left Security","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Windows","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-09-17T00:00:00Z","employer_posted_date":"2026-10-09","last_verified_at":"2026-10-10T23:38:38Z","board_verified":true,"closed_at":null,"days_open":24,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":24},"description":"Title: DevSecOps Architect\nLocation: Hollywood- onsite (flex 1 day remote) \nDuration: Direct Hire\nCompensation: $ 180,000- $185,000\nWork Requirements: U.S. Citizen, GC Holders, or Authorized to Work in the U.S.\nDevSecOps Architect\nAs the DevSecOps Architect, you will define, build, and champion the integration of security into every stage of the Secure Software Development Lifecycle (S-SDLC), embedding automated security controls, governance, and compliance into CI/CD pipelines, cloud infrastructure, and application delivery processes across the enterprise.\nReporting to the Director II of Cybersecurity Architecture, Engineering & IAM, this role requires a deeply technical, security-minded architect and engineer who bridges the worlds of software development, cloud operations, and cybersecurity. You will design and implement secure-by-default development frameworks, automate security testing and compliance enforcement, and drive a cultural shift toward shared security ownership, ensuring that every application and infrastructure deployment across all Rock business units is built secure from the ground up.\nThis is a shift-left architecture role. The ideal candidate does not sit at the end of the pipeline reviewing what others have built, they embed themselves into the engineering lifecycle, define the standards developers work within, and build the tooling and automation that makes security the path of least resistance. You architect at scale, write production-grade code, and measure your impact in vulnerabilities prevented, not just discovered.\nResponsibilities\nSecurity Architecture & Secure SDLC\nDesign and implement an enterprise DevSecOps architecture that embeds security controls, automated testing, and compliance validation into every phase of the software development lifecycle, from code commit through production deployment\nDefine and maintain secure coding standards, application security reference architectures, and security design patterns that development teams adopt as foundational building blocks, not optional guidelines\nArchitect threat modeling frameworks and processes that enable development teams to proactively identify and mitigate security risks during design and development phases, before code is written\nEstablish and govern security gate criteria within CI/CD pipelines, ensuring that code, container images, infrastructure-as-code templates, and third-party dependencies meet security and compliance thresholds before promotion to production\nOwn the security architecture review process for new applications, platforms, and major system changes, providing timely, actionable guidance that accelerates delivery rather than blocking it\nPipeline Engineering & Automation\nDesign, build, and maintain secure CI/CD pipelines integrating automated security tooling across the full spectrum: static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container scanning, infrastructure-as-code (IaC) scanning, and secrets detection\nDevelop and maintain custom pipeline integrations, security automation scripts, and policy-as-code frameworks using Python, PowerShell, Go, or similar languages, enforcing security controls programmatically at scale\nImplement automated compliance-as-code solutions that continuously validate infrastructure and application configurations against regulatory requirements (PCI-DSS, SOX, tribal gaming regulations) and internal security policies, eliminating manual evidence collection\nEngineer automated remediation workflows that detect, alert, and resolve common security misconfigurations and vulnerabilities without manual intervention, reducing mean time to remediate across the portfolio\nBuild developer-facing security tooling and integrations that surface security findings directly within developer workflows (IDE plugins, pull request gates, ticketing integrations), making security feedback immediate and actionable\nCloud & Infrastructure Security\nArchitect and enforce security guardrails across cloud environments (Azure, AWS, Google Cloud), including network segmentation, identity and access policies, encryption standards, logging configurations, and monitoring baselines\nDesign and implement secure infrastructure-as-code (Terraform, Ansible, ARM/Bicep, CloudFormation) templates and modules that serve as hardened, reusable baselines for all cloud and on-premises deployments\nOversee container and Kubernetes security architecture, including image hardening, runtime protection, network policies, secrets management, and admission control policies\nCollaborate with cloud engineering, infrastructure, and platform teams to ensure IaaS, PaaS, and serverless workloads across Linux and Windows environments are deployed and operated in accordance with zero-trust principles and enterprise security standards\nDefine and maintain cloud security posture management (CSPM) standards, continuously monitoring for drift and enforcing guardrails that prevent insecure configurations from reaching production\nApplication Security & Vulnerability Management\nLead the application security program in partnership with development teams - conducting architecture reviews, code reviews, and penetration testing coordination to identify and remediate vulnerabilities before they reach production\nEvaluate, implement, and manage application security tooling across SAST, DAST, SCA, container, and cloud posture domains, ensuring comprehensive, continuous coverage across the full application and infrastructure portfolio\nDrive adoption of secure software supply chain practices, including software bill of materials (SBOM) generation, dependency management, artifact signing, provenance verification, and third-party component vetting\nEstablish a vulnerability management lifecycle with defined SLAs, risk-based prioritization, and integration into development sprints - ensuring findings are remediated by development teams, not just reported by security\nLead red team coordination and penetration testing engagements, translating findings into architectural improvements and developer education, not just remediation tickets\nCulture, Enablement & Continuous Improvement\nChampion a DevSecOps culture of shared security responsibility across development, operations, and security teams, breaking down silos and fostering collaboration through training, enablement, and embedded security practices\nDevelop and deliver security training programs, workshops, secure coding guidelines, and self-service tooling that empower developers to build securely and independently - without requiring security team involvement for every decision\nEstablish DevSecOps metrics and KPIs (mean time to remediate, vulnerability escape rate, pipeline security coverage, compliance drift, developer security adoption) to measure program effectiveness and drive continuous improvement\nResearch, prototype, and evaluate emerging DevSecOps capabilities, including AI-powered security testing, LLM/generative AI security controls, and intelligent vulnerability prioritization, piloting innovations that deliver measurable security outcomes\nMentor and provide technical guidance to security engineers, developers, and operations staff, raising the security proficiency and awareness of the broader technology organization\nStay at the forefront of DevSecOps, application security, cloud-native security, and AI-powered security testing trends, continuously identifying opportunities to adopt emerging technologies and practices for competitive advantage\nQualifications & Experience\n8-10+ years of combined experience in cybersecurity, software engineering, DevOps/platform engineering, or cloud architecture, with at least 4+ years focused on DevSecOps, application security, or security engineering in enterprise environments\nDemonstrated success designing and implementing enterprise DevSecOps programs, including secure CI/CD pipelines, automated security testing, and policy-as-code frameworks at scale\nhands-on experience with Python, Go, PowerShell, or similar languages, with the ability to build custom security tooling, pipeline integrations, and automation frameworks from scratch Strong software development proficiency,\nhands-on experience architecting and securing workloads in IaaS, PaaS, serverless, and containerized (Docker, Kubernetes) environments on Azure and/or AWS across Linux and Windows Deep infrastructure expertise\nExtensive experience with CI/CD platforms (GitHub Actions, Azure DevOps, GitLab CI, Jenkins) and infrastructure-as-code tools (Terraform, Ansible, ARM/Bicep, CloudFormation)\nStrong working knowledge of application security testing tools and practices: SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection, and the vulnerability management lifecycle end-to-end\nDeep understanding of cloud security architecture, zero-trust principles, identity and access management, network security, and data protection across hybrid and multi-cloud environments\nExperience with secure software supply chain practices: SBOM, artifact signing, dependency governance, and third-party risk management\nFamiliarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required\nRelevant certifications preferred: CISSP, CISM, CSSLP, GWEB, Microsoft SC-series, Azure Solutions Architect/DevOps Engineer, AWS Security Specialty/DevOps Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent\nProfessional Skills\nTranslate complex security requirements into practical, developer-friendly architectures, tooling, and automated controls that integrate seamlessly into existing development and operations workflows, without creating friction\nOperate as a hands-on technical leader who architects solutions and personally writes, reviews, and ships high-quality code and automation, not a delegator or reviewer only\nInfluence and drive cultural change\nAbout INSPYR Solutions\nTechnology is our focus and quality is our commitment. As a leading global expert in delivering flexible technology and talent solutions, we strategically align industry and technical expertise with our clients’ business objectives and cultural needs. Our tailored offerings include a wide variety of professional services, project solutions, managed services, and talent resources, all bolstered by our strategic partnerships with cutting-edge technology services. By always striving for excellence and focusing on the human aspect of our business, we work seamlessly with our talent and clients to match the right solutions to the right opportunities. Learn more about us at www.inspyrsolutions.com.\nINSPYR Solutions provides Equal Employment Opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, or any other protected status. INSPYR Solutions complies with all applicable laws governing nondiscrimination in employment in every location in which the company has facilities. Applicants requiring reasonable accommodation during the application or interview process should contact  for assistance.\nInformation collected and processed through your application with INSPYR Solutions (including any job applications you choose to submit) is subject to INSPYR Solutions' Privacy Policy and INSPYR Solutions' AI and Automated Employment Decision Tool Policy: https://www.inspyrsolutions.com/policies/. By submitting an application, you are consenting to being contacted by INSPYR Solutions through phone, email, or text.\n26-159434","description_format":"text","description_chars":11685,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"phd","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps","Artificial Intelligence","Application Security","Industrial AI"],"lifecycle":[{"event":"open","at":"2026-10-09T15:33:46Z"}],"visa":[],"liveness":{"score":23,"band":"cold","label":"Long shot","p_open":1,"p_active":0.303,"p_room":0.75,"age_days":23,"expected_fill_days":26,"reasons":["conf:1","agency","stale_co","velocity","win:late","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":{"stated_usd_annual":185000,"is_top_pay":false},"html_url":"https://alion.io/job/inspyr-solutions-website-devsecops-architect","json_url":"https://alion.io/job/inspyr-solutions-website-devsecops-architect.json","meta":{"generated_at":"2026-10-11T07:33:28Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"assistant_verified","counted_by":"address","units_charged":1,"used_today":1646,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3872763},"rest":"https://alion.io/mcp/rest/get_company?id=3872763"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Finspyr-solutions-website-devsecops-architect"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Finspyr-solutions-website-devsecops-architect"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Finspyr-solutions-website-devsecops-architect"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/inspyr-solutions-website-devsecops-architect\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Finspyr-solutions-website-devsecops-architect"}]}