Security AI DevSecOps Engineer

Regional FinancePlano, TexasHybridFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

Take your career to the next level! In the last few years our goal has been expansion, creating growth opportunities for many of our team members. Not only are we serious about growth, but we are also serious about helping our customers during hard financial times.

We take pride in providing solutions and offering a helping hand, not only to our customers but also to the communities we serve. As we continue to expand and grow into a national leader in consumer financing, we invite you to consider joining our team.

If you're passionate about making a meaningful impact in people's lives and bringing a personal touch to finance, we'd love to have you on board!

Job Purpose

The AI Security DevSecOps Engineer is a specialized individual contributor role at the intersection of DevSecOps, AI/ML security, and internal AI development. This person will embed with development teams across the organization to secure CI/CD pipelines and AI development lifecycles end-to-end. In addition to securing how software and AI systems are built and deployed, this engineer will serve as our internal AI developer — designing, building, and orchestrating AI agents that transform how the Security team operates. The ideal candidate is equally comfortable writing a pipeline security gate and building an LLM-powered automation workflow.

Duties and Responsibilities

CI/CD & Pipeline Security

- Design and implement security controls across CI/CD platforms (e.g., GitHub Actions, GitLab CI, Jenkins, Azure DevOps), including SAST, DAST, SCA, container image scanning, and secrets detection.
- Develop and maintain policy-as-code enforcement using tools such as Open Policy Agent (OPA), Sentinel, or Kyverno to automate security guardrails at pipeline stages.
- Establish and govern infrastructure-as-code (IaC) security reviews using tools such as Checkov, tfsec, or Bridgecrew across Terraform and CloudFormation environments.
- Lead software supply chain security initiatives including SBOM generation (Syft, Grype, etc), artifact signing (Sigstore/Cosign, etc), and dependency governance.
- Implement code security standards and report on compliance to such standards
- Ensure API security is effective and consistent with best practices

AI/ML Security

- Partner with AI/ML engineering teams to perform threat modeling of LLM-powered applications, model training pipelines, and inference serving layers.
- Implement controls aligned to OWASP LLM Top 10 and MITRE ATLAS, including defenses against prompt injection, data exfiltration, model inversion, and adversarial inputs.
- Secure MLOps workflows including model registries, dataset pipelines, and deployment platforms (e.g., MLflow, Kubeflow, SageMaker).
- Evaluate and advise on AI vendor security posture, third-party model integrations, and emerging AI supply chain risks.

Internal AI Development & Agent Orchestration

- Design, build, and maintain internal AI agents and automation workflows that accelerate Security team operations — including alert triage, vulnerability enrichment, threat intelligence correlation, compliance evidence collection, and reporting.
- Leverage LLM APIs (e.g., Anthropic Claude, OpenAI) and orchestration frameworks (e.g., LangChain, LlamaIndex) to build reliable, guardrailed agentic systems.
- Establish best practices for responsible internal AI development, including prompt governance, output validation, and audit logging of agent actions.
- Identify and prioritize automation opportunities across the Security team, translating manual workflows into AI-assisted or fully automated pipelines.

Developer Partnership & Security Enablement

- Serve as a trusted security partner — not a gatekeeper — embedded with development teams to champion secure-by-default patterns and reduce friction in the SDLC.
- Design and deliver paved-road security templates, reusable pipeline components, and developer-facing runbooks that make the secure path the easy path.
- Facilitate threat modeling workshops and security design reviews for new products, services, and AI initiatives.
- Communicate security risks and recommendations effectively to both technical engineers and non-technical stakeholders.

Cloud & Secrets Management

- Partner with Development and Cloud teams to enhance secrets management strategy using tools such as HashiCorp Vault or AWS Secrets Manager, enforcing least-privilege access patterns.
- Monitor and improve cloud security posture (AWS, Azure, or GCP) including network security and container/Kubernetes hardening.
- Support incident response activities including those related to CI/CD, cloud, or AI-specific threats.

Metrics & Reporting

- Define and monitor key security metrics across pipeline security coverage, and AI agent operational health.
- Provide regular reporting on DevSecOps program maturity, AI security posture, and automation impact to security leadership.

Minimum Qualifications

Education & Experience

- Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field.
- 4–7 years of security engineering experience, with meaningful tenure in AppSec, DevSecOps, cloud security, or a closely related role.
- Demonstrated hands-on experience securing CI/CD pipelines using modern tooling (Snyk, Semgrep, Checkmarx, Trivy, Checkov, or comparable).
- Strong Python or similar scripting proficiency — this role builds tools, not just configures them.
- Working knowledge of LLM security risks including prompt injection, jailbreaking, model inversion, data poisoning, and AI supply chain threats.
- Experience building with LLM APIs or AI orchestration frameworks (LangChain, LlamaIndex, or similar).
- Cloud security proficiency in AWS, Azure, or GCP covering IAM, network security, secrets management, and container/Kubernetes hardening.
- Demonstrated ability to collaborate cross-functionally with engineering teams and translate security concepts for non-security audiences.

Preferred Qualifications

Education & Experience

- Master’s degree in Computer Science, Information Security, or a related field.
- Experience with MLOps platforms and securing model registries and training pipelines.
- Background in agentic AI architectures including multi-agent orchestration, tool use, memory management, and guardrail design.
- Experience with SIEM/SOAR platforms (Splunk, Exabeam, Tines, Torq, or similar) and security data pipelines.

Preferred Certifications

- Certified Information Systems Security Professional (CISSP)
- Offensive Security Certified Professional (OSCP) or Offensive Security Web Expert (OSWE)
- AWS Certified Security – Specialty or equivalent cloud security certification
- Certified AI Security Professional (CAISP) or comparable emerging AI security credential
- Certified DevSecOps Professional (CDP) or Certified DevSecOps Expert (CDE)

Critical Competencies

- Deep knowledge of DevSecOps principles, secure SDLC practices, and CI/CD security tooling.
- Strong understanding of AI/ML threat landscapes including OWASP LLM Top 10, MITRE ATLAS, and emerging attack vectors against AI systems.
- Ability to design, build, and operate AI agents and automation workflows in a production security context.
- Excellent written and oral communication skills with the ability to present to technical and executive audiences.
- Strong project management and organizational skills; able to manage multiple initiatives in a fast-paced, collaborative environment.
- Ability to work both collaboratively and independently, and to influence without direct authority.
- Intellectual curiosity and a growth mindset — the AI security landscape evolves rapidly and this role demands continuous learning.

Working Conditions

Hybrid work is permitted for this position. Regional has offices in Greenville, SC and Plano, TX available for in-person work. Some travel may be required (less than 10%).

#LI-hybrid

Regional is an equal opportunity employer and does not discriminate on the basis of race, color, religion, creed, national origin, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity, transgender status, age, disability, genetic information, veteran status, uniform service, or any other characteristic protected by applicable law (“Protected Characteristics”). Regional’s policy of non-discrimination applies to all phases of the employment process and relationship, including, but not limited to, recruitment and selection; compensation and benefits; professional development and training; promotions and opportunities; transfers; social and recreational programs; layoff; and terminations.