Point your AI agent at freehire and let it find you a job.

Get the CLI →

Penn Engineering

New

Principal Development Security Ops Architect-25121

Posted Updated
Discussion

As PennEngineering accelerates its Speed of Now transformation (respond in 1 hour, quote in 1 day, samples in 1 week, finished product in 1 month), we are rapidly expanding our cloud-native, AI-powered application portfolio. Delivering at this pace demands that security is not a checkpoint at the end of development, but an engineered capability embedded into every layer of how we build and deploy software.

The Principal DevSecOps Architect is responsible for managing the enterprise security architecture and DevSecOps strategy that enables PennEngineering's engineering teams to ship code safely at high velocity. This is a hands-on senior technical leadership role: part strategist, part architect, part builder, serving as PennEngineering’s technical authority on DevSecOps and cloud security. You will own the security posture of our global AWS cloud environment and customer-facing platforms, automate the guardrails that protect organizational assets, and ensure that our CI/CD pipelines enforce security by design, without creating friction that slows our teams down. You will set multi-year technical direction, advise senior leadership on security risk and investment priorities, and raise the technical bar across the engineering organization.

As PennEngineering's AI application portfolio grows, including AI-powered workflows, agentic systems, and customer-facing digital platforms, this role will play a critical part in establishing the security architecture and governance that allow those systems to operate reliably, safely, and at enterprise scale.

Enterprise Strategy & Technical Leadership

  • Owns the DevSecOps strategy and multi-year security architecture roadmap, aligning security investment with PennEngineering’s risk posture, compliance obligations, and Speed of Now objectives
  • Serve as the highest a technical authority and escalation point for cloud security architecture decisions; attend security design reviews and define the reference cloud security architecture.
  • Advise leadership on emerging threats, security investment priorities, and technology selection; present risk posture and roadmap updates to stakeholders
  • Provide technical leadership and mentorship to senior engineers and architects across the security and platform organizations; set the technical bar for hiring and help develop security engineering talent

Cloud Security Posture & Remediation

  • Continuously assess, harden, and elevate the security posture of PennEngineering's AWS cloud infrastructure, covering both customer-facing platforms and internal enterprise systems
  • Design and build custom security tools, frameworks, and policies tailored to protect PennEngineering's internal and external organizational assets
  • Own the end-to-end vulnerability management lifecycle, including triage, tracking, prioritization, and automated remediation of identified vulnerabilities and cloud misconfigurations
  • Establish a continuous posture improvement program with defined baselines, remediation SLAs, and executive-level reporting on security health

Pipeline Security & CI/CD Integration

  • Architect and implement automated security scanning (SAST, SCA, and DAST), embedded directly into CI/CD pipelines, ensuring checks are high-fidelity and low-latency to support our daily deployment cadence
  • Configure pre-commit hooks, pull request checks, and branch protection rules that automatically detect and block secrets, misconfigurations, or vulnerable dependencies before they reach production
  • Partner with AI engineering teams to secure AI/LLM workloads within the pipeline, including prompt injection protections, model input/output validation, and agentic system guardrails
  • Establish security gate standards and developer-friendly documentation so engineering teams understand what is enforced, why, and how to resolve failures quickly

Automated Governance & Policy-as-Code

  • Replace manual security audits with automated policy enforcement using infrastructure-as-code tools (Terraform, AWS Config), ensuring non-compliant infrastructure cannot be provisioned
  • Build event-driven automation to detect and auto-remediate common security issues in near real-time, reducing mean time to respond across the environment
  • Define, own, and enforce enterprise-wide cloud security governance standards, including access controls, secrets management, encryption policies, and data classification frameworks
  • Establish audit-ready documentation and evidence collection practices to support internal compliance reviews and external assessments

Cloud Operations & Threat Response

  • Maintain the operational security health of PennEngineering's AWS environment, using automation to manage scaling events, configuration drift, and self-healing infrastructure
  • Operationalize CrowdStrike and Zscaler telemetry by automating the correlation of security alerts to reduce noise and trigger rapid, automated response workflows
  • Define and own security incident response playbooks; lead root-cause analysis and post-incident reviews to drive systemic improvements
  • Collaborate with IS, infrastructure, and AI engineering teams to ensure threat response practices are integrated across the full technology stack

Security Architecture for AI & Emerging Platforms

  • Define the security architecture for PennEngineering's AI-powered application portfolio, including data access controls, model governance, prompt safety, and auditability for agentic systems
  • Evaluate and advise on security posture for new platforms, tools, and third-party integrations as the technology portfolio evolves
  • Partner with the Principal Systems Architect and AI engineering teams to embed security requirements into solution designs from the earliest stages
  • Stay current on emerging threats relevant to AI systems, cloud-native architectures, and manufacturing/industrial environments, and translate findings into actionable architectural guidance

Key KPIs

  • Vulnerability remediation SLA compliance: % of identified vulnerabilities resolved within defined timeframes by severity tier
  • Pipeline security gate effectiveness: % of CI/CD pipelines with automated security scanning enabled; false-positive rate maintained below threshold to avoid developer friction
  • Mean time to detect and respond (MTTD / MTTR) for security incidents across the cloud environment
  • Policy-as-code coverage: % of infrastructure provisioned through automated, policy-enforced pipelines vs. manual processes
  • Cloud security posture score: continuous improvement trend against defined baseline using AWS Security Hub or equivalent
  • AI workload security coverage: % of AI-powered applications and agentic systems operating under defined security architecture standards

What does success look like?

Success in this role means PennEngineering's engineering teams ship code at high velocity with confidence, knowing that automated security guardrails are working in the background, not slowing them down. Security findings are caught earlier in the development cycle, remediated faster, and tracked with full visibility. Our AWS environment maintains a continuously improving posture, and our AI-powered platforms operate under clear, auditable security architecture.

The Principal DevSecOps Architect is successful when security is a competitive enabler for PennEngineering's Speed of Now transformation, not a constraint on it. You are proactive, automation-first, and deeply collaborative. You build relationships with engineering and product teams by making security easy to do correctly, and you bring the same data-driven discipline to security operations that our engineering teams bring to delivery.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available