Senior DevSecOps Engineer
Core
Secure the resilience, integrity, and performance of the Arbor platform (AI-enabled systems and developer tooling) by combining deep security engineering with a secure-by-design mindset.
Role type
Senior DevSecOps Engineer
Builds
AI-enabled school management tools and platform infrastructure for 12,000+ schools
Domain
EdTech / Cloud Security / AI Security
Deliverable
production ML models | infrastructure
Required skills
Vulnerability management, DevSecOps engineering, distributed cloud systems (AWS), Infrastructure as Code (Terraform, CloudFormation), container security (Docker), software supply-chain security (SBOM, SLSA, Sigstore), secrets management, security tooling (SAST, DAST, SCA, IaC scanning), policy-as-code (OPA/Conftest), AI/LLM security (prompt injection, jailbreaks, data leakage), AI threat modelling (MITRE ATLAS), AI governance frameworks (NIST AI RMF, ISO/IEC 42001)
Preferred skills
Enterprise scale experience, Agile/Kanban, Clean Code, compliance frameworks (NIST CSF, ISO 27001, SOC 2, UK GDPR), certifications (AWS Security Specialty, OSCP)
Technologies
AWS, Terraform, CloudFormation, PHP, Bash, Python, Docker, Vault, DataDog, Prometheus, Snyk, Trivy, OPA, Conftest
Responsibilities
Pinpoint security enhancements across platform architecture, embed robust security processes and tooling, threat model new and existing systems (including AI/LLM features), strengthen software supply chain, secure AI usage across SDLC, evolve deployment frameworks, manage secrets, participate in incident response, maintain documentation
Seniority
Senior, hands-on IC