Anticipated End Date:2026-06-26
Position Title:AI DevSecOps Senior Engineer
Job Description:AI DevSecOps Senior EngineerLocations: This role requires associates to be in-office
1-2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered if candidates reside within a commuting distance from an office
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
PLEASE NOTE: This position is not eligible for current or future VISA sponsorship.
The
AI DevSecOps Senior Engineer develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support information security in compliance with established company policies, regulatory requirements, and generally accepted information security controls. You will lead the design and integration of DevSecOps, Application Security and Vulnerability Management capabilities across our enterprise. This individual contributor role will drive secure-by-design practices across CI/CD pipelines, cloud-native platforms, and modern development workflows-including AI-assisted coding environments. You will partner closely with application engineering, cloud, and platform teams to embed scalable, automated security controls that reduce risk while enabling developer velocity.
How you will make an Impact:- Lead the design and implementation of DevSecOps solutions integrated into CI/CD pipelines (GitHub, GitLab, Jenkins)
- Define and implement secure SDLC practices, including automated testing, threat modeling, and secure coding standards
- Own and optimize CNAPP platforms (e.g., Wiz, Prisma Cloud) to improve cloud security posture and workload protection
- Drive vulnerability management strategy, including risk-based prioritization and integration into developer workflows
- Integrate and tune AppSec tools (SAST, DAST, SCA, container scanning) for scalable pipeline adoption
- Establish guardrails for AI-generated code security, including validation of outputs and mitigation of risks such as insecure code patterns and data exposure
- Embed security controls into AI-enabled applications and APIs, addressing emerging risks (e.g., prompt injection, model misuse)
- Partner with engineering teams to reduce vulnerability backlog and MTTR
- Define KPIs and reporting for security posture, pipeline coverage, and risk reduction
- Serve as a technical advisor and escalation point for complex security and integration challenges
- Leads system and network architecture support for information and network security technologies;
- Leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations;
- Leads the development of requirements, system architecture, and software design of security products and services;
- Develops security incident response plans and strategies.
- Provides trouble resolution and serves as point of technical escalation on complex problems.
- Creates presentations and seeks IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the Enterprise. Sets vendor strategy and direction.
Minimum Requirements:Requires BS/BA in information Technology or related field of study and a minimum of 8 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; requires broad-based experience to plan and design highly complex systems; or any combination of education and experience, which would provide an equivalent background.
Preferred Skills, Experiences and Competencies:- Experience in DevSecOps, Application Security, Cloud Security, or related fields
- Hands-on experience integrating security into CI/CD pipelines at scale
- Experience with CNAPP platforms (e.g., Wiz, Prisma Cloud)
- Strong knowledge of: Application Security (SAST, DAST, SCA, API security)Cloud Security (AWS, Azure, or GCP)Containers & Kubernetes security
- Vulnerability management and risk prioritization
- Experience with automation, scripting, and infrastructure-as-code (IaC)
- Experience securing AI/LLM-enabled applications or AI-assisted development workflows
- Familiarity with AI security risks (e.g., OWASP Top 10 for LLMs, prompt injection, data leakage)
- Experience with tools such as Snyk, Checkmarx, Veracode, SonarQube
- Strong understanding of DevOps and Agile practices
- Security certifications (e.g., CISSP, CCSP, CSSLP) preferred
Job Level:Non-Management Exempt
Workshift:1st Shift (United States of America)
Job Family:IFT > IT Security & Compliance
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
NOTE: Workday keeps job postings active through 11:59:59 PM on the day before the listed end date. Example: If the end date is 3/13, the posting will automatically come down on 3/12 at 11:59:59 PM. In other words - the job is posted until 3/13, not through 3/13.