DevSecOps Architect
Hard Rock International
Our team members are the key to our company’s success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site:
Job Description:
At Seminole Hard Rock Support Services, we are on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. As the DevSecOps Architect, you will define, build, and champion the integration of security into every stage of the Secure Software Development Lifecycle (S-SDLC), embedding automated security controls, governance, and compliance into CI/CD pipelines, cloud infrastructure, and application delivery processes across the enterprise. Reporting to the Director II of Cybersecurity Architecture, Engineering & IAM, this role requires a deeply technical, security-minded architect and engineer who bridges the worlds of software development, cloud operations, and cybersecurity. You will design and implement secure-by-default development frameworks, automate security testing and compliance enforcement, and drive a cultural shift toward shared security ownership, ensuring that every application and infrastructure deployment across all Seminole Hard Rock business units is built secure from the ground up. This is a shift-left architecture role. The ideal candidate does not sit at the end of the pipeline reviewing what others have built, they embed themselves into the engineering lifecycle, define the standards developers work within, and build the tooling and automation that makes security the path of least resistance. You architect at scale, write production-grade code, and measure your impact in vulnerabilities prevented, not just discovered.
Responsibilities
- Security Architecture & Secure SDLC Design and implement an enterprise DevSecOps architecture that embeds security controls, automated testing, and compliance validation into every phase of the software development lifecycle, from code commit through production deployment
- Define and maintain secure coding standards, application security reference architectures, and security design patterns that development teams adopt as foundational building blocks, not optional guidelines
- Architect threat modeling frameworks and processes that enable development teams to proactively identify and mitigate security risks during design and development phases, before code is written
- Establish and govern security gate criteria within CI/CD pipelines, ensuring that code, container images, infrastructure-as-code templates, and third-party dependencies meet security and compliance thresholds before promotion to production
- Own the security architecture review process for new applications, platforms, and major system changes, providing timely, actionable guidance that accelerates delivery rather than blocking it
- Pipeline Engineering & Automation Design, build, and maintain secure CI/CD pipelines integrating automated security tooling across the full spectrum: static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container scanning, infrastructure-as-code (IaC) scanning, and secrets detection
- Develop and maintain custom pipeline integrations, security automation scripts, and policy-as-code frameworks using Python, PowerShell, Go, or similar languages, enforcing security controls programmatically at scale
- Implement automated compliance-as-code solutions that continuously validate infrastructure and application configurations against regulatory requirements (PCI-DSS, SOX, tribal gaming regulations) and internal security policies, eliminating manual evidence collection
- Engineer automated remediation workflows that detect, alert, and resolve common security misconfigurations and vulnerabilities without manual intervention, reducing mean time to remediate across the portfolio
- Build developer-facing security tooling and integrations that surface security findings directly within developer workflows (IDE plugins, pull request gates, ticketing integrations), making security feedback immediate and actionable
- Cloud & Infrastructure Security Architect and enforce security guardrails across cloud environments (Azure, AWS, Google Cloud), including network segmentation, identity and access policies, encryption standards, logging configurations, and monitoring baselines
- Design and implement secure infrastructure-as-code (Terraform, Ansible, ARM/Bicep, CloudFormation) templates and modules that serve as hardened, reusable baselines for all cloud and on-premises deployments
- Oversee container and Kubernetes security architecture, including image hardening, runtime protection, network policies, secrets management, and admission control policies
- Collaborate with cloud engineering, infrastructure, and platform teams to ensure IaaS, PaaS, and serverless workloads across Linux and Windows environments are deployed and operated in accordance with zero-trust principles and enterprise security standards
- Define and maintain cloud security posture management (CSPM) standards, continuously monitoring for drift and enforcing guardrails that prevent insecure configurations from reaching production
- Application Security & Vulnerability Management Lead the application security program in partnership with development teams — conducting architecture reviews, code reviews, and penetration testing coordination to identify and remediate vulnerabilities before they reach production
- Evaluate, implement, and manage application security tooling across SAST, DAST, SCA, container, and cloud posture domains, ensuring comprehensive, continuous coverage across the full application and infrastructure portfolio
- Drive adoption of secure software supply chain practices, including software bill of materials (SBOM) generation, dependency management, artifact signing, provenance verification, and third-party component vetting
- Establish a vulnerability management lifecycle with defined SLAs, risk-based prioritization, and integration into development sprints — ensuring findings are remediated by development teams, not just reported by security
- Lead red team coordination and penetration testing engagements, translating findings into architectural improvements and developer education, not just remediation tickets
- Culture, Enablement & Continuous Improvement Champion a DevSecOps culture of shared security responsibility across development, operations, and security teams, breaking down silos and fostering collaboration through training, enablement, and embedded security practices
- Develop and deliver security training programs, workshops, secure coding guidelines, and self-service tooling that empower developers to build securely and independently — without requiring security team involvement for every decision
- Establish DevSecOps metrics and KPIs (mean time to remediate, vulnerability escape rate, pipeline security coverage, compliance drift, developer security adoption) to measure program effectiveness and drive continuous improvement
- Research, prototype, and evaluate emerging DevSecOps capabilities, including AI-powered security testing, LLM/generative AI security controls, and intelligent vulnerability prioritization, piloting innovations that deliver measurable security outcomes
- Mentor and provide technical guidance to security engineers, developers, and operations staff, raising the security proficiency and awareness of the broader technology organization
- Stay at the forefront of DevSecOps, application security, cloud-native security, and AI-powered security testing trends, continuously identifying opportunities to adopt emerging technologies and practices for competitive advantage
Qualifications & Experience
8–10+ years of combined experience in cybersecurity, software engineering, DevOps/platform engineering, or cloud architecture, with at least 4+ years focused on DevSecOps, application security, or security engineering in enterprise environments Demonstrated success designing and implementing enterprise DevSecOps programs, including secure CI/CD pipelines, automated security testing, and policy-as-code frameworks at scale hands-on experience with Python, Go, PowerShell, or similar languages, with the ability to build custom security tooling, pipeline integrations, and automation frameworks from scratch Strong software development proficiency, hands-on experience architecting and securing workloads in IaaS, PaaS, serverless, and containerized (Docker, Kubernetes) environments on Azure and/or AWS across Linux and Windows Deep infrastructure expertise Extensive experience with CI/CD platforms (GitHub Actions, Azure DevOps, GitLab CI, Jenkins) and infrastructure-as-code tools (Terraform, Ansible, ARM/Bicep, CloudFormation) Strong working knowledge of application security testing tools and practices: SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection, and the vulnerability management lifecycle end-to-end Deep understanding of cloud security architecture, zero-trust principles, identity and access management, network security, and data protection across hybrid and multi-cloud environments Experience with secure software supply chain practices: SBOM, artifact signing, dependency governance, and third-party risk management Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required Relevant certifications preferred: CISSP, CISM, CSSLP, GWEB, Microsoft SC-series, Azure Solutions Architect/DevOps Engineer, AWS Security Specialty/DevOps Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent
Professional Skills
Translate complex security requirements into practical, developer-friendly architectures, tooling, and automated controls that integrate seamlessly into existing development and operations workflows, without creating friction Operate as a hands-on technical leader who architects solutions and personally writes, reviews, and ships high-quality code and automation, not a delegator or reviewer only Influence and drive cultural change across engineering and operations organizations, building trust, credibility, and shared ownership of security outcomes without relying on authority Collaborate effectively across cross-functional teams, bridging cybersecurity, software development, DevOps, cloud engineering, compliance, and business stakeholders to deliver integrated, secure delivery capabilities Communicate complex technical and security concepts clearly to both technical and non-technical audiences, including executive presentations, architecture reviews, and developer-facing documentation Thrive in an Agile, fast-paced environment that values innovation, rapid iteration, and measurable security outcomes over process and bureaucracy Demonstrate a passion for shifting security left, empowering developers and building a resilient, secure-by-default engineering culture that protects the enterprise while enabling speed and innovation
Thank you for choosing us as your employer of choice! If you are ready for an exciting opportunity working in a creative environment where you can bring your authentic self to work, we want to connect with you! If you're unable to find a position that matches your interest, please tell us a little about yourself, and we'll recommend jobs that match your interests. Be Iconic represents the roots of our culture. The Seminole Tribe of Florida remains the only unconquered tribe in the United States of America. The Tribe established Seminole Gaming in 1979, when it opened the first high-stakes bingo hall in the United States. Building on its rich heritage of courageous and groundbreaking achievements, the Seminole Tribe of Florida acquired Hard Rock International in March 2007—the first transaction of its kind by a Native American tribe. Today, Hard Rock International remains one of the most globally recognized companies in the world, with Hard Rock Hotel, Casino, Cafe and Rock Shop® venues in over 74 countries. With the continued growth of Seminole Gaming and Hard Rock International, Seminole Hard Rock Support Services was created to support all of our brands and lines of business. With the largest global footprint in the hospitality industry for over 50 years, our number-one job is to bring fun and excitement to our team members and our guests!
#J-18808-Ljbffr$240k - $265k
...Title: Principal Architect Location: New York, Boston, DC, Chicago and Toronto The Performance Transformation practice within... ...data management, and modern data platforms. Experience with DevSecOps, build and release management, and SDLC maturity models. Familiarity...SuggestedMinimum wageWork at officeLocal areaRemote workWork from homeFlexible hours3 days per week1 day per week$161.9k - $243k
Principal Architect, Applications & Integration Date: Sep 23, 2026 Company: Dorman Products Dorman was founded on the belief that people... ..., event‑driven, and distributed patterns. Experience with DevSecOps, CI/CD, automated testing, observability, security,...SuggestedFull time- Location Details: Raymond, OH Work Type: Onsite (4 days/week) W2 Only RESPONSIBILITIES AWS Cloud Solutions Design, deploy, and support AWS-hosted environments and applications supporting SDV and engineering initiatives. Provision, configure, and...Suggested
- ...successful career with opportunities to learn, grow, and make an impact. Join us! Position Summary: The team is looking for a lead architect for critical HPS/MBSS 2026 initiatives including Active/Active Cloud, Gateway Modernization in support of new business. Role...SuggestedWork experience placementWork at officeFlexible hoursShift workDay shift
$146.4k - $263.6k
...Are you excited to improve the security of systems that power life online for billions of users? Are you a security architect who enjoys working with developers to help organizations stay safe? Join our Information Security Team! Akamai's Information Security...SuggestedWork experience placementWork at officeWorldwide- ...brightest minds across development, design, and construction. The Role We Want You For LJC is seeking an experienced Project Architect to join our Life Sciences practice. This role is responsible for the technical leadership, coordination, and execution of...For contractorsCasual workFlexible hours
$118.3k - $219.8k
...serves as a strategic technology partner across multiple products and business domains. The team consists of experienced product architects who provide architectural leadership, drive technology modernization, and ensure alignment with enterprise standards while enabling...Full timeLocal area- ...who work entirely on not for profits projects in New York. This medium sized firm is busy and growing, and looking to add a Project Architect with 7-12 years' experience to their team. The studio work entirely with not for profit clients, but retain a strong design...Work at office
- ...What you bring to this role Experience: Minimum of ten years of architectural experience, with at least five years of recent Project Architect experience on relevant, large-scale projects leading multi-disciplinary teams required. Experience with one of Flad's market...Temporary workFlexible hours
- ...global practice of more than four hundred professionals across eleven offices. Our Los Angeles studio is seeking a talented Project Architect with 5–8 years of experience to join our growing team. Our work includes luxury residential, office, hospitality, and mixed-use...Full timeFor contractorsWork at officeRemote workRelocation package
- ...about our firm and our award-winning projectsWe are experiencing exciting growth and have opportunities for a well-rounded Project Architects with experience or exposure working in a variety of sectors and project types; Multifamily, Hospitality, infrastructure and/or...Local area
- ...Senior Architect Location: St. Louis, Missouri (Remote) Role Overview We are seeking a Senior Architect with a background in healthcare provider technologies to lead a major application modernization and migration initiative. This program focuses on upgrading...Remote workShift work
- ...ASRC Federal NetCentric Technology, LLC is seeking a Senior Architect to join our team for the Kirtland Engineering and Operations Support (KEOS) contract at Kirtland Air Force Base (KAFB) in Albuquerque, New Mexico. KEOS is a base maintenance contract (BMC), also known...Contract workFor contractorsWork at office
$138k - $200.1k
...U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time, including CPT/OPT.\\*\\*\\*The Senior Architect will provide technical leadership and thought leadership across Empower, partnering with enterprise architects, business teams, IT...16 hoursFull timeContract workTemporary workWork experience placementCasual workWork at officeLocal areaRemote workWork visaFlexible hours- ...Services in collaboration with the PM. Responsible for securing QA reviewsand the implementation of comments. Must be a licensed architect and is responsible for signing/sealing drawings. Needs to participate in and contribute to a culture of technical excellence. RESPONSIBILITIES...Temporary workFor contractors
$130k - $145k
...Services in collaboration with the PM. Responsible for securing QA reviewsand the implementation of comments. Must be a licensed architect and is responsible for signing/sealing drawings. Needs to participate in and contribute to a culture of technical excellence. RESPONSIBILITIES...For contractorsWork from homeMonday to FridayFlexible hours$169.3k - $304.7k
...Are you an architect who enjoys working at scale? Are you up to the task of architecting a cutting-edge solutions? Join the Network Operations Systems Group Our team develops innovative solutions crucial to deploying and maintaining Akamai's global network...Work experience placementWork at officeWorldwide- ...SpecPro Sustainment and Environmental (SSE) is seeking a Senior Architect to support the Naval Facilities Engineering Systems Command Southeast (NAVFAC SE), Production Design Construction Division (PDC4) at Naval Air Station Jacksonville, FL. The Senior Architect will...Temporary workWork at officeFlexible hours
- ...projects of varying scales and complexities, delivered through collaboration, technical rigor, and thoughtful leadership. As a Project Architect, you'll partner with clients, design leaders, project managers, and interdisciplinary teams to help bring visionary concepts to...For contractorsLocal area
$156.7k - $290.9k
...designing and implementing solutions to respond to security incidents. Act as a conduit between Global Architecture (Enterprise Architects) and the Engineering or Development teams. Work across/with Architects from different organizations. Introduce/trains teams...Local area$155k - $210k
...Overview Senior Solutions Architect Navy Yard, Washington, DC (4 days onsite required) Secret clearance At Bcore, our strength... ...Identity Services integration (CAC/PIV, Entra ID, Keycloak) DevSecOps, security monitoring (Splunk, Sentinel, EDR), and DoD network...Work at office- ...a place where your ideas matter and your growth is supported, you’ll feel at home here. Why This Role Matters As the Senior Architect in our Phoenix office, you’ll play a crucial role in solidifying and growing Shive-Hattery’s presence in the Government Buildings...Work at officeLocal area
$156k - $234k
...York, NY: East Norriton, PA: Full time: Posted 2 Days Ago: JR100795## Position SummaryWe are looking for an experienced Senior Data Architect to own data product architecture end to end, working closely together with Trinity domain experts to design and build data...Full timeWork at officeRemote work- ...' strategic objectives, evaluating the impact of strategic design decisions, and contributing to the architecture roadmap. DMZ Architect Technical DMZ network architect responsible for DMZ network project designs with focus on SASE and Cloud designs. Also provide...Work at officeRemote workFlexible hoursShift workDay shift
$120k - $225k
...specialized subject matter expertise. About the Role Solution Architect, Technology – Wellington Management offers comprehensive... ...lifecycle. Collaborate with developers, technical leads, and DevSecOps teams to resolve design issues and implementation challenges....Temporary workImmediate startRemote workFlexible hours1 day per week- ...optimization opportunities, establish governance models, and architect scalable cloud solutions while remaining actively engaged in technical... ...cloud infrastructure, platform engineering, Kubernetes, DevSecOps, automation, networking, security, observability, and AI-...
- ...Neighborhoods, Pulte Mortgage, PGP Title, Pulte Insurance Agency —all united under the PulteGroup name. Job Summary The Integration Architect defines the enterprise integration strategy and provides hands‑on architecture leadership for its adoption. This role establishes...Contract workTemporary workHome officeFlexible hours
- ...standards. This role will help shape those solutions while also providing hands-on delivery expertise.The Boomi Developer / Solution Architect will combine solution architecture and technical leadership with hands-on integration development. The position will partner with...Hourly payContract work
- We are looking for an experienced Senior Lead – Snowflake Engineer to lead the design, development, implementation, and optimization of cloud-based data solutions using Snowflake. The role requires strong hands-on technical expertise in Snowflake, SQL, Python, data warehousing...
$110.9k - $221.8k
...fresh thinking, and focuses on growth, so our people, our business, and our customers can achieve their full potential. Product Architect – Customer Outcomes Are you a highly motivated individual with a passion for the latest engineering and manufacturing software...Full timeWork at officeWork from home
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to DevSecOps Architect. Be the first to apply!

