Job Title: Security & Agentic AI DevSecOps Engineer
Location: Milpitas, CA
Duration: Contract
Key Responsibilities
AI Security & Agentic Systems (Automation First)
• Design and implement automated Agentic and AI security controlsfor agentic systems, including:
o Automated model access control, inference authorization, and rate limiting
o Policy driven prompt/instruction validation and misuse detection
o Automated enforcement of agent to agent authentication and authorization
• Implement continuous, automated threat modeling for:
o LLM pipelines
o Agent orchestration frameworks
o AI gateways and inference services
• Build secure by default reference architectures where AI guardrails are enforced via:
o Configuration as code
o Runtime policy engines
o Automated security testing pipelines
• Create Plugins , Hooks and Skills using claude code and or Microsoft AI foundry
DevSecOps & Secure SDLC (End to End Automation)
• Implement fully automated Secure SDLC pipelines, integrating:
o SAST, DAST, SCA, secrets detection, container scanning, and IaC scanning
o AI specific security testing (prompt injection, model misuse, data leakage)
o Automated build and release policy enforcement (fail gates, conditional approvals)
• Ensure all security checks are:
o Triggered automatically via CI/CD and MLOps pipelines
o Enforced consistently across dev, test, and production
• Automate security validation during:
o Design reviews (template driven controls)
o Architecture reviews (reusable security patterns)
o Pre release readiness checks
SBOM, AI BOM & Supply Chain Automation
• Design and operate automated SBOM and AI BOM pipelines, including:
o Continuous generation of SBOMs for software, containers, firmware, and artifacts
o Automated AI BOMs covering models, datasets, checkpoints, and training artifacts
• Implement automated vulnerability, license, and provenance analysis:
o Continuous ingestion of CVEs and advisories
o Automated policy enforcement for non compliant components
• Integrate SBOM and AI BOM outputs into:
o CI/CD pipelines
o Deployment gates
o Audit and compliance reporting workflows
Runtime Security, Risk & Metrics Automation
• Implement continuous, automated security monitoringacross:
o Application runtimes
o AI/ML inference services
o Agent workflows and interactions
• Develop automated security metrics and telemetry to measure:
o Vulnerability exposure and remediation velocity
o Secure SDLC and DevSecOps maturity
o Model and AI risk posture over time
• Automate security feedback loops so findings:
o Generate actionable tasks
o Feed directly into engineering backlogs
o Drive measurable risk reduction
Technical Influence & Enablement
• Ability and willing to learn,teach and develop agentic AI workflow automation using copilot studio and or Claude code
• Act as a technical authority on AI security automation and DevSecOps.
• Define reusable security automation patterns, templates, and reference implementations.
• Partner with engineering, AI/ML, platform, and compliance teams to replace manual security workflows with automated controls.
• Contribute to internal security standards that mandate automation by default.
• Strong hands on experience designing automated Product Security or AI Security systems.
• Deep knowledge of:
o Operating systems, infrastructure, cloud platforms, and hybrid environments
o Automation frameworks and pipeline driven enforcement models
• Ability to interpret and secure code written in multiple languages, with automation as the primary mitigation strategy.
• Experience integrating security tooling via APIs and pipelines, not manual review.
• Familiarity with security intelligence ingestion and automation, including:
o CVE feeds
o Security advisories
o Automated alerting and remediation workflows
• Strong understanding of cybersecurity, privacy, and AI governance requirements, with experience translating them into automated controls.
• Ability to concurrently deliver multiple security automation initiatives.
________________________________________
Minimum Qualifications
• Bachelor’s degree in Computer Science, Cybersecurity, IT Security, or equivalent experience.
• Experience in DevOps, SecOps, DevSecOps, or MLOps, with a strong automation focus.
• Demonstrated success implementing automated Secure SDLC pipelines.
• Ability to evaluate code and architecture risk and remediate through automation, not policy alone.
• Familiarity with security frameworks and scoring systems:
o MITRE ATT&CK
o CVSS
o CWE
• Strong technical communication skills and cross functional influence.