layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Regional Finance
Plano, TX; 9001 - Plano TX
Source: Regional Finance careers · View original posting
From Regional Finance's posting. “We” and “our” refer to the employer.
Take your career to the next level! In the last few years our goal has been expansion, creating growth opportunities for many of our team members. Not only are we serious about growth, but we are also serious about helping our customers during hard financial times.
We take pride in providing solutions and offering a helping hand, not only to our customers but also to the communities we serve. As we continue to expand and grow into a national leader in consumer financing, we invite you to consider joining our team.
If you're passionate about making a meaningful impact in people's lives and bringing a personal touch to finance, we'd love to have you on board!
Job Purpose
The AI Security DevSecOps Engineer is a specialized individual contributor role at the intersection of DevSecOps, AI/ML security, and internal AI development. This person will embed with development teams across the organization to secure CI/CD pipelines and AI development lifecycles end-to-end. In addition to securing how software and AI systems are built and deployed, this engineer will serve as our internal AI developer — designing, building, and orchestrating AI agents that transform how the Security team operates.
The ideal candidate is equally comfortable writing a pipeline security gate and building an LLM-powered automation workflow.
Duties and Responsibilities
CI/CD & Pipeline Security
Design and implement security controls across CI/CD platforms (e.g., GitHub Actions, GitLab CI, Jenkins, Azure DevOps), including SAST, DAST, SCA, container image scanning, and secrets detection.
Develop and maintain policy-as-code enforcement using tools such as Open Policy Agent (OPA), Sentinel, or Kyverno to automate security guardrails at pipeline stages.
Establish and govern infrastructure-as-code (IaC) security reviews using tools such as Checkov, tfsec, or Bridgecrew across Terraform and CloudFormation environments.
Lead software supply chain security initiatives including SBOM generation (Syft, Grype, etc), artifact signing (Sigstore/Cosign, etc), and dependency governance.
Implement code security standards and report on compliance to such standards
Ensure API security is effective and consistent with best practices
AI/ML Security
Partner with AI/ML engineering teams to perform threat modeling of LLM-powered applications, model training pipelines, and inference serving layers.
Implement controls aligned to OWASP LLM Top 10 and MITRE ATLAS, including defenses against prompt injection, data exfiltration, model inversion, and adversarial inputs.
Secure MLOps workflows including model registries, dataset pipelines, and deployment platforms (e.g., MLflow, Kubeflow, SageMaker).
Evaluate and advise on AI vendor security posture, third-party model integrations, and emerging AI supply chain risks.
Internal AI Development & Agent Orchestration
Design, build, and maintain internal AI agents and automation workflows that accelerate Security team operations — including alert triage, vulnerability enrichment, threat intelligence correlation, compliance evidence collection, and reporting.
Leverage LLM APIs (e.g., Anthropic Claude, OpenAI) and orchestration frameworks (e.g., LangChain, LlamaIndex) to build reliable, guardrailed agentic systems.
Establish best practices for responsible internal AI development, including prompt governance, output validation, and audit logging of agent actions.
Identify and prioritize automation opportunities across the Security team, translating manual workflows into AI-assisted or fully automated pipelines.
Developer Partnership & Security Enablement
Serve as a trusted security partner — not a gatekeeper — embedded with development teams to champion secure-by-default patterns and reduce friction in the SDLC.
Design and deliver paved-road security templates, reusable pipeline components, and developer-facing runbooks that make the secure path the easy path.
Facilitate threat modeling workshops and security design reviews for new products, services, and AI initiatives.
Communicate security risks and recommendations effectively to both technical engineers and non-technical stakeholders.
Cloud & Secrets Management
Partner with Development and Cloud teams to enhance secrets management strategy using tools such as HashiCorp Vault or AWS Secrets Manager, enforcing least-privilege access patterns.
Monitor and improve cloud security posture (AWS, Azure, or GCP) including network security and container/Kubernetes hardening.
Support incident response activities including those related to CI/CD, cloud, or AI-specific threats.
Metrics & Reporting
Define and monitor key security metrics across pipeline security coverage, and AI agent operational health.
Provide regular reporting on DevSecOps program maturity, AI security posture, and automation impact to security leadership.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: