×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Director of DevOps​/SecOps

Job in Denver, Denver County, Colorado, 80285, USA
Listing for: Service Core
Full Time position
Listed on 2026-06-19
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 190000 - 225000 USD Yearly USD 190000.00 225000.00 YEAR
Job Description & How to Apply Below

Director of Dev Ops/Sec Ops

Service Core is a leading field service software platform built for the portable sanitation and roll‑off industries. We provide two SaaS products—Service Core for liquid waste operators and Docket for solid waste haulers—serving thousands of operators across North America.

About the role

We’re looking for a Director of Dev/Sec Ops to own the security posture and operational foundation across Service Core’s entire cloud environment. The role is security‑first, operating across AWS (Service Core) and GCP/Firebase (Docket), and includes AI tool governance.

What you’ll do AI Tool Governance & Security
  • Partner with the AI Council and Engineering Directors to build an AI tool evaluation framework—defining the security, privacy, and compliance criteria for new AI tools.
  • Govern multi‑LLM provider relationships—review data processing agreements, audit data retention policies, and ensure contractual protections for customer data.
  • Establish and enforce policies around data flow through AI services: PII boundaries, source code confidentiality rules, and customer data handling for coding assistants, LLM APIs, and agentic tools.
  • Secure MCP‑connected agents with least‑privilege access models, audit trails, and data egress controls.
  • Define secure patterns for integrating LLM capabilities into products—including prompt injection defenses, output validation, model access controls, and logging/observability.
  • Build and maintain an AI tool inventory with risk classifications and lead periodic reviews.
  • Partner with engineering and product to help obtain AI productivity benefits while managing risk.
Security Leadership
  • Own and continuously improve security posture across AWS and GCP/Firebase.
  • Lead threat modeling, vulnerability management, and security incident response programs.
  • Establish and enforce security policies, standards, and controls across the SDLC.
  • Champion a security‑first engineering culture.
  • Manage relationships with external auditors, penetration testers, and compliance bodies.
Compliance & Risk
  • Drive SOC 2 Type II compliance and own evidence collection across both platforms.
  • Manage PCI‑DSS considerations across payment processor integrations.
  • Build and maintain a risk register and prioritize risks to leadership.
  • Own third‑party vendor security reviews for 20+ integration partners, including AI vendors.
  • Monitor regulatory developments relevant to SaaS, AI, and the industries we serve.
Dev Ops & Platform Engineering
  • Secure CI/CD pipelines across both cloud environments—secrets management, dependency scanning, SAST/DAST.
  • Lead infrastructure‑as‑code strategy and embed security guardrails by default.
  • Own cloud security architecture.
  • Secure Cloudflare CDN/WAF configuration, DDoS posture, and DNS hygiene.
  • Drive incident response readiness—runbooks, on‑call processes, post‑mortems, and SLA accountability.
Team & Cross‑Functional Leadership
  • Hire, develop, and lead a Dev Sec Ops  team.
  • Collaborate with engineering leads on architectural decisions with security implications.
  • Report to senior leadership on security metrics, risk posture, compliance status, and AI tool governance.
  • Serve as the internal expert and educator on security and AI risk topics.
What you’ll bring
  • 10+ years of experience in Dev Ops, Sec Ops, or a combined Dev Sec Ops  role.
  • 3+ years in a leadership or management capacity with direct reports.
  • Deep hands‑on experience with AWS security—including IAM, VPC, ECS, Lambda, SQS, RDS, DynamoDB, Secrets Manager, Cloud Watch, Cloud Formation.
  • Meaningful experience with GCP and/or Firebase—including Firestore security rules, Cloud Functions security, GCP IAM, and service account management.
  • Experience owning or significantly contributing to SOC 2 Type II audits.
  • Strong background in securing CI/CD pipelines and containerized workloads (Docker, ECS, or EKS).
  • Demonstrated experience governing third‑party integrations and API security at scale.
  • Working knowledge of SAST, DAST, SCA, dependency scanning, and secrets management tooling.
  • Real point of view on AI tool security—understanding risks of coding assistants, LLM APIs, MCP‑connected agents, and AI in developer workflows.
  • Ability to communicate risk and security…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary