IT Operations Specialist - AI Reviews/DevSecOps
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
At Fluor, we are proud to design and build projects and careers. We are committed to fostering a welcoming and collaborative work environment that encourages big-picture thinking, brings out the best in our employees, and helps us develop innovative solutions that contribute to building a better world together. If this sounds like a culture you would like to work in.
Job DescriptionThe AI Reviews / Dev Sec Ops Specialist supports secure delivery of traditional and AI-enabled solutions by performing application security reviews, AI security assessments, and Dev Sec Ops control validation before production use. The role works closely with Security Operations, AI Security and Privacy Architecture, developers, internal business customers, platform teams, and vendors to identify risks early, verify remediation, and produce defensible evidence for governance and audit needs.
- Perform security reviews for AI-enabled applications, copilots, agents, integrations, and supporting APIs before production deployment.
- Execute AI-specific security checks, including prompt-injection testing, jailbreak resistance review, tool-misuse assessment, sensitive-data leakage testing, grounding/source validation, and abuse-case review.
- Review remediation plans, validate fixes, and document residual risk, compensating controls, or waiver/risk-register inputs when required.
- Partner with development and platform teams to embed secure coding, threat modeling, CI/CD security gates, SBOM/SCA review, and secure deployment practices into delivery workflows.
- Assess third-party and internally developed AI solutions for data handling, access control, logging, retention, model interaction, and integration risks.
- Maintain reusable review checklists, evidence templates, testing playbooks, and operating procedures for AI and application security assessments.
- Stay current with AI security threats, application vulnerabilities, OWASP guidance, and Dev Sec Ops tooling trends, and translate lessons learned into practical review criteria.
Job Requirements
- Accredited four (4) year degree or global equivalent in applicable field of study and five (5) years of work-related experience or a combination of education and directly related experience equal to nine (9) years if non-degreed; some locations may have additional or different qualifications in order to comply with local requirements
- Ability to communicate effectively with audiences that include but are not limited to management, coworkers, clients, vendors, contractors, and visitors
- Job related technical knowledge necessary to complete the job
- Ability to learn and apply knowledge of applicable local, state/province, and federal/national statutes and guidelines
- Ability to attend to detail and work in a time-conscious and time-effective manner
Job Requirements
- Ability to support a globally distributed team and coordinate reviews across time zones as needed.
- Ability to document technical findings clearly enough for developers, IT leaders, risk owners, and non-technical stakeholders.
- Ability to handle sensitive application, architecture, vendor, and security assessment information appropriately.
- Other duties as assigned.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field.
- Experience performing application security reviews or Dev Sec Ops engineering in enterprise environments.
- Hands-on experience with SAST, DAST, SCA/dependency scanning, secrets scanning, IaC scanning, API security testing, and CI/CD security controls.
- Familiarity with AI security concerns such as prompt injection, jailbreak techniques, insecure tool use, data leakage, model/agent governance, and AI system abuse cases.
- Working knowledge of OWASP Top Ten, OWASP API Top Ten, and emerging AI security guidance such as OWASP Top 10 for LLM Applications.
- Ability to read architecture diagrams, understand authentication/authorization flows, and identify practical security gaps in application design.
- Proficiency with scripting or programming languages such as Python, JavaScript, Java, Power Shell, or similar is a plus.
- Strong written communication, note-taking, prioritization, and collaboration skills.
We are an equal opportunity employer. All qualified individuals will receive consideration for employment without regard to race, color, age, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, genetic information, or any other criteria…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).