{"schemaVersion":"jobsearcher.job.v1","id":"8d9779b6d26e225346adc138","url":"https://jobsearcher.com/jobs/8d9779b6d26e225346adc138","canonicalUrl":"https://jobsearcher.com/jobs/8d9779b6d26e225346adc138","title":"Sr Developer Security Operations Architect","description":"At PennEngineering, we innovate and collaborate to make the world a better place. You can contribute to work that matters with a company where diversity, equity and inclusion are shared values. We're committed to fostering an environment for every employee that's welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us.\nWe are seeking a Senior Developer Security Architect who is responsible for building and operating the security architecture that enables PennEngineering' s engineering teams to ship code safely at high velocity. This is a hands-on leadership role: part architect, part builder, part platform engineer.\nAs PennEngineering' s AI application portfolio grows, including AI-powered workflows, agentic systems, and customer-facing digital platforms, this role will play a critical part in establishing the security architecture and governance frameworks that allow those systems to operate reliably, safely, and at enterprise scale.\nJoin us as we build the future in Manufacturing and Engineering!\nPERKS AND BENEFITS:\nPTO, holiday pay, 401K, tuition reimbursement\nMedical, Dental and vision insurance\nCompany provided technology including Laptop, necessary monitors and hardware for office and home environments, iPhone, etc.\nEmployee Centric Culture\nWHAT YOU WILL DO:\nCloud Security Posture & Remediation\nContinuously assess, harden, and elevate the security posture of PennEngineering's AWS cloud infrastructure, covering both customer-facing platforms and internal enterprise systems\nDesign and build custom security tools, frameworks, and policies tailored to protect PennEngineering's internal and external organizational assets\nOwn the end-to-end vulnerability management lifecycle, including triage, tracking, prioritization, and automated remediation of identified vulnerabilities and cloud misconfigurations\nEstablish a continuous posture improvement program with defined baselines, remediation SLAs, and executive-level reporting on security health\nPipeline Security & CI/CD Integration\nArchitect and implement automated security scanning (SAST, SCA, and DAST), embedded directly into CI/CD pipelines, ensuring checks are high-fidelity and low-latency to support our daily deployment cadence\nConfigure pre-commit hooks, pull request checks, and branch protection rules that automatically detect and block secrets, misconfigurations, or vulnerable dependencies before they reach production\nPartner with AI engineering teams to secure AI/LLM workloads within the pipeline, including prompt injection protections, model input/output validation, and agentic system guardrails\nEstablish security gate standards and developer-friendly documentation so engineering teams understand what is enforced, why, and how to resolve failures quickly\nAutomated Governance & Policy-as-Code\nReplace manual security audits with automated policy enforcement using infrastructure-as-code tools (Terraform, AWS Config), ensuring non-compliant infrastructure cannot be provisioned\nBuild event-driven automation to detect and auto-remediate common security issues in near real-time, reducing mean time to respond across the environment\nDefine and maintain security governance standards, including access controls, secrets management, encryption policies, and data classification frameworks\nEstablish audit-ready documentation and evidence collection practices to support internal compliance reviews and external assessments\nCloud Operations & Threat Response\nMaintain the operational security health of PennEngineering's AWS environment, using automation to manage scaling events, configuration drift, and self-healing infrastructure\nOperationalize CrowdStrike and Zscaler telemetry by automating the correlation of security alerts to reduce noise and trigger rapid, automated response workflows\nDefine and own security incident response playbooks; lead root-cause analysis and post-incident reviews to drive systemic improvements\nCollaborate with IS, infrastructure, and AI engineering teams to ensure threat response practices are integrated across the full technology stack\nSecurity Architecture for AI & Emerging Platforms\nDefine the security architecture for PennEngineering's AI-powered application portfolio, including data access controls, model governance, prompt safety, and auditability for agentic systems\nEvaluate and advise on security posture for new platforms, tools, and third-party integrations as the technology portfolio evolves\nPartner with the Principal Systems Architect and AI engineering teams to embed security requirements into solution designs from the earliest stages\nStay current on emerging threats relevant to AI systems, cloud-native architectures, and manufacturing/industrial environments, and translate findings into actionable architectural guidance\n#LI-BS1\nRequirements:\nWHAT WE ARE LOOKING FOR:\n8+ years of experience in cloud security, DevSecOps, or security engineering, with at least 3 years in an architect-level role\nDeep expertise in AWS cloud architecture and security services, including IAM, Security Hub, GuardDuty, Config, KMS, VPC design, and CloudTrail\nProven experience integrating automated security tooling (SAST, SCA, DAST) into modern CI/CD pipelines without degrading deployment velocity\nHands-on experience with infrastructure-as-code and policy-as-code approaches using Terraform or AWS CDK\nStrong scripting and automation skills in Python, Go, or Bash, with the ability to build custom security tools and integrate systems programmatically\nExperience securing containerized workloads including Docker, Kubernetes, and ECS/EKS deployments\nPractical knowledge of vulnerability management, threat modeling, incident response, and security operations in a cloud-native environment\nDemonstrated ability to work as a trusted partner to engineering and product teams, designing security that accelerates rather than blocks delivery\nExcellent communication skills, including the ability to translate technical security risks into business terms for senior leadership\nBachelor's degree in Computer Science, Information Security, Engineering, or a related technical field\nPreferred Qualifications\nExperience defining security architecture for AI/LLM-powered systems, including prompt injection protections, model access controls, output validation, and auditability requirements for agentic applications\nHands-on experience operationalizing CrowdStrike and Zscaler in an enterprise environment\nFamiliarity with Model Context Protocol (MCP) and emerging security considerations for tool-use in agentic AI systems\nExperience in manufacturing, industrial, or complex B2B technology environments\nRelevant certifications: AWS Security Specialty, CISSP, CCSP, or equivalent\nExperience contributing to or leading security programs in support of SOC 2, ISO 27001, or similar compliance frameworks\nBackground working in a global organization with multi-region cloud deployments\nPennEngineering is committed to Diversity, Equity and Belonging, and we welcome applicants from all backgrounds and experiences. We are an equal opportunity employer and prohibit discrimination and harassment based on race, color, religion, national origin, ancestry, disability, sex, gender identity or expression, sexual orientation, military or veteran status, or any other characteristic protected by applicable law. We lift up voices and opinions by creating a respectful work environment where difference is valued, and we are doing our part to build towards a greater society where diverse points of view are celebrated.\n\nCompensation: 140,000","company":"Pennengineering","rawCompany":"pennengineering","city":"Doylestown","state":"PA","isRemote":false,"isActive":false,"createdAt":"2026-08-04T18:07:08.959Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Sr Developer Security Operations Architect","description":"At PennEngineering, we innovate and collaborate to make the world a better place. You can contribute to work that matters with a company where diversity, equity and inclusion are shared values. We're committed to fostering an environment for every employee that's welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us.\nWe are seeking a Senior Developer Security Architect who is responsible for building and operating the security architecture that enables PennEngineering' s engineering teams to ship code safely at high velocity. This is a hands-on leadership role: part architect, part builder, part platform engineer.\nAs PennEngineering' s AI application portfolio grows, including AI-powered workflows, agentic systems, and customer-facing digital platforms, this role will play a critical part in establishing the security architecture and governance frameworks that allow those systems to operate reliably, safely, and at enterprise scale.\nJoin us as we build the future in Manufacturing and Engineering!\nPERKS AND BENEFITS:\nPTO, holiday pay, 401K, tuition reimbursement\nMedical, Dental and vision insurance\nCompany provided technology including Laptop, necessary monitors and hardware for office and home environments, iPhone, etc.\nEmployee Centric Culture\nWHAT YOU WILL DO:\nCloud Security Posture & Remediation\nContinuously assess, harden, and elevate the security posture of PennEngineering's AWS cloud infrastructure, covering both customer-facing platforms and internal enterprise systems\nDesign and build custom security tools, frameworks, and policies tailored to protect PennEngineering's internal and external organizational assets\nOwn the end-to-end vulnerability management lifecycle, including triage, tracking, prioritization, and automated remediation of identified vulnerabilities and cloud misconfigurations\nEstablish a continuous posture improvement program with defined baselines, remediation SLAs, and executive-level reporting on security health\nPipeline Security & CI/CD Integration\nArchitect and implement automated security scanning (SAST, SCA, and DAST), embedded directly into CI/CD pipelines, ensuring checks are high-fidelity and low-latency to support our daily deployment cadence\nConfigure pre-commit hooks, pull request checks, and branch protection rules that automatically detect and block secrets, misconfigurations, or vulnerable dependencies before they reach production\nPartner with AI engineering teams to secure AI/LLM workloads within the pipeline, including prompt injection protections, model input/output validation, and agentic system guardrails\nEstablish security gate standards and developer-friendly documentation so engineering teams understand what is enforced, why, and how to resolve failures quickly\nAutomated Governance & Policy-as-Code\nReplace manual security audits with automated policy enforcement using infrastructure-as-code tools (Terraform, AWS Config), ensuring non-compliant infrastructure cannot be provisioned\nBuild event-driven automation to detect and auto-remediate common security issues in near real-time, reducing mean time to respond across the environment\nDefine and maintain security governance standards, including access controls, secrets management, encryption policies, and data classification frameworks\nEstablish audit-ready documentation and evidence collection practices to support internal compliance reviews and external assessments\nCloud Operations & Threat Response\nMaintain the operational security health of PennEngineering's AWS environment, using automation to manage scaling events, configuration drift, and self-healing infrastructure\nOperationalize CrowdStrike and Zscaler telemetry by automating the correlation of security alerts to reduce noise and trigger rapid, automated response workflows\nDefine and own security incident response playbooks; lead root-cause analysis and post-incident reviews to drive systemic improvements\nCollaborate with IS, infrastructure, and AI engineering teams to ensure threat response practices are integrated across the full technology stack\nSecurity Architecture for AI & Emerging Platforms\nDefine the security architecture for PennEngineering's AI-powered application portfolio, including data access controls, model governance, prompt safety, and auditability for agentic systems\nEvaluate and advise on security posture for new platforms, tools, and third-party integrations as the technology portfolio evolves\nPartner with the Principal Systems Architect and AI engineering teams to embed security requirements into solution designs from the earliest stages\nStay current on emerging threats relevant to AI systems, cloud-native architectures, and manufacturing/industrial environments, and translate findings into actionable architectural guidance\n#LI-BS1\nRequirements:\nWHAT WE ARE LOOKING FOR:\n8+ years of experience in cloud security, DevSecOps, or security engineering, with at least 3 years in an architect-level role\nDeep expertise in AWS cloud architecture and security services, including IAM, Security Hub, GuardDuty, Config, KMS, VPC design, and CloudTrail\nProven experience integrating automated security tooling (SAST, SCA, DAST) into modern CI/CD pipelines without degrading deployment velocity\nHands-on experience with infrastructure-as-code and policy-as-code approaches using Terraform or AWS CDK\nStrong scripting and automation skills in Python, Go, or Bash, with the ability to build custom security tools and integrate systems programmatically\nExperience securing containerized workloads including Docker, Kubernetes, and ECS/EKS deployments\nPractical knowledge of vulnerability management, threat modeling, incident response, and security operations in a cloud-native environment\nDemonstrated ability to work as a trusted partner to engineering and product teams, designing security that accelerates rather than blocks delivery\nExcellent communication skills, including the ability to translate technical security risks into business terms for senior leadership\nBachelor's degree in Computer Science, Information Security, Engineering, or a related technical field\nPreferred Qualifications\nExperience defining security architecture for AI/LLM-powered systems, including prompt injection protections, model access controls, output validation, and auditability requirements for agentic applications\nHands-on experience operationalizing CrowdStrike and Zscaler in an enterprise environment\nFamiliarity with Model Context Protocol (MCP) and emerging security considerations for tool-use in agentic AI systems\nExperience in manufacturing, industrial, or complex B2B technology environments\nRelevant certifications: AWS Security Specialty, CISSP, CCSP, or equivalent\nExperience contributing to or leading security programs in support of SOC 2, ISO 27001, or similar compliance frameworks\nBackground working in a global organization with multi-region cloud deployments\nPennEngineering is committed to Diversity, Equity and Belonging, and we welcome applicants from all backgrounds and experiences. We are an equal opportunity employer and prohibit discrimination and harassment based on race, color, religion, national origin, ancestry, disability, sex, gender identity or expression, sexual orientation, military or veteran status, or any other characteristic protected by applicable law. We lift up voices and opinions by creating a respectful work environment where difference is valued, and we are doing our part to build towards a greater society where diverse points of view are celebrated.\n\nCompensation: 140,000","datePosted":"2026-08-04T18:07:08.959Z","dateModified":"2026-08-04T18:07:08.959Z","hiringOrganization":{"@type":"Organization","name":"Pennengineering","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Doylestown","addressRegion":"PA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"8d9779b6d26e225346adc138"},"url":"https://jobsearcher.com/jobs/8d9779b6d26e225346adc138"}}