Take your career to the next level! In the last few years our goal has been expansion, creating growth opportunities for many of our team members. Not only are we serious about growth, but we are also serious about helping our customers during hard financial times. We take pride in providing solutions and offering a helping hand, not only to our customers but also to the communities we serve. As we continue to expand and grow into a national leader in consumer financing, we invite you to consider joining our team. If you're passionate about making a meaningful impact in people's lives and bringing a personal touch to finance, we'd love to have you on board!
Job Purpose
The AI Security DevSecOps Engineer is a specialized individual contributor role at the intersection of DevSecOps, AI/ML security, and internal AI development. This person will embed with development teams across the organization to secure CI/CD pipelines and AI development lifecycles end-to-end. In addition to securing how software and AI systems are built and deployed, this engineer will serve as our internal AI developer — designing, building, and orchestrating AI agents that transform how the Security team operates. The ideal candidate is equally comfortable writing a pipeline security gate and building an LLM-powered automation workflow.
Duties and Responsibilities
CI/CD & Pipeline Security
- Design and implement security controls across CI/CD platforms (e.g., GitHub Actions, GitLab CI, Jenkins, Azure DevOps), including SAST, DAST, SCA, container image scanning, and secrets detection.
- Develop and maintain policy-as-code enforcement using tools such as Open Policy Agent (OPA), Sentinel, or Kyverno to automate security guardrails at pipeline stages.
- Establish and govern infrastructure-as-code (IaC) security reviews using tools such as Checkov, tfsec, or Bridgecrew across Terraform and CloudFormation environments.
- Lead software supply chain security initiatives including SBOM generation (Syft, Grype, etc), artifact signing (Sigstore/Cosign, etc), and dependency governance.
- Implement code security standards and report on compliance to such standards.
- Ensure API security is effective and consistent with best practices.
AI/ML Security
- Partner with AI/ML engineering teams to perform threat modeling of LLM-powered applications, model training pipelines, and inference serving layers.
- Implement controls aligned to OWASP LLM Top 10 and MITRE ATLAS, including defenses against prompt injection, data exfiltration, model inversion, and adversarial inputs.
- Secure MLOps workflows including model registries, dataset pipelines, and deployment platforms (e.g., MLflow, Kubeflow, SageMaker).
- Evaluate and advise on AI vendor security posture, third‑party model integrations, and emerging AI supply chain risks.
Internal AI Development & Agent Orchestration
- Design, build, and maintain internal AI agents and automation workflows that accelerate Security team operations — including alert triage, vulnerability enrichment, threat intelligence correlation, compliance evidence collection, and reporting.
- Leverage LLM APIs (e.g., Anthropic Claude, OpenAI) and orchestration frameworks (e.g., LangChain, LlamaIndex) to build reliable, guardrailed agentic systems.
- Establish best practices for responsible internal AI development, including prompt governance, output validation, and audit logging of agent actions.
- Identify and prioritize automation opportunities across the Security team, translating manual workflows into AI-assisted or fully automated pipelines.
Developer Partnership & Security Enablement
- Serve as a trusted security partner — not a gatekeeper — embedded with development teams to champion secure‑by‑default patterns and reduce friction in the SDLC.
- Design and deliver paved‑road security templates, reusable pipeline components, and developer‑facing runbooks that make the secure path the easy path.
- Facilitate threat modeling workshops and security design reviews for new products, services, and AI initiatives.
- Communicate security risks and recommendations effectively to both technical engineers and non‑technical stakeholders.
Cloud & Secrets Management
- Partner with Development and Cloud teams to enhance secrets management strategy using tools such as HashiCorp Vault or AWS Secrets Manager, enforcing least‑privilege access patterns.
- Monitor and improve cloud security posture (AWS, Azure, or GCP) including network security and container/Kubernetes hardening.
- Support incident response activities including those related to CI/CD, cloud, or AI‑specific threats.
Metrics & Reporting
- Define and monitor key security metrics across pipeline security coverage, and AI agent operational health.
- Provide regular reporting on DevSecOps program maturity, AI security posture, and automation impact to security leadership.
Minimum Qualifications
- Education & Experience: Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field.
- 4–7 years of security engineering experience, with meaningful tenure in AppSec, DevSecOps, cloud security, or a closely related role.
- Demonstrated hands‑on experience securing CI/CD pipelines using modern tooling (Snyk, Semgrep, Checkmarx, Trivy, Checkov, or comparable).
- Strong Python or similar scripting proficiency — this role builds tools, not just configures them.
- Working knowledge of LLM security risks including prompt injection, jailbreaking, model inversion, data poisoning, and AI supply chain threats.
- Experience building with LLM APIs or AI orchestration frameworks (LangChain, LlamaIndex, or similar).
- Cloud security proficiency in AWS, Azure, or GCP covering IAM, network security, secrets management, and container/Kubernetes hardening.
- Demonstrated ability to collaborate cross‑functionally with engineering teams and translate security concepts for non‑security audiences.
Preferred Qualifications
- Education & Experience: Master’s degree in Computer Science, Information Security, or a related field.
- Experience with MLOps platforms and securing model registries and training pipelines.
- Background in agentic AI architectures including multi‑agent orchestration, tool use, memory management, and guardrail design.
- Experience with SIEM/SOAR platforms (Splunk, Exabeam, Tines, Torq, or similar) and security data pipelines.
Preferred Certifications
- Certified Information Systems Security Professional (CISSP)
- Offensive Security Certified Professional (OSCP) or Offensive Security Web Expert (OSWE)
- AWS Certified Security – Specialty or equivalent cloud security certification
- Certified AI Security Professional (CAISP) or comparable emerging AI security credential
- Certified DevSecOps Professional (CDP) or Certified DevSecOps Expert (CDE)
Critical Competencies
- Deep knowledge of DevSecOps principles, secure SDLC practices, and CI/CD security tooling.
- Strong understanding of AI/ML threat landscapes including OWASP LLM Top 10, MITRE ATLAS, and emerging attack vectors against AI systems.
- Ability to design, build, and operate AI agents and automation workflows in a production security context.
- Excellent written and oral communication skills with the ability to present to technical and executive audiences.
- Strong project management and organizational skills; able to manage multiple initiatives in a fast‑paced, collaborative environment.
- Ability to work both collaboratively and independently, and to influence without direct authority.
- Intellectual curiosity and a growth mindset — the AI security landscape evolves rapidly and this role demands continuous learning.
Working Conditions
Hybrid work is permitted for this position. Regional has offices in Greenville, SC and Plano, TX available for in-person work. Some travel may be required (less than 10%).
Regional is an equal opportunity employer and does not discriminate on the basis of race, color, religion, creed, national origin, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity, transgender status, age, disability, genetic information, veteran status, uniform service, or any other characteristic protected by applicable law (“Protected Characteristics”). Regional’s policy of non-discrimination applies to all phases of the employment process and relationship, including, but not limited to, recruitment and selection; compensation and benefits; professional development and training; promotions and opportunities; transfers; social and recreational programs; layoff; and terminations.
Founded in 1987, Regional Finance provides services to 500,000 plus customers annually and provides employment for over 2000 team members and growing. We place an emphasis on making a meaningful difference in peoples’ lives by bringing a personal touch to finances and a commitment to diversity, equity, and inclusion that creates a work environment where all employees have a sense of belonging. Team members will have the opportunity to give back to their communities through our outreach program, Regional Reach, that services many organizations throughout the year such as the American Heart Association. Regional Finance is continuously expanding with future plans to become a national brand. Whether you are looking for a job in finance, customer service or even a management role, there are many opportunities for advancement within our company.
At Regional Finance, we care about each other, our customers, and our communities and look for each Team Member’s strengths to meet our shared goals.
Benefits
- Team members will have an incredible benefits package, including but not limited to a comprehensive medical, dental, and vision plan, 401k plans with a company match, and PTO and paid holidays.
- We offer a variety of incredible benefits, including but not limited to a comprehensive medical, dental, and vision plan, 401(k) plans with matching company contributions, PTO and paid holidays, paid parental leave and an employee assistance program for mental health and counseling.
Notice to California Applicants Regional Management Corp. (“Regional Management,” “we,” “our,” or “us”) respects the privacy of our employee’s personal information. Pursuant to the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act of 2020 (“CPRA”), we are required to provide California employees and job applicants with a privacy policy that contains a comprehensive description of our online and offline practices regarding our collection, use, sale, sharing, and retention of their personal information as well as a description of the rights they have regarding their personal information. This Privacy Policy provides the information the CCPA requires as well as other useful information regarding our collection and use of employees and job applicants’ personal information. If you are a job applicant who resides in the states of California, please review our California Employee Privacy Policy by clicking on the following link: California Employee Privacy Policy
#J-18808-LjbffrSecurity AI DevSecOps Engineer in plano at Unknown Company
This position is listed as full time and hybrid.