• Davie, FL
    2 days ago

    Job Description

    Skip to main content

    You may choose to display a cookie banner on the external site. You must specify the message in the cookie banner and may add a link to a relevant policy. If you are unfamiliar with these requirements, please seek the advice of legal counsel.

    What are cookies?

    Cookies are simple text files that are stored on your computer or mobile device by a website's server. Each cookie is unique to your web browser. Some information that we collect about you is collected passively through the use of "cookies." Cookies are small files of information, which save and retrieve information about your visit to the Website - for example, how you entered and navigated our Website, and what information was of interest to you. We use this information to remember you when you return and to customize our Website to your preferences. It will contain some anonymous information such as a unique identifier, website's domain name, and some digits and numbers. We may use two types of cookies: (i) Session cookies; and (ii) Persistent Cookies. Session Cookies and Persistent Cookies are categorized as: (a) Strictly Necessary Cookies; (b) Performance and Functional Cookies; (c) Targeting Cookies and (d) Social Media Cookies.

    What types of cookies do we use?

    Necessary cookies

    Necessary cookies allow us to offer you the best possible experience when accessing and navigating through our website and using its features. These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information. For example, these cookies let us recognize that you have created an account and have logged into that account. Strictly Necessary Cookies do not store any Personal Information.

    Performance & Functional cookies

    These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance. If you do not allow Performance Cookies we will not know when you have visited our site, and we will not be able to monitor its performance. (Examples: monitor website performance and collect anonymous data on how visitors use a website).

    Targeting cookies

    These cookies enable us and third-party services to collect aggregated data for statistical purposes on how our visitors use the website. These cookies do not contain personal information such as names and email addresses and are used to help us improve your user experience of the website. These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising. Examples include: Criteo, Google.

    Social Media Cookies

    These cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools. Examples include: Facebook, Instagram, Twitter).

    How to delete cookies?

    If you want to restrict or block the cookies that are set by our website, you can do so through your browser setting. Alternatively, you can visit www.internetcookies.com, which contains comprehensive information on how to do this on a wide variety of browsers and devices. You will find general information about cookies and details on how to delete cookies from your device.

    Do not track signals

    Currently, our systems do not recognize browser "do-not-track" requests. You may, however, disable certain tracking as discussed in the Cookies section (e.g., by disabling cookies). Please note that Hard Rock does not collect, and is not aware of third parties that collect, from users of the Website personal information about users' online activities across third party websites.

    Clear GIFS, Pixel Tags and other technologies

    Clear GIFs are tiny graphics with a unique identifier, similar in function to cookies. In contrast to cookies, which are stored on your computer's hard drive, clear GIFs are embedded invisibly on web pages. We may use clear GIFs (a.k.a. web beacons, web bugs or pixel tags), in connection with our Website to, among other things, track the activities of Website visitors, help us manage content, and compile statistics about Website usage. You may view and change your preferences at any time by using the 'Privacy Settings' link found in the footer of our website. We and our third party service providers also use clear GIFs in HTML e-mails to our customers, to help us track e-mail response rates, identify when our e-mails are viewed, and track whether our e-mails are forwarded.

    Third party analytics and tracking

    We use automated devices and applications, such as Google Analytics, to evaluate usage of our Site. We also may use other analytic means to evaluate our services. We use these tools to help us improve our services, performance and user experiences. These entities may use cookies, tracking pixels and other tracking technologies to perform their services. We do not share your personal information with these third parties.

    Contacting us

    If you have any questions about this policy or our use of cookies, please contact us at dataprotection@shrss.com.

    Read Full Privacy Message

    Decline

    Accept Cookies

    Sign In

    Search for JobsStay Connected

    DevSecOps Architect page is loaded

    DevSecOps Architect

    Apply

    remote typeHybrid

    locationsSupport Services Headquarters Building

    time typeFull time

    posted onPosted Today

    job requisition idR13428

    Our team members are the key to our company's success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits

    Job Description:

    At Seminole Hard Rock Support Services, we are on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. As the DevSecOps Architect, you will define, build, and champion the integration of security into every stage of the Secure Software Development Lifecycle (S-SDLC), embedding automated security controls, governance, and compliance into CI/CD pipelines, cloud infrastructure, and application delivery processes across the enterprise.

    Reporting to the Director II of Cybersecurity Architecture, Engineering & IAM, this role requires a deeply technical, security-minded architect and engineer who bridges the worlds of software development, cloud operations, and cybersecurity. You will design and implement secure-by-default development frameworks, automate security testing and compliance enforcement, and drive a cultural shift toward shared security ownership, ensuring that every application and infrastructure deployment across all Seminole Hard Rock business units is built secure from the ground up.

    This is a shift-left architecture role. The ideal candidate does not sit at the end of the pipeline reviewing what others have built, they embed themselves into the engineering lifecycle, define the standards developers work within, and build the tooling and automation that makes security the path of least resistance. You architect at scale, write production-grade code, and measure your impact in vulnerabilities prevented, not just discovered.

    Responsibilities

    Security Architecture & Secure SDLC

    • Design and implement an enterprise DevSecOps architecture that embeds security controls, automated testing, and compliance validation into every phase of the software development lifecycle, from code commit through production deployment
    • Define and maintain secure coding standards, application security reference architectures, and security design patterns that development teams adopt as foundational building blocks, not optional guidelines
    • Architect threat modeling frameworks and processes that enable development teams to proactively identify and mitigate security risks during design and development phases, before code is written
    • Establish and govern security gate criteria within CI/CD pipelines, ensuring that code, container images, infrastructure-as-code templates, and third-party dependencies meet security and compliance thresholds before promotion to production
    • Own the security architecture review process for new applications, platforms, and major system changes, providing timely, actionable guidance that accelerates delivery rather than blocking it

    Pipeline Engineering & Automation

    • Design, build, and maintain secure CI/CD pipelines integrating automated security tooling across the full spectrum: static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), container scanning, infrastructure-as-code (IaC) scanning, and secrets detection
    • Develop and maintain custom pipeline integrations, security automation scripts, and policy-as-code frameworks using Python, PowerShell, Go, or similar languages, enforcing security controls programmatically at scale
    • Implement automated compliance-as-code solutions that continuously validate infrastructure and application configurations against regulatory requirements (PCI-DSS, SOX, tribal gaming regulations) and internal security policies, eliminating manual evidence collection
    • Engineer automated remediation workflows that detect, alert, and resolve common security misconfigurations and vulnerabilities without manual intervention, reducing mean time to remediate across the portfolio
    • Build developer-facing security tooling and integrations that surface security findings directly within developer workflows (IDE plugins, pull request gates, ticketing integrations), making security feedback immediate and actionable

    Cloud & Infrastructure Security

    • Architect and enforce security guardrails across cloud environments (Azure, AWS, Google Cloud), including network segmentation, identity and access policies, encryption standards, logging configurations, and monitoring baselines
    • Design and implement secure infrastructure-as-code (Terraform, Ansible, ARM/Bicep, CloudFormation) templates and modules that serve as hardened, reusable baselines for all cloud and on-premises deployments
    • Oversee container and Kubernetes security architecture, including image hardening, runtime protection, network policies, secrets management, and admission control policies
    • Collaborate with cloud engineering, infrastructure, and platform teams to ensure IaaS, PaaS, and serverless workloads across Linux and Windows environments are deployed and operated in accordance with zero-trust principles and enterprise security standards
    • Define and maintain cloud security posture management (CSPM) standards, continuously monitoring for drift and enforcing guardrails that prevent insecure configurations from reaching production

    Application Security & Vulnerability Management

    • Lead the application security program in partnership with development teams - conducting architecture reviews, code reviews, and penetration testing coordination to identify and remediate vulnerabilities before they reach production
    • Evaluate, implement, and manage application security tooling across SAST, DAST, SCA, container, and cloud posture domains, ensuring comprehensive, continuous coverage across the full application and infrastructure portfolio
    • Drive adoption of secure software supply chain practices, including software bill of materials (SBOM) generation, dependency management, artifact signing, provenance verification, and third-party component vetting
    • Establish a vulnerability management lifecycle with defined SLAs, risk-based prioritization, and integration into development sprints - ensuring findings are remediated by development teams, not just reported by security
    • Lead red team coordination and penetration testing engagements, translating findings into architectural improvements and developer education, not just remediation tickets

    Culture, Enablement & Continuous Improvement

    • Champion a DevSecOps culture of shared security responsibility across development, operations, and security teams, breaking down silos and fostering collaboration through training, enablement, and embedded security practices
    • Develop and deliver security training programs, workshops, secure coding guidelines, and self-service tooling that empower developers to build securely and independently - without requiring security team involvement for every decision
    • Establish DevSecOps metrics and KPIs (mean time to remediate, vulnerability escape rate, pipeline security coverage, compliance drift, developer security adoption) to measure program effectiveness and drive continuous improvement
    • Research, prototype, and evaluate emerging DevSecOps capabilities, including AI-powered security testing, LLM/generative AI security controls, and intelligent vulnerability prioritization, piloting innovations that deliver measurable security outcomes
    • Mentor and provide technical guidance to security engineers, developers, and operations staff, raising the security proficiency and awareness of the broader technology organization
    • Stay at the forefront of DevSecOps, application security, cloud-native security, and AI-powered security testing trends, continuously identifying opportunities to adopt emerging technologies and practices for competitive advantage

    Qualifications & Experience

    • 8-10+ years of combined experience in cybersecurity, software engineering, DevOps/platform engineering, or cloud architecture, with at least 4+ years focused on DevSecOps, application security, or security engineering in enterprise environments
    • Demonstrated success designing and implementing enterprise DevSecOps programs, including secure CI/CD pipelines, automated security testing, and policy-as-code frameworks at scale
    • hands-on experience with Python, Go, PowerShell, or similar languages, with the ability to build custom security tooling, pipeline integrations, and automation frameworks from scratch Strong software development proficiency,
    • hands-on experience architecting and securing workloads in IaaS, PaaS, serverless, and containerized (Docker, Kubernetes) environments on Azure and/or AWS across Linux and Windows Deep infrastructure expertise
    • Extensive experience with CI/CD platforms (GitHub Actions, Azure DevOps, GitLab CI, Jenkins) and infrastructure-as-code tools (Terraform, Ansible, ARM/Bicep, CloudFormation)
    • Strong working knowledge of application security testing tools and practices: SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection, and the vulnerability management lifecycle end-to-end
    • Deep understanding of cloud security architecture, zero-trust principles, identity and access management, network security, and data protection across hybrid and multi-cloud environments
    • Experience with secure software supply chain practices: SBOM, artifact signing, dependency governance, and third-party risk management
    • Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required
    • Relevant certifications preferred: CISSP, CISM, CSSLP, GWEB, Microsoft SC-series, Azure Solutions Architect/DevOps Engineer, AWS Security Specialty/DevOps Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent

    Professional Skills

    • Translate complex security requirements into practical, developer-friendly architectures, tooling, and automated controls that integrate seamlessly into existing development and operations workflows, without creating friction
    • Operate as a hands-on technical leader who architects solutions and personally writes, reviews, and ships high-quality code and automation, not a delegator or reviewer only
    • Influence and drive cultural change across engineering and operations organizations, building trust, credibility, and shared ownership of security outcomes without relying on authority
    • Collaborate effectively across cross-functional teams, bridging cybersecurity, software development, DevOps, cloud engineering, compliance, and business stakeholders to deliver integrated, secure delivery capabilities
    • Communicate complex technical and security concepts clearly to both technical and non-technical audiences, including executive presentations, architecture reviews, and developer-facing documentation
    • Thrive in an Agile, fast-paced environment that values innovation, rapid iteration, and measurable security outcomes over process and bureaucracy
    • Demonstrate a passion for shifting security left, empowering developers and building a resilient, secure-by-default engineering culture that protects the enterprise while enabling speed and innovation

    Why work here?

    Thank you for choosing us as your employer of choice! If you are ready for an exciting opportunity working in a creative environment where you can bring your authentic self to work, we want to connect with you!

    Get In Touch

    If you''re unable to find a position that matches your interest, please tell us a little about yourself, and we''ll recommend jobs that match your interests.

    Get Started

    About Us

    Be Iconic represents the roots of our culture.

    The Seminole Tribe of Florida remains the only unconquered tribe in the United States of America. The Tribe established Seminole Gaming in 1979, when it opened the first high-stakes bingo hall in the United States. Building on its rich heritage of courageous and groundbreaking achievements, the Seminole Tribe of Florida acquired Hard Rock International in March 2007-the first transaction of its kind by a Native American tribe.

    Today, Hard Rock International remains one of the most globally recognized companies in the world, with Hard Rock Hotel, Casino, Cafe and Rock Shop venues in over 74 countries. With the continued growth of Seminole Gaming and Hard Rock International, Seminole Hard Rock Support Services was created to support all of our brands and lines of business.

    With the largest global footprint in the hospitality industry for over 50 years, our number-one job is to bring fun and excitement to our team members and our guests!

    Read More

    Follow Us

    *

    Privacy Policy

    2026 Workday, Inc. All rights reserved.

    Numbers & Facts

    LocationDavie, FL

    Skills

    • ARM (Advanced RISC Machine)unmatched
    • Advertisingunmatched
    • Agile Programming Methodologiesunmatched
    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Ansibleunmatched
    • Applications Securityunmatched
    • Architectural Servicesunmatched
    • Artificial Intelligence (AI)unmatched
    • Automationunmatched
    • Bill of Materials (BOM)unmatched
    • Bridge Buildingunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Casinosunmatched
    • Civil Engineeringunmatched
    • Cloud Applicationsunmatched
    • Cloud Architectureunmatched
    • Cloud Computingunmatched
    • Code Reviewsunmatched
    • Coding Standardsunmatched
    • Computer Securityunmatched
    • Content Managementunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Improvementunmatched
    • Continuous Integrationunmatched
    • Cookiesunmatched
    • Cross-Functionalunmatched
    • Cryptographyunmatched
    • Customer Support/Serviceunmatched
    • Data Collectionunmatched
    • Design Patterns Programming Methodologiesunmatched
    • DevOpsunmatched
    • Dockerunmatched
    • Documentationunmatched
    • Embedded Systemsunmatched
    • Emerging Technologyunmatched
    • Enterprise Architectureunmatched
    • Enterprise Protectionunmatched
    • Establish Prioritiesunmatched
    • Facebookunmatched
    • Gamingunmatched
    • GitHubunmatched
    • Go Programming Language (Golang)unmatched
    • Graphicsunmatched
    • HTML (HyperText Markup Language)unmatched
    • Hard Drivesunmatched
    • Hospitality and Tourismunmatched
    • IDE (Integrated Development Environment)unmatched
    • Identity Data Managementunmatched
    • Information/Data Security (InfoSec)unmatched
    • Infrastructure as a Service (IaaS)unmatched
    • Internet Securityunmatched
    • Internet Statisticsunmatched
    • Jenkinsunmatched
    • Linux Operating Systemunmatched
    • Machine Toolunmatched
    • Mail Processingunmatched
    • Maintain Complianceunmatched
    • Mentoringunmatched
    • Metricsunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows Operating Systemunmatched
    • Network Securityunmatched
    • Operations Security (OPSEC)unmatched
    • PCI-DSSunmatched
    • Penetration Testingunmatched
    • Performance Analysisunmatched
    • Performance Managementunmatched
    • Performance Metricsunmatched
    • Platform as a Service (PaaS)unmatched
    • Process Improvementunmatched
    • Process Modelingunmatched
    • Product Lifecycleunmatched
    • Program Evaluationunmatched
    • Prototypingunmatched
    • Python Programming/Scripting Languageunmatched
    • Quality Assurance Methodologyunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Regulatory Requirementsunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • Rock Mechanicsunmatched
    • Sales Pipelineunmatched
    • Sarbanes-Oxley Act (SOX)unmatched
    • Scripting (Scripting Languages)unmatched
    • Secure Codingunmatched
    • Security Architectureunmatched
    • Security Designunmatched
    • Security Monitoringunmatched
    • Security Policyunmatched
    • Service Level Agreement (SLA)unmatched
    • Social Mediaunmatched
    • Software Configuration Managementunmatched
    • Software Developmentunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software Engineeringunmatched
    • Software Testingunmatched
    • Standards Developmentunmatched
    • Statisticsunmatched
    • Supply Chainunmatched
    • Targeted Advertisingunmatched
    • Team Lead/Managerunmatched
    • Technical Leadershipunmatched
    • Test Automationunmatched
    • Test Toolsunmatched
    • Threat Modelingunmatched
    • Time Managementunmatched
    • Training Programunmatched
    • Training/Teachingunmatched
    • Trend Analysisunmatched
    • Twitterunmatched
    • User Interface/Experience (UI/UX)unmatched
    • Validation Testingunmatched
    • Web Browsersunmatched
    • Web Client Plug-insunmatched
    • Web Site Monitoringunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder