DevSecOps Engineer

Torch.AILeawood, KS
Hybrid

About The Position

We're looking for a mid-level DevSecOps Engineer to join our Platform Engineering team and embed security directly into our delivery pipeline. You'll own and extend our container scanning and patching workflows, harden our Kubernetes admission controls, and bring compliance-as-code practices to our DoD-aligned environments. This is a hands-on role: you'll be writing pipeline code, tuning policy engines, and working across AWS and Azure infrastructure — not auditing from the sidelines. Torch.AI builds a government-owned reasoning infrastructure which creates a Reasoning Layer to enable machine reasoning at scale, in environments where it is hardest to achieve and least tolerant of failure. This is not incremental software. It is long-term infrastructure designed to endure, integrate, and evolve alongside the systems it supports. The Reasoning Layer is a modular architecture where data is connected, governed, transformed, represented, fused, reasoned over, and delivered into mission applications and operational workflows. We are seeking candidates who approach problems creatively, are comfortable operating without full clarity, and take responsibility for outcomes, not just implementation. If you’re driven to strengthen U.S. defense readiness and protect national interests, Torch.AI offers meaningful impact at national scale. Torch.AI was founded on a simple operational insight: better use of data leads to better decisions. As data volumes increased across commercial, enterprise, and national security environments, the limiting factor was not collection, storage, or user interface design. The missing layer was machine understanding. And an infrastructure that could operate and reason between layers, preserve context, reconcile meaning, and make data useful for decisions in real time. We believe the government must own its data and decision environment. In mission and operational environments, the layer where data becomes context, context informs models, models support decisions, and decisions shape action cannot be controlled entirely by private technology vendors. Ownership does not mean the government must build every component itself. It means the government maintains stewardship and authority over the mission and operational layer. Commercial software, models, and services can contribute to the environment, but they should not capture the mission. We are craftsmen. We build with intention. We ship with discipline. You’ll collaborate with engineers, data experts, veterans, and mission practitioners. You’ll own meaningful work, move quickly, and see your systems deployed in production, often within weeks. We are fast-paced, entrepreneurial, and mission-driven. Every day is a new puzzle.

Requirements

  • 5-8 years of experience in DevSecOps, platform security, or infrastructure security engineering
  • Hands-on experience with container/image scanning tools (Grype, Trivy, or equivalent)
  • IaC security scanning experience (Checkov, tfsec, or equivalent)
  • Kubernetes admission control policy authoring (Kyverno or OPA/Gatekeeper)
  • CI/CD pipeline development with embedded security gates (GitHub Actions preferred)
  • Cloud IAM/identity hardening experience across AWS and Azure
  • U.S. citizenship is required for all positions.
  • Must be eligible to obtain and maintain an active Secret, Top Secret, or Top Secret/SCI clearance.

Nice To Haves

  • DoD compliance experience: STIGs, CKLB checklist automation, RMF/ATO process
  • Secrets management platform experience (HashiCorp Vault, Infisical, or similar)
  • SBOM generation and management (syft or equivalent)
  • Cosign/Sigstore image signing experience
  • Experience operating in airgapped or disconnected network environments
  • Active U.S. Government security clearance
  • CKS (Certified Kubernetes Security Specialist) certification
  • Security+ or equivalent (often required for DoD contract work)
  • Threat modeling experience
  • Experience routing infrastructure logs to a SIEM or centralized log analytics platform
  • CKA
  • CompTIA Security
  • CISSP, CISM, or the hands-on OSCP

Responsibilities

  • Own and extend our container image scanning and patching pipeline (Grype, Copa, Anchore Enterprise) integrated with GHCR and GitHub Actions
  • Build and maintain Kubernetes admission control policies (Kyverno) for image signature verification (cosign) across our AKS and EKS clusters
  • Translate DoD compliance requirements (STIG, CKLB, RMF) into automated, policy-as-code checks rather than manual checklist audits
  • Add security gates to CI/CD pipelines — IaC scanning, SBOM generation, secrets detection — across our Terragrunt/OpenTofu infrastructure
  • Harden cloud identity and access across AWS and Azure (IAM, Entra ID, Conditional Access)
  • Support security needs for airgapped/disconnected environments, including image transfer and validation pipelines
  • Partner with the platform team on Jira-tracked (PLAT project) security work and document policies in Confluence
  • Conduct vulnerability assessments and cybersecurity scans
  • Implement and maintain secure DevSecOps pipelines
  • Automate security testing and compliance reporting
  • Support deployments into AWS GovCloud, Azure Government, Cloud One, Platform One, and other government environments
  • Develop and maintain RMF accreditation documentation
  • Support ATO package preparation and approval activities
  • Establish continuous monitoring processes
  • Support classified environment integration and sustainment
  • Reduce cybersecurity risks across all software development efforts

Benefits

  • Competitive base salary
  • Quarterly performance bonuses
  • Equity participation within the first 12 months
  • Unlimited PTO + 11 paid company holidays
  • Professional development in a high-growth, mission-driven environment
  • Weekly in-office catering at HQ
  • 401(k) plan
  • PPO, HSA, and TRICARE Supplement medical options
  • Above-market HSA contributions
  • HSA, FSA, and Dependent Care FSA options
  • Dental and vision plans above national averages
  • Employer-paid life insurance (1× salary)
  • Employer-paid Short-Term and Long-Term Disability
  • Voluntary Accident, Critical Illness, and Hospital Indemnity coverage
  • Up to $300/month in tax-advantaged commuter benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service