> Markdown version of [/jobs/ext/2519035-sec-ops-architect-i](https://www.wearedevelopers.com/jobs/ext/2519035-sec-ops-architect-i). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sec Ops Architect I - **Company:** o9 Solutions - **Location:** Dallas, TX, United States - **Experience:** Expert - **Salary:** $169,793.0 - $233,466.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Application Integration Architecture, Audit Trail, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Information Engineering, DevOps, Elasticsearch, Intrusion Detection and Prevention, Python (Programming Language), Machine Learning, Open Web Application Security, Tensorflow, Red Team (Cyber Security), Zero Trust Network Access, Security Information and Event Management, Software Engineering, Data Streaming, Google Cloud, Cloud Platform System, Data Classification, Pytorch, Large Language Models, Multi-Agent Systems, Prompt Engineering, Apache Spark, Mitre Att&ck, Model Validation, Cyber Threat Analysis, AI Platforms, Scikit Learn, Kubernetes, Information Technology, Cybercrime, Xgboost, Apache Kafka, Machine Learning Operations, Virtual Agents, Data Pipelines, Devsecops, Security Orchestration, Automation & Response - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f236fd1058d34cfc ## About the Role * 10+ Years Overall: Progressive hands-on experience in cybersecurity engineering, AI security, or security data science - with a foundational identity as a software engineer who developed deep security expertise. * 3+ Years AI Security / MLSecOps: Proven experience in AI platform security (agent governance, model risk, RAG security) or building and operationalising ML models for security use cases at production scale. * AI Agent Engineering: Demonstrated experience building autonomous agents using frameworks such as CrewAI, LangChain, LangGraph, or equivalent - including tool-use, multi-agent orchestration, and agent observability. * Security Platform Depth: Hands-on experience with enterprise security platforms - EDR, NG-SIEM, SOAR, WAF/ZTNA, PAM, or equivalents at comparable scale. * Cloud & Kubernetes: Deep experience securing large-scale containerised environments across AWS, Azure, and GCP - with exposure to multi-tenant SaaS architectures. Technical Skills * Languages & Data Engineering: Python for ML model development, pipeline authoring, and security automation. Streaming and batch platforms (Spark, Kafka, Elasticsearch, or equivalent). * ML Frameworks & LLM Integration: ML frameworks (scikit-learn, XGBoost, PyTorch) and LLM/agent orchestration (LangChain, CrewAI). Experience integrating LLM APIs into security workflows via prompt engineering and RAG pipelines. * Security Frameworks: MITRE ATT&CK, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI RMF, ISO 42001, ISO 27001. Ability to map AI risks and ML model outputs to specific TTPs. * Observability & MLOps: ML model lifecycle management (MLflow or equivalent), experiment tracking, model drift detection, and production monitoring for security ML models. Education & Certifications * Education: Bachelor's in Computer Science, Software Engineering, or related discipline required; Master's in CS, Data Science, AI, or Cybersecurity highly preferred. * Certifications: Relevant certifications are a strong plus: cloud security specialties (AWS/Azure/GCP), CISM, MITRE ATT&CK Defender, or SANS AI/ML security courses. We value demonstrated hands-on capability over certification count. ## Description Own the security architecture for o9's GenAI platform - ensuring every AI agent, model, and integration is governed, auditable, and stoppable. * AI Agent Security Architecture: Design and enforce agent identity controls, permission scoping, and behavioural baselining for all production AI agents. Build UEBA-style models that detect when an agent deviates from learned tool-call patterns, data-access scope, or egress destinations - triggering automated containment via kill-switch controls. * AI SBOM & Model Risk Management: Architect the AI Bill of Materials (AIBOM/SBOM) pipeline - model provenance verification, hash integrity, dependency scanning, and supply chain trust for every LLM, embedding model, and agent deployed to production. Ensure no model reaches production without a signed inventory entry. * RAG & Prompt Security: Design security controls for retrieval-augmented generation pipelines - source allowlisting, tenant isolation, PII scrubbing, indirect prompt injection detection, and embedding anomaly monitoring. Secure the retrieval boundary as the highest-risk component in the AI stack. * Cross-System AI Integration Security: Define security review gates for AI integrations with enterprise systems (ticketing, DevOps, observability, MCP servers). Enforce token governance, credential rotation, blast-radius modelling, and data classification for every cross-system data flow. * AI Governance & Compliance: Align AI security controls to ISO 42001, NIST AI RMF, MITRE ATLAS, and OWASP Top 10 for LLM Applications. Maintain audit trails for every model decision. Support EU AI Act and DPDPA compliance evidence generation. AI/ML Engineering for Security Operations Build ML models and autonomous agents that convert raw security telemetry into predictive, actionable defence. * Threat Detection & Anomaly Modelling: Build, fine-tune, and deploy ML models that detect anomalous patterns, novel attack variations, and stealthy TTPs mapped to MITRE ATT&CK across the full telemetry corpus - including predictive weak-point analysis that scores which assets or identities are most likely to be exploited next. * Autonomous Security Agents: Architect and build the autonomous security agent layer - threat-hunting agents, vulnerability-management agents, configuration-audit agents, and incident-response agents operating at machine speed. Define full observability: reasoning traces, tool calls, results, and outputs - tamper-proof and forensically auditable. * LLM-Powered SOAR & Enrichment: Evolve SOAR playbooks from rule-based automation to ML-driven, context-aware orchestration - integrating LLM-based enrichment into triage and response decision loops. Reduce false-positive rates (target: <20%) while preserving detection fidelity. * Identity Threat Scoring: Build ML-powered identity risk scoring on top of identity protection telemetry - reducing identity threat risk scores and maintaining them autonomously through continuous model retraining from red team findings. Security Telemetry & Platform Operations Ensure scalable, real-time security visibility across o9's entire infrastructure and customer environment footprint. * Telemetry Pipeline Architecture: Design scalable, real-time pipelines that ingest, normalise, and correlate high-velocity security telemetry from EDR, WAF/ZTNA, PAM, cloud environments (AWS, Azure, GCP), and DevOps toolchains into a unified, enriched security data model. * Detection Engineering & Correlation: Build cross-platform correlation logic joining identity signals, endpoint behavioural data, network events, and privileged-access telemetry. Author detection rules and tuning frameworks that reduce noise while preserving true-positive fidelity. * Shift-Left DevSecOps: Embed security telemetry and policy-as-code requirements into the CI/CD pipeline so every new service, agent, and integration is observable from day one - not instrumented retrospectively. Integrate ML enrichment into vulnerability exposure scoring with predictive remediation prioritisation. Technical Leadership & Research * Architecture Authority: Serve as the technical authority for AI security and MLSecOps across the security programme - defining standards, reviewing architectures, and raising AI security maturity across the organisation. * Research & Innovation: Evaluate emerging AI security techniques (agent-based threat hunting, LLM-powered forensics, graph-ML for lateral movement detection, neurosymbolic trust boundaries) and translate research into production capabilities. * Mentorship: Coach security engineers in ML/AI fundamentals and ML engineers in security domain knowledge - building a team that bridges both disciplines. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [TikTok's Privacy Innovation](https://www.wearedevelopers.com/videos/1036-tiktok-s-privacy-innovation) - [Photonic Computing: Programming a New Class of AI Accelerators (incl. Live Coding)](https://www.wearedevelopers.com/videos/100196-photonic-computing-programming-a-new-class-of-ai-accelerators-incl-live-coding) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Explainable machine learning explained](https://www.wearedevelopers.com/videos/589-explainable-machine-learning-explained) - [Serverless deployment of (large) NLP models ](https://www.wearedevelopers.com/videos/158-serverless-deployment-of-large-nlp-models) ## Related Articles - [MLOps – What’s the deal behind it?](https://www.wearedevelopers.com/magazine/125-mlops-what-s-the-deal-behind-it) - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)