Platform / DevSecOps Engineer - Secure AI Systems

The 3M Company
Maplewood, MN, United States
19 days ago
Apply on 3m.wd1.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$145,676.0 - $178,049.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Computing Platforms Audit Trail Microsoft Azure Backup Devices Bash Shell Cloud Computing Code Review Cyber Security Information Systems Databases Computer Engineering
+29 more
Disaster Recovery Firmware Python (Programming Language) Routing OpenID OpenStack Windows PowerShell Scrum Methodology Role-Based Access Control Release Management Reliability Engineering Cloud Services Zero Trust Network Access Security Assertion Markup Language (SAML) Virtualization Technology Software Vulnerability Management Private Cloud Environment Cloud-native Network Functions (CNF) Scripting Google Cloud IT Architecture Kubernetes Information Technology Github Enterprise Terraform Network Server Software Version Control Devsecops Vmware

Job description

As a Platform / DevSecOps Engineer - Secure AI Systems, you will be the principal hands-on owner of the secure platform foundation for a new-to-the-world AI architecture. You will design, build, automate, operate, secure, and ensure recoverability of an evolving environment that spans isolated cloud networks, hybrid infrastructure, and a future fully air-gapped on-premises platform. Working in partnership with the program’s senior technical team, you will establish the foundation early, shape architecture decisions, and remain directly accountable for how the platform performs in real environments. Architecting and implementing scalable runtime components for real-time inference, near-real-time reasoning, large offline simulations, cloud services, on-premises deployments, and embedded or edge environments.

  • Own the end-to-end operation of business-critical collaboration and software-development platforms, including the compute, storage, networking, database, and runner infrastructure supporting isolated and air-gapped environments.

  • Establish, build, and operate the secure platform foundation, with accountability for availability, performance, capacity, cost, maintenance, and day-to-day reliability.

  • Design and enforce Zero Trust boundaries across public, quarantine, DMZ, cloud, on-premises, developer, and internal application environments using segmentation, least-privilege access, and controlled ingress and egress.

  • Administer GitHub Enterprise Server, including repositories, permissions, ephemeral Actions runners, audit logs, upgrades, backups, and disaster-recovery configurations.

  • Integrate identity, privileged-access, secrets, key, and certificate services using federation, SAML, OIDC, RBAC, conditional access, credential rotation, and lifecycle controls.

  • Design, develop and operate a controlled software-supply-chain pipeline that scans, validates, traces, and securely promotes trusted source code, packages, containers, firmware, and other artifacts into protected environments.

  • Engineer geographically redundant backup, replication, restore, and failover capabilities across cloud and on-premises environments, with recovery proven through routine testing.

  • Automate, monitor, and continuously secure the platform using reusable Terraform modules, scripting, centralized observability, vulnerability remediation, threat modeling and hunting, security reviews, threat detection.

  • Lead major incident-response activities, including investigation, containment, recovery, root-cause analysis, and implementation of corrective actions., All US-based 3M full time employees will need to sign an employee agreement as a condition of employment with 3M. This agreement lays out key terms on using 3M Confidential Information and Trade Secrets. It also has provisions discussing conflicts of interest and how inventions are assigned. Employees that are Job Grade 7 or equivalent and above may also have obligations to not compete against 3M or solicit its employees or customers, both during their employment, and for a period after they leave 3M.

Learn more about 3M’s creative solutions to the world’s problems at www.3M.com or on Instagram, Facebook, and LinkedIn @3M.

Responsibilities of this position include that corporate policies, procedures and security standards are complied with while performing assigned duties.

Safety is a core value at 3M. All employees are expected to contribute to a strong Environmental Health and Safety (EHS) culture by following safety policies, identifying hazards, and engaging in continuous improvement.

Requirements

  • Bachelor’s degree or higher in computer science, computer engineering, cybersecurity, or information systems (completed and verified prior to start), * High School Diploma/GED (completed and verified prior to start) and seven (7) years of experience building, operating, automating, securing, or recovering business-critical technology platforms and infrastructure., * Seven (7) years of professional experience in platform engineering, DevSecOps, site reliability engineering, cloud infrastructure, infrastructure security, or a related field.
  • Three (3) years of hands on experience designing, deploying, and operating infrastructure using Terraform across public cloud (AWS, Azure, GCP) and private cloud/virtualization technologies (e.g., OpenStack, VMWare).
  • Three (3) years of production experience administering GitHub Enterprise Server or a comparable self-hosted software-development platform, including identity, permissions, automation runners, audit logging, upgrades, backup, and recovery.

Additional qualifications that could help you succeed even further in this role include:

  • Three (3) years of scripting and software-development capability using scripting languages like Python, Bash, and/or PowerShell, with disciplined use of source control, code review, testing, release management, and documentation.
  • Hands-on experience designing, deploying, and managing highly scalable Kubernetes environments.
  • Hands-on experience building greenfield infrastructure platforms and operating critical systems in air-gapped, disconnected, or highly isolated production environments.
  • Experience serving as the technical owner of mission-critical production enterprise platforms supporting multiple engineering teams, including responsibility for architecture decisions, operational readiness, reliability, security, and disaster recovery.
  • Experience deploying and operating physical infrastructure, including servers, storage, networking, and virtualization platforms.
  • Experience designing and implementing systems that protect sensitive intellectual property or regulated information in environments such as trade-secret-intensive research, government, defense, healthcare, critical infrastructure, classified, or export-controlled programs.
  • Experience implementing and maintaining compliance controls aligned with cybersecurity frameworks such as NIST CSF, FedRAMP, CMMC, DoD STIGs, or comparable security standards.
  • A hands-on, low-ego working style; strong security judgment; comfort operating under ambiguity; and discretion when handling highly confidential or access-controlled intellectual property.
  • Experience working with Agile Scrum methodologies.

Benefits & conditions

Applicable to US Applicants Only:The expected compensation range for this position is $145,676 - $178,049, which includes base pay plus variable incentive pay, if eligible. This range represents a good faith estimate for this position. The specific compensation offered to a candidate may vary based on factors including, but not limited to, the candidate’s relevant knowledge, training, skills, work location, and/or experience. In addition, this position may be eligible for a range of benefits (e.g., Medical, Dental & Vision, Health Savings Accounts, Health Care & Dependent Care Flexible Spending Accounts, Disability Benefits, Life Insurance, Voluntary Benefits, Paid Absences and Retirement Benefits, etc.). Additional information is available at: https://www.3m.com/3M/en_US/careers-us/working-at-3m/benefits/.

About the company

Collaborate with Innovative 3Mers Around the World

Collaborate with Innovative 3Mers Around the World

Choosing where to start and grow your career has a major impact on your professional and personal life, so it’s equally important you know that the company that you choose to work at, and its leaders, will support and guide you. With a wide variety of people, global locations, technologies and products, 3M is a place where you can collaborate with other curious, creative 3Mers.

This position provides an opportunity to transition from other private, public, government or military experience to a 3M career.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on 3m.wd1.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo ¡ LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos ¡ LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo ¡ LIVE

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 ¡ World Congress 2025

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 ¡ Coffee With Developers

1:51 min

Overview of the three Google Maps routing applications

Germån Álvarez ¡ LIVE

Videos

See all

Related articles

See all