> Markdown version of [/jobs/ext/2852668-platform-devsecops-engineer-secure-ai-systems](https://www.wearedevelopers.com/jobs/ext/2852668-platform-devsecops-engineer-secure-ai-systems). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform / DevSecOps Engineer - Secure AI Systems - **Company:** The 3M Company - **Location:** Maplewood, MN, United States - **Experience:** Experienced - **Salary:** $145,676.0 - $178,049.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Computing Platforms, Audit Trail, Microsoft Azure, Backup Devices, Bash Shell, Cloud Computing, Code Review, Cyber Security, Information Systems, Databases, Computer Engineering, Disaster Recovery, Firmware, Python (Programming Language), Routing, OpenID, OpenStack, Windows PowerShell, Scrum Methodology, Role-Based Access Control, Release Management, Reliability Engineering, Cloud Services, Zero Trust Network Access, Security Assertion Markup Language (SAML), Virtualization Technology, Software Vulnerability Management, Private Cloud Environment, Cloud-native Network Functions (CNF), Scripting, Google Cloud, IT Architecture, Kubernetes, Information Technology, Github Enterprise, Terraform, Network Server, Software Version Control, Devsecops, Vmware - **Published:** September 11, 2026 - **Apply:** https://3m.wd1.myworkdayjobs.com/Search/job/US-Minnesota-Maplewood/Platform---DevSecOps-Engineer---Secure-AI-Systems_R01170666-1 ## About the Role * Bachelor's degree or higher in computer science, computer engineering, cybersecurity, or information systems (completed and verified prior to start), * High School Diploma/GED (completed and verified prior to start) and seven (7) years of experience building, operating, automating, securing, or recovering business-critical technology platforms and infrastructure., * Seven (7) years of professional experience in platform engineering, DevSecOps, site reliability engineering, cloud infrastructure, infrastructure security, or a related field. * Three (3) years of hands on experience designing, deploying, and operating infrastructure using Terraform across public cloud (AWS, Azure, GCP) and private cloud/virtualization technologies (e.g., OpenStack, VMWare). * Three (3) years of production experience administering GitHub Enterprise Server or a comparable self-hosted software-development platform, including identity, permissions, automation runners, audit logging, upgrades, backup, and recovery. Additional qualifications that could help you succeed even further in this role include: * Three (3) years of scripting and software-development capability using scripting languages like Python, Bash, and/or PowerShell, with disciplined use of source control, code review, testing, release management, and documentation. * Hands-on experience designing, deploying, and managing highly scalable Kubernetes environments. * Hands-on experience building greenfield infrastructure platforms and operating critical systems in air-gapped, disconnected, or highly isolated production environments. * Experience serving as the technical owner of mission-critical production enterprise platforms supporting multiple engineering teams, including responsibility for architecture decisions, operational readiness, reliability, security, and disaster recovery. * Experience deploying and operating physical infrastructure, including servers, storage, networking, and virtualization platforms. * Experience designing and implementing systems that protect sensitive intellectual property or regulated information in environments such as trade-secret-intensive research, government, defense, healthcare, critical infrastructure, classified, or export-controlled programs. * Experience implementing and maintaining compliance controls aligned with cybersecurity frameworks such as NIST CSF, FedRAMP, CMMC, DoD STIGs, or comparable security standards. * A hands-on, low-ego working style; strong security judgment; comfort operating under ambiguity; and discretion when handling highly confidential or access-controlled intellectual property. * Experience working with Agile Scrum methodologies. ## Description As a Platform / DevSecOps Engineer - Secure AI Systems, you will be the principal hands-on owner of the secure platform foundation for a new-to-the-world AI architecture. You will design, build, automate, operate, secure, and ensure recoverability of an evolving environment that spans isolated cloud networks, hybrid infrastructure, and a future fully air-gapped on-premises platform. Working in partnership with the program's senior technical team, you will establish the foundation early, shape architecture decisions, and remain directly accountable for how the platform performs in real environments. Architecting and implementing scalable runtime components for real-time inference, near-real-time reasoning, large offline simulations, cloud services, on-premises deployments, and embedded or edge environments. * Own the end-to-end operation of business-critical collaboration and software-development platforms, including the compute, storage, networking, database, and runner infrastructure supporting isolated and air-gapped environments. * Establish, build, and operate the secure platform foundation, with accountability for availability, performance, capacity, cost, maintenance, and day-to-day reliability. * Design and enforce Zero Trust boundaries across public, quarantine, DMZ, cloud, on-premises, developer, and internal application environments using segmentation, least-privilege access, and controlled ingress and egress. * Administer GitHub Enterprise Server, including repositories, permissions, ephemeral Actions runners, audit logs, upgrades, backups, and disaster-recovery configurations. * Integrate identity, privileged-access, secrets, key, and certificate services using federation, SAML, OIDC, RBAC, conditional access, credential rotation, and lifecycle controls. * Design, develop and operate a controlled software-supply-chain pipeline that scans, validates, traces, and securely promotes trusted source code, packages, containers, firmware, and other artifacts into protected environments. * Engineer geographically redundant backup, replication, restore, and failover capabilities across cloud and on-premises environments, with recovery proven through routine testing. * Automate, monitor, and continuously secure the platform using reusable Terraform modules, scripting, centralized observability, vulnerability remediation, threat modeling and hunting, security reviews, threat detection. * Lead major incident-response activities, including investigation, containment, recovery, root-cause analysis, and implementation of corrective actions., All US-based 3M full time employees will need to sign an employee agreement as a condition of employment with 3M. This agreement lays out key terms on using 3M Confidential Information and Trade Secrets. It also has provisions discussing conflicts of interest and how inventions are assigned. Employees that are Job Grade 7 or equivalent and above may also have obligations to not compete against 3M or solicit its employees or customers, both during their employment, and for a period after they leave 3M. Learn more about 3M's creative solutions to the world's problems at www.3M.com or on Instagram, Facebook, and LinkedIn @3M. Responsibilities of this position include that corporate policies, procedures and security standards are complied with while performing assigned duties. Safety is a core value at 3M. All employees are expected to contribute to a strong Environmental Health and Safety (EHS) culture by following safety policies, identifying hazards, and engaging in continuous improvement. ## Related Videos - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer)