DevSecOps Engineer
Don't apply into the void.
Most applications for this TORCH.AI role vanish into an ATS. With jobfinder-ai, your agent finds the actual hiring manager or founder behind this opening and sends a tailored email from your own inbox — so a real person reads your pitch and replies. We then follow up until you land on the calendar.
Reach the decision-maker — $5About the role
**The world’s most consequential systems need the world’s best builders.**
A new era is taking shape. AI is no longer confined to models or interfaces. It is becoming the foundation of how decisions are made across governments, industries, and real\-world environments. What matters now is not just access to capability, but how it is applied, controlled, and sustained over time.
Torch.AI builds a government\-owned reasoning infrastructure which creates a Reasoning Layer to enable machine reasoning at scale, in environments where it is hardest to achieve and least tolerant of failure. This is not incremental software. It is long\-term infrastructure designed to endure, integrate, and evolve alongside the systems it supports.
Not another dashboard. Not another workflow app. Not another black\-box model glued to a PowerPoint.
The Reasoning Layer is a modular architecture where data is connected, governed, transformed, represented, fused, reasoned over, and delivered into mission applications and operational workflows. It does not replace systems of record. It enables them to function better together.
The Reasoning Layer is comprised of: ORCUS (ingestion, orchestration, governance), NEXUS (semantic representation, vectorization), HALO (graph\-based fusion and reasoning) and various product and capability components deployed for specific customer use cases.
We are seeking candidates who approach problems creatively, are comfortable operating without full clarity, and take responsibility for outcomes, not just implementation.
If you’re driven to strengthen U.S. defense readiness and protect national interests, Torch.AI offers meaningful impact at national scale.
**What Makes Torch.AI Different**
Torch.AI was founded on a simple operational insight: better use of data leads to better decisions. As data volumes increased across commercial, enterprise, and national security environments, the limiting factor was not collection, storage, or user interface design. The missing layer was machine understanding. And an infrastructure that could operate and reason between layers, preserve context, reconcile meaning, and make data useful for decisions in real time.
We believe the government must own its data and decision environment. In mission and operational environments, the layer where data becomes context, context informs models, models support decisions, and decisions shape action cannot be controlled entirely by private technology vendors.
Ownership does not mean the government must build every component itself. It means the government maintains stewardship and authority over the mission and operational layer. Commercial software, models, and services can contribute to the environment, but they should not capture the mission.
We are craftsmen.
We build with intention.
We ship with discipline.
You’ll collaborate with engineers, data experts, veterans, and mission practitioners. You’ll own meaningful work, move quickly, and see your systems deployed in production, often within weeks.
We are fast\-paced, entrepreneurial, and mission\-driven. Every day is a new puzzle.
**The Type of Candidates Who Thrive**
People who do well here tend to approach problems similarly.
* They are comfortable operating without full clarity. * They pay attention to what actually happens, not just what was intended. * They are willing to be wrong, adjust quickly, and improve based on real feedback. * They take responsibility for outcomes, not just implementation.
This is not a good fit for someone who needs tightly defined problems or prefers distance from how their work is used.
**Security Clearance**
Some roles require an active **Secret, Top Secret, or Top Secret/SCI** clearance. Where required, candidates must be eligible to obtain and maintain the appropriate clearance level.
U.S. citizenship is required for all positions. Torch.AI does not sponsor employment visas.
If you do not currently hold a clearance but are eligible, sponsorship may be available depending on role and mission requirements.
**Work Location**
Most roles are based at our headquarters in Leawood, KS. Some hybrid/remote positions across the Arlington, VA, Washington, DC, and Maryland (DMV) region are available. Limited travel (\<10%) may be required for some roles.
**Compensation, Benefits, Incentives**
We offer competitive, performance\-aligned compensation tied to technical depth, clearance level, and mission impact.
Total Rewards Include:
* Competitive base salary * Quarterly performance bonuses * Equity participation within the first 12 months * Unlimited PTO \+ 11 paid company holidays * Professional development in a high\-growth, mission\-driven environment * Weekly in\-office catering at HQ
Benefits:
* 401(k) plan (no current employer match, but under consideration) * PPO, HSA, and TRICARE Supplement medical options * Above\-market HSA contributions * HSA, FSA, and Dependent Care FSA options * Dental and vision plans above national averages * Employer\-paid life insurance (1× salary) * Employer\-paid Short\-Term and Long\-Term Disability * Voluntary Accident, Critical Illness, and Hospital Indemnity coverage * Up to $300/month in tax\-advantaged commuter benefits
Torch.AI is an Equal Opportunity / Affirmative Action Employer committed to building a team that reflects the mission we serve.
If you want to build AI systems that move from ingestion to actionable insight and know exactly why they produced the answer they did, we should talk.
Position Summary
We're looking for a mid\-level DevSecOps Engineer to join our Platform Engineering team and embed security directly into our delivery pipeline. You'll own and extend our container scanning and patching workflows, harden our Kubernetes admission controls, and bring compliance\-as\-code practices to our DoD\-aligned environments. This is a hands\-on role: you'll be writing pipeline code, tuning policy engines, and working across AWS and Azure infrastructure — not auditing from the sidelines.
What You'll Do
* Own and extend our container image scanning and patching pipeline (Grype, Copa, Anchore Enterprise) integrated with GHCR and GitHub Actions * Build and maintain Kubernetes admission control policies (Kyverno) for image signature verification (cosign) across our AKS and EKS clusters * Translate DoD compliance requirements (STIG, CKLB, RMF) into automated, policy\-as\-code checks rather than manual checklist audits * Add security gates to CI/CD pipelines — IaC scanning, SBOM generation, secrets detection — across our Terragrunt/OpenTofu infrastructure * Harden cloud identity and access across AWS and Azure (IAM, Entra ID, Conditional Access) * Support security needs for airgapped/disconnected environments, including image transfer and validation pipelines * Partner with the platform team on Jira\-tracked (PLAT project) security work and document policies in Confluence * Conduct vulnerability assessments and cybersecurity scans * Implement and maintain secure DevSecOps pipelines * Automate security testing and compliance reporting * Support deployments into AWS GovCloud, Azure Government, Cloud One, Platform One, and other government environments * Develop and maintain RMF accreditation documentation * Support ATO package preparation and approval activities * Establish continuous monitoring processes * Support classified environment integration and sustainment * Reduce cybersecurity risks across all software development efforts
Position Goals
* Accelerate deployment into government cloud environments * Reduce time required to obtain ATO approvals * Support deployments into classified operational networks * Improve competitiveness on government proposals * Reduce cybersecurity\-related program risk * Increase customer confidence in operational deployments * Establish reusable accreditation and deployment processes across multiple programs
Must\-Have Skills
* 5\-8 years of experience in DevSecOps, platform security, or infrastructure security engineering * Hands\-on experience with container/image scanning tools (Grype, Trivy, or equivalent) * IaC security scanning experience (Checkov, tfsec, or equivalent) * Kubernetes admission control policy authoring (Kyverno or OPA/Gatekeeper) * CI/CD pipeline development with embedded security gates (GitHub Actions preferred) * Cloud IAM/identity hardening experience across AWS and Azure
Strong Differentiators
* DoD compliance experience: STIGs, CKLB checklist automation, RMF/ATO process * Secrets management platform experience (HashiCorp Vault, Infisical, or similar) * SBOM generation and management (syft or equivalent) * Cosign/Sigstore image signing experience * Experience operating in airgapped or disconnected network environments
Nice to Have
* Active U.S. Government security clearance * CKS (Certified Kubernetes Security Specialist) certification * Security\+ or equivalent (often required for DoD contract work) * Threat modeling experience * Experience routing infrastructure logs to a SIEM or centralized log analytics platform * CKS or CKA * CompTIA Security * CISSP, CISM, or the hands\-on OSCP
Ready to reach the decision-maker?
Set this role as a target and your agent does the sourcing, finds the verified email, writes the pitch, and follows up — on autopilot.
Start your hunt