Service Core

2 jobs near Columbus, OH

Director of DevOps/SecOps

Denver, CO · On-site

$190 - $225/hr

Director of DevOps/SecOps ServiceCore is a leading field service software platform built for the ... Strong company culture aligned with core values: Love our Customers, Be Real, Give a Shit, Deliver ...

VAN DRIVER

Youngstown, OH · On-site

$15.50/hr

OVERVIEW: Responsible for providing safe, reliable and efficient transportation for residents. RESPONSIBILITIES: * Work with Transportation Supervisor to pre-plan and schedule transportation needs of ...

Director of DevOps/SecOps

Service Core

Denver, CO • On-site

$190 - $225/hr

Other

Medical, Dental, Vision, Retirement

Re-posted 27 days ago


Job description

Director of DevOps/SecOps

ServiceCore is a leading field service software platform built for the portable sanitation and roll‑off industries. We provide two SaaS products—ServiceCore for liquid waste operators and Docket for solid waste haulers—serving thousands of operators across North America.

About the role

We’re looking for a Director of Dev/SecOps to own the security posture and operational foundation across ServiceCore’s entire cloud environment. The role is security‑first, operating across AWS (ServiceCore) and GCP/Firebase (Docket), and includes AI tool governance.

What you’ll do AI Tool Governance & Security
  • Partner with the AI Council and Engineering Directors to build an AI tool evaluation framework—defining the security, privacy, and compliance criteria for new AI tools.
  • Govern multi‑LLM provider relationships—review data processing agreements, audit data retention policies, and ensure contractual protections for customer data.
  • Establish and enforce policies around data flow through AI services: PII boundaries, source code confidentiality rules, and customer data handling for coding assistants, LLM APIs, and agentic tools.
  • Secure MCP‑connected agents with least‑privilege access models, audit trails, and data egress controls.
  • Define secure patterns for integrating LLM capabilities into products—including prompt injection defenses, output validation, model access controls, and logging/observability.
  • Build and maintain an AI tool inventory with risk classifications and lead periodic reviews.
  • Partner with engineering and product to help obtain AI productivity benefits while managing risk.
Security Leadership
  • Own and continuously improve security posture across AWS and GCP/Firebase.
  • Lead threat modeling, vulnerability management, and security incident response programs.
  • Establish and enforce security policies, standards, and controls across the SDLC.
  • Champion a security‑first engineering culture.
  • Manage relationships with external auditors, penetration testers, and compliance bodies.
Compliance & Risk
  • Drive SOC 2 Type II compliance and own evidence collection across both platforms.
  • Manage PCI‑DSS considerations across payment processor integrations.
  • Build and maintain a risk register and prioritize risks to leadership.
  • Own third‑party vendor security reviews for 20+ integration partners, including AI vendors.
  • Monitor regulatory developments relevant to SaaS, AI, and the industries we serve.
DevOps & Platform Engineering
  • Secure CI/CD pipelines across both cloud environments—secrets management, dependency scanning, SAST/DAST.
  • Lead infrastructure‑as‑code strategy and embed security guardrails by default.
  • Own cloud security architecture.
  • Secure Cloudflare CDN/WAF configuration, DDoS posture, and DNS hygiene.
  • Drive incident response readiness—runbooks, on‑call processes, post‑mortems, and SLA accountability.
Team & Cross‑Functional Leadership
  • Hire, develop, and lead a DevSecOps team.
  • Collaborate with engineering leads on architectural decisions with security implications.
  • Report to senior leadership on security metrics, risk posture, compliance status, and AI tool governance.
  • Serve as the internal expert and educator on security and AI risk topics.
What you’ll bring
  • 10+ years of experience in DevOps, SecOps, or a combined DevSecOps role.
  • 3+ years in a leadership or management capacity with direct reports.
  • Deep hands‑on experience with AWS security—including IAM, VPC, ECS, Lambda, SQS, RDS, DynamoDB, Secrets Manager, CloudWatch, CloudFormation.
  • Meaningful experience with GCP and/or Firebase—including Firestore security rules, Cloud Functions security, GCP IAM, and service account management.
  • Experience owning or significantly contributing to SOC 2 Type II audits.
  • Strong background in securing CI/CD pipelines and containerized workloads (Docker, ECS, or EKS).
  • Demonstrated experience governing third‑party integrations and API security at scale.
  • Working knowledge of SAST, DAST, SCA, dependency scanning, and secrets management tooling.
  • Real point of view on AI tool security—understanding risks of coding assistants, LLM APIs, MCP‑connected agents, and AI in developer workflows.
  • Ability to communicate risk and security concepts clearly to non‑technical audiences and executives.
  • Background in SaaS with understanding of multi‑tenant security architecture.
Nice to have
  • Relevant certifications: CISSP, AWS Security Specialty, Google Professional Cloud Security Engineer, CCSP, or equivalent.
  • Experience with PCI‑DSS compliance in a SaaS context.
  • Familiarity with Cloudflare security features: WAF, Zero Trust, Workers, DDoS protection.
  • Experience securing PHP legacy applications alongside modern microservices.
  • Hands‑on experience with vector database security (e.g., Qdrant) or AI/ML pipeline security.
  • Experience defining data governance policies for AI tools in a software engineering organization.
  • Background building DevSecOps functions from scratch at a growth‑stage company.
Benefits & Compensation
  • Base Salary: $190,000–$225,000 (dependent on experience)
  • 14 company holidays plus an open time‑off policy.
  • Healthcare, dental and vision insurance with generous employer contributions.
  • 401(k) with match.
  • Regular lunches and a fully‑stocked kitchen (if in Denver).
  • Bi‑weekly Grubhub lunch stipend for remote employees.
  • Company‑provided hardware of your choice/configuration.
  • Strong company culture aligned with core values: Love our Customers, Be Real, Give a Shit, Deliver Results, and Keep it Fun.
#J-18808-Ljbffr