Skip to content
Skip to content
DevOps Jobs
Torch.AI

DevSecOps Engineer

Torch.AI

Location
Hybrid (LEAWOOD, KS)
Level
Senior Level
Posted 2 days ago

About the Role

Torch.AI builds government-owned reasoning infrastructure to enable machine reasoning at scale for national security missions. This role embeds security directly into the delivery pipeline, owning container scanning, Kubernetes policy, and DoD compliance automation.

Skills

DevSecOps Kubernetes AWS Azure Container Scanning IaC Scanning CI/CD Pipelines Cloud IAM Policy-as-Code RMF/ATO Process STIGs GitHub Actions Kyverno Terraform Secrets Management SBOM Generation

Benefits

  • 401(k)
  • Medical
  • Dental
  • Vision
  • Life Insurance
  • Disability
  • Unlimited PTO

Perks

  • Equity
  • Bonuses
  • Catering

Full job details

Job DetailsJob Location: HQ - LEAWOOD, KS 66211Position Type: Full-Time - Clearance EligibleThe world’s most consequential systems need the world’s best builders. A new era is taking shape. AI is no longer confined to models or interfaces. It is becoming the foundation of how decisions are made across governments, industries, and real-world environments. What matters now is not just access to capability, but how it is applied, controlled, and sustained over time. Torch.AI builds a government-owned reasoning infrastructure which creates a Reasoning Layer to enable machine reasoning at scale, in environments where it is hardest to achieve and least tolerant of failure. This is not incremental software. It is long-term infrastructure designed to endure, integrate, and evolve alongside the systems it supports. Not another dashboard. Not another workflow app. Not another black-box model glued to a PowerPoint. The Reasoning Layer is a modular architecture where data is connected, governed, transformed, represented, fused, reasoned over, and delivered into mission applications and operational workflows. It does not replace systems of record. It enables them to function better together. The Reasoning Layer is comprised of: ORCUS (ingestion, orchestration, governance), NEXUS (semantic representation, vectorization), HALO (graph-based fusion and reasoning) and various product and capability components deployed for specific customer use cases. We are seeking candidates who approach problems creatively, are comfortable operating without full clarity, and take responsibility for outcomes, not just implementation. If you’re driven to strengthen U.S. defense readiness and protect national interests, Torch.AI offers meaningful impact at national scale. What Makes Torch.AI Different Torch.AI was founded on a simple operational insight: better use of data leads to better decisions. As data volumes increased across commercial, enterprise, and national security environments, the limiting factor was not collection, storage, or user interface design. The missing layer was machine understanding. And an infrastructure that could operate and reason between layers, preserve context, reconcile meaning, and make data useful for decisions in real time. We believe the government must own its data and decision environment. In mission and operational environments, the layer where data becomes context, context informs models, models support decisions, and decisions shape action cannot be controlled entirely by private technology vendors. Ownership does not mean the government must build every component itself. It means the government maintains stewardship and authority over the mission and operational layer. Commercial software, models, and services can contribute to the environment, but they should not capture the mission. We are craftsmen. We build with intention. We ship with discipline. You’ll collaborate with engineers, data experts, veterans, and mission practitioners. You’ll own meaningful work, move quickly, and see your systems deployed in production, often within weeks. We are fast-paced, entrepreneurial, and mission-driven. Every day is a new puzzle. The Type of Candidates Who Thrive People who do well here tend to approach problems similarly. They are comfortable operating without full clarity. They pay attention to what actually happens, not just what was intended. They are willing to be wrong, adjust quickly, and improve based on real feedback. They take responsibility for outcomes, not just implementation. This is not a good fit for someone who needs tightly defined problems or prefers distance from how their work is used. Security Clearance Some roles require an active Secret, Top Secret, or Top Secret/SCI clearance. Where required, candidates must be eligible to obtain and maintain the appropriate clearance level. U.S. citizenship is required for all positions. Torch.AI does not sponsor employment visas. If you do not currently hold a clearance but are eligible, sponsorship may be available depending on role and mission requirements. Work Location Most roles are based at our headquarters in Leawood, KS. Some hybrid/remote positions across the Arlington, VA, Washington, DC, and Maryland (DMV) region are available. Limited travel (<10%) may be required for some roles. Compensation, Benefits, Incentives We offer competitive, performance-aligned compensation tied to technical depth, clearance level, and mission impact. Total Rewards Include: Competitive base salary Quarterly performance bonuses Equity participation within the first 12 months Unlimited PTO + 11 paid company holidays Professional development in a high-growth, mission-driven environment Weekly in-office catering at HQ Benefits: 401(k) plan (no current employer match, but under consideration) PPO, HSA, and TRICARE Supplement medical options Above-market HSA contributions HSA, FSA, and Dependent Care FSA options Dental and vision plans above national averages Employer-paid life insurance (1× salary) Employer-paid Short-Term and Long-Term Disability Voluntary Accident, Critical Illness, and Hospital Indemnity coverage Up to $300/month in tax-advantaged commuter benefits Torch.AI is an Equal Opportunity / Affirmative Action Employer committed to building a team that reflects the mission we serve. If you want to build AI systems that move from ingestion to actionable insight and know exactly why they produced the answer they did, we should talk.QualificationsPosition Summary  We're looking for a mid-level DevSecOps Engineer to join our Platform Engineering team and embed security directly into our delivery pipeline. You'll own and extend our container scanning and patching workflows, harden our Kubernetes admission controls, and bring compliance-as-code practices to our DoD-aligned environments. This is a hands-on role: you'll be writing pipeline code, tuning policy engines, and working across AWS and Azure infrastructure — not auditing from the sidelines.  What You'll Do  Own and extend our container image scanning and patching pipeline (Grype, Copa, Anchore Enterprise) integrated with GHCR and GitHub Actions  Build and maintain Kubernetes admission control policies (Kyverno) for image signature verification (cosign) across our AKS and EKS clusters  Translate DoD compliance requirements (STIG, CKLB, RMF) into automated, policy-as-code checks rather than manual checklist audits  Add security gates to CI/CD pipelines — IaC scanning, SBOM generation, secrets detection — across our Terragrunt/OpenTofu infrastructure  Harden cloud identity and access across AWS and Azure (IAM, Entra ID, Conditional Access)  Support security needs for airgapped/disconnected environments, including image transfer and validation pipelines  Partner with the platform team on Jira-tracked (PLAT project) security work and document policies in Confluence  Conduct vulnerability assessments and cybersecurity scans  Implement and maintain secure DevSecOps pipelines  Automate security testing and compliance reporting  Support deployments into AWS GovCloud, Azure Government, Cloud One, Platform One, and other government environments  Develop and maintain RMF accreditation documentation  Support ATO package preparation and approval activities  Establish continuous monitoring processes  Support classified environment integration and sustainment  Reduce cybersecurity risks across all software development efforts  Position Goals  Accelerate deployment into government cloud environments  Reduce time required to obtain ATO approvals  Support deployments into classified operational networks  Improve competitiveness on government proposals  Reduce cybersecurity-related program risk  Increase customer confidence in operational deployments  Establish reusable accreditation and deployment processes across multiple programs  Must-Have Skills  5-8 years of experience in DevSecOps, platform security, or infrastructure security engineering  Hands-on experience with container/image scanning tools (Grype, Trivy, or equivalent)  IaC security scanning experience (Checkov, tfsec, or equivalent)  Kubernetes admission control policy authoring (Kyverno or OPA/Gatekeeper)  CI/CD pipeline development with embedded security gates (GitHub Actions preferred)  Cloud IAM/identity hardening experience across AWS and Azure  Strong Differentiators  DoD compliance experience: STIGs, CKLB checklist automation, RMF/ATO process  Secrets management platform experience (HashiCorp Vault, Infisical, or similar)  SBOM generation and management (syft or equivalent)  Cosign/Sigstore image signing experience  Experience operating in airgapped or disconnected network environments  Nice to Have  Active U.S. Government security clearance  CKS (Certified Kubernetes Security Specialist) certification  Security+ or equivalent (often required for DoD contract work)  Threat modeling experience  Experience routing infrastructure logs to a SIEM or centralized log analytics platform  CKS or CKA  CompTIA Security  CISSP, CISM, or the hands-on OSCP