Platform / DevSecOps Engineer - Secure AI Systems
3M
- Location
- US, Minnesota, Maplewood
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 6 approvals (FY2023)
- Posted
- Sep 10, 2026
Skills
About this role
Job Description
Collaborate with Innovative 3Mers Around the World Collaborate with Innovative 3Mers Around the World Choosing where to start and grow your career has a major impact on your professional and personal life, so it’s equally important you know that the company that you choose to work at, and its leaders, will support and guide you. With a wide variety of people, global locations, technologies and products, 3M is a place where you can collaborate with other curious, creative 3Mers. This position provides an opportunity to transition from other private, public, government or military experience to a 3M career. The Impact You’ll Make in this Role As a Platform / DevSecOps Engineer - Secure AI Systems, you will be the principal hands-on owner of the secure platform foundation for a new -to-the-world AI architecture. You will design, build, automate, operate , secure, and ensure recoverability of an evolving environment that spans isolated cloud networks , hybrid infrastructure, and a future fully air-gapped on-premises platform. Working in partnership with the program's senior technical team, you will establish the foundation early, shape architecture decisions, and remain directly accountable for how the platform performs in real environments. Architecting and implementing scalable runtime components for real-time inference, near-real-time reasoning, large offline simulations, cloud services, on-premises deployments, and embedded or edge environments. Own the end-to-end operation of business-critical collaboration and software-development platforms, including the compute , storage, networking, database, and runner infrastructure supporting isolated and air-gapped environments. Establish, b uild , and operate the secure platform foundation, with accountability for availability, performance, capacity, cost, maintenance, and day-to-day reliability. Design and enforce Zero Trust boundaries across public, quarantine, DMZ, cloud, on-premises, developer , and internal application environments using segmentation, least-privilege access, and controlled ingress and egress. Administer GitHub Enterprise Server, including repositories, permissions, ephemeral Actions runners, audit logs, upgrades, backups, and disaster-recovery configurations. Integrate identity, privileged-access , secrets, key, and certificate services using federation, SAML, OIDC, RBAC, conditional access, credential rotation, and lifecycle controls. Design , develop and operate a controlled software-supply-chain pipeline that scans, validates , traces, and securely promotes trusted source code, packages, containers, firmware, and other artifacts into protected environments. Engineer geographically redundant backup, replication, restore, and failover capabilities across cloud and on-premises environments, with recovery proven through routine testing. Automate , monitor , and continuously secure the platform using reusable Terraform modules , scripting, centralized observability, vulnerability remediation, threat modeling and hunting , security reviews, threat detection . Lead major incident -response activities, including investigation, containment, recovery, root-cause analysis, and implementation of corrective actions . Your Skills and Expertise To set you up for success in this role from day one, 3M requires (at a minimum) the following qualifications: Bachelor's degree or higher in computer science, computer engineering, cybersecurity, or information systems (completed and verified prior to start) OR High School Diploma/GED (completed and verified prior to start) and seven ( 7) years of experience building, operating , automating, securing, or recovering business-critical technology platforms and infrastructure. AND Seven ( 7) years of