
Platform / DevSecOps Engineer - Secure AI Systems
3M · US, Minnesota, Maplewood
Job description
Job Description: Collaborate with Innovative 3Mers Around the World Collaborate with Innovative 3Mers Around the World Choosing where to start and grow your career has a major impact on your professional and personal life, so it’s equally important you know that the company that you choose to work at, and its leaders, will support and guide you. With a wide variety of people, global locations, technologies and products, 3M is a place where you can collaborate with other curious, creative 3Mers. This position provides an opportunity to transition from other private, public, government or military experience to a 3M career. The Impact You’ll Make in this Role As a Platform / DevSecOps Engineer - Secure AI Systems, you will be the principal hands-on owner of the secure platform foundation for a new-to-the-world AI architecture. You will design, build, automate, operate, secure, and ensure recoverability of an evolving environment that spans isolated cloud networks, hybrid infrastructure, and a future fully air-gapped on-premises platform. Working in partnership with the program's senior technical team, you will establish the foundation early, shape architecture decisions, and remain directly accountable for how the platform performs in real environments. Architecting and implementing scalable runtime components for real-time inference, near-real-time reasoning, large offline simulations, cloud services, on-premises deployments, and embedded or edge environments. Own the end-to-end operation of business-critical collaboration and software-development platforms, including the compute, storage, networking, database, and runner infrastructure supporting isolated and air-gapped environments. Establish, build, and operate the secure platform foundation, with accountability for availability, performance, capacity, cost, maintenance, and day-to-day reliability. Design and enforce Zero Trust boundaries across public, quarantine, DMZ, cloud, on-premises, developer, and internal application environments using segmentation, least-privilege access, and controlled ingress and egress. Administer GitHub Enterprise Server, including repositories, permissions, ephemeral Actions runners, audit logs, upgrades, backups, and disaster-recovery configurations. Integrate identity, privileged-access, secrets, key, and certificate services using federation, SAML, OIDC, RBAC, conditional access, credential rotation, and lifecycle controls. Design, develop and operate a controlled software-supply-chain pipeline that scans, validates, traces, and securely promotes trusted source code, packages, containers, firmware, and other artifacts into protected environments. Engineer geographically redundant backup, replication, restore, and failover capabilities across cloud and on-premises environments, with recovery proven through routine testing. Automate, monitor, and continuously secure the platform using reusable Terraform modules, scripting, centralized observability, vulnerability remediation, threat modeling and hunting, security reviews, threat detection. Lead major incident-response activities, including investigation, containment, recovery, root-cause analysis, and implementation of corrective actions. Your Skills and Expertise To set you up for success in this role from day one, 3M requires (at a minimum) the following qualifications: Bachelor's degree or higher in computer science, computer engineering, cybersecurity, or information systems (completed and verified prior to start) OR High School Diploma/GED (completed and verified prior to start) and seven (7) years of experience building, operating, automating, securing, or recovering business-critical technology platforms and infrastructure. AND Seven (7) years of professional experience in platform engineering, DevSecOps, site reliability engineering, cloud infrastructure, infrastructure security, or a related field. Three (3) years of hands on experience designing, deploying, and operating infrastructure using Terraform across public cloud (AWS, Azure, GCP) and private cloud/virtualization technologies (e.g., OpenStack, VMWare). Three (3) years of production experience administering GitHub Enterprise Server or a comparable self-hosted software-development platform, including identity, permissions, automation runners, audit logging, upgrades, backup, and recovery. Additional qualifications that could help you succeed even further in this role include: Three (3) years of scripting and software-development capability using scripting languages like Python, Bash, and/or PowerShell, with disciplined use of source control, code review, testing, release management, and documentation. Hands-on experience designing, deploying, and managing highly scalable Kubernetes environments. Hands-on experience building greenfield infrastructure platforms and operating critical systems in air-gapped, disconnected, or highly isolated production environments. Experience serving as the technical owner of mission-critical production enterprise platforms supporting multiple engineering teams, including responsibility for architecture decisions, operational readiness, reliability, security, and disaster recovery. Experience deploying and operating physical infrastructure, including servers, storage, networking, and virtualization platforms. Experience designing and implementing systems that protect sensitive intellectual property or regulated information in environments such as trade-secret-intensive research, government, defense, healthcare, critical infrastructure, classified, or export-controlled programs. Experience implementing and maintaining compliance controls aligned with cybersecurity frameworks such as NIST CSF, FedRAMP, CMMC, DoD STIGs, or comparable security standards. A hands-on, low-ego working style; strong security judgment; comfort operating under ambiguity; and discretion when handling highly confidential or access-controlled intellectual property. Experience working with Agile Scrum methodologies. Location: Onsite in 3M Center Maplewood, MN Travel: May include up to 5% travel Relocation Benefits: May be offered Must be legally authorized to work in country of employment without sponsorship for employment visa status (e.g., H1B status). Supporting Your Well-being 3M offers many programs to help you live your best life – both physically and financially. To ensure competitive pay and benefits, 3M regularly benchmarks with other companies that are comparable in size and scope. Chat with Max For assistance with searching through our current job openings or for more information about all things 3M, visit Max, our virtual recruiting assistant on 3M.com/careers. Applicable to US Applicants Only:The expected compensation range for this position is $145,676 - $178,049, which includes base pay plus variable incentive pay, if eligible. This range represents a good faith estimate for this position. The specific compensation offered to a candidate may vary based on factors including, but not limited to, the candidate’s relevant knowledge, training, skills, work location, and/or experience. In addition, this position may be eligible for a range of benefits (e.g., Medical, Dental & Vision, Health Savings Accounts, Health Care & Dependent Care Flexible Spending Accounts, Disability Benefits, Life Insurance, Voluntary Benefits, Paid Absences and Retirement Benefits, etc.). Additional information is available at: https://www.3m.com/3M/en_US/careers-us/working-at-3m/benefits/. Good Faith Posting Date Range 09/10/2026 To 10/10/2026 Or until filled All US-based 3M full time employees will need to sign an employee agreement as a condition of employment with 3M. This agreement lays out key terms on using 3M Confidential Information and Trade Secrets. It also has provisions discussing conflicts of interest and how inventions are assigned. Employees that are Job Grade 7 or eq
Verified and listed by ActiveJobs. Applications are made directly on 3M's own career page — we never sit in the middle.