At a Glance
- Tasks: Secure and govern enterprise artifact management platforms in cloud environments.
- Company: Join a global leader in advancing essential intelligence with a diverse team.
- Benefits: Competitive salary, annual incentives, and comprehensive benefits package.
- Other info: Collaborative culture with opportunities for continuous learning and career growth.
- Why this job: Make a real impact on application security and AI governance in a dynamic environment.
- Qualifications: 3-6 years in DevSecOps or software supply chain security; strong hands-on experience required.
The predicted salary is between 63000 - 77000 £ per year.
About the Role
Grade Level (for internal use)
The Dev Sec Ops Engineer - Artifact Management & Software Supply Chain Security focuses on securing and governing enterprise artifact and dependency management platforms.
This role combines Dev Sec Ops, application security, and cloud security to ensure that build artifacts and dependencies are trusted, curated, and consumed securely across CI/CD pipelines and cloud environments.
Key Responsibilities
- Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments.
- Define and enforce package curation, promotion, and trust models aligned with application security and compliance requirements.
- Implement and govern waiver and approval workflows for dependency and artifact usage, ensuring risk-based decision-making.
- Partner with App Sec, platform, and engineering teams to standardize secure dependency and artifact consumption patterns.
- Define and maintain repository architectures supporting multiple environments, teams, and trust boundaries.
- Enforce policies ensuring artifact immutability, provenance, versioning, and trusted sourcing.
- Integrate artifact repositories into CI/CD pipelines built on Git Hub, Jenkins, and Azure Dev Ops.
- Embed security controls for AI/ML and Gen AI workloads within CI/CD pipelines and developer workflows.
- Define and enforce secure usage patterns for LLMs and AI services, including prompt handling, data protection, and model access controls.
- Implement safeguards against AI-specific threats, including prompt injection, model poisoning, data leakage, and insecure model outputs.
- Integrate AI security scanning and validation into build pipelines, ensuring safe model usage and dependency integrity.
- Collaborate with engineering teams to establish secure-by-design AI application architectures.
- Ensure compliance with enterprise Responsible AI policies (data privacy, bias management, model governance).
- Secure AI-related secrets, tokens, and API access used in pipelines and applications.
- Monitor and respond to security risks introduced by AI/ML components, including third-party models and APIs.
- Contribute to AI risk governance, auditability, and traceability across the SDLC.
- Stay current on emerging AI security threats, vulnerabilities, and regulatory expectations.
- Align artifact and dependency controls with cloud security best practices for deployed applications.
- Monitor usage, risk posture, and effectiveness of artifact controls and drive continuous improvement.
- Develop automation and policy-as-code for artifact lifecycle management, approvals, and governance.
- Support security incident investigations related to software supply chain integrity or dependency risk.
- Create documentation, standards, and enablement materials for secure developer adoption.
- Required Qualifications
- 3-6 years of experience in Dev Sec Ops, platform security, or software supply chain security.
- Strong hands-on experience with JFrog Artifactory, including deployment and enterprise architecture.
- Experience designing package curation and promotion models.
- Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle.
- Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage.
- Experience integrating AI or ML components into applications or pipelines (preferred hands-on exposure).
- Familiarity with Responsible AI principles and AI governance frameworks.
- Experience implementing waiver and approval workflows for dependencies and artifacts.
- Strong understanding of application security principles and dependency risk management.
- Hands-on experience integrating repositories with Git Hub, Jenkins, and Azure Dev Ops pipelines.
- Experience working in cloud environments (Azure preferred; AWS/GCP acceptable).
- Proficiency with automation and scripting (Python, Groovy, Terraform, etc.).
- Knowledge of modern SDLC and Dev Sec Ops operating models.
Compensation/Benefits Information
(This section is only applicable to US candidates) S&P Global states that the anticipated base salary range for this position is $125,000 to $165,000.
Final base salary for this role will be based on the individual's geographic location, as well as experience level, skill set, training, licenses and certifications.
In addition to base compensation, this role is eligible for an annual incentive plan.
This role is not eligible for additional compensation such as an annual incentive bonus or sales commission plan.
This role is eligible to receive additional S&P Global benefits.
For more information on the benefits we provide to our employees, please click here .
What's In It For You?
Our Mission
Advancing Essential Intelligence.
Our People
We're more than 35,000 strong worldwide-so we're able to understand nuances while having a broad perspective.
Our team is driven by curiosity and a shared belief that Essential Intelligence can help build a more prosperous future for us all.
- From finding new wa
- #J-18808-Ljbffr
Associate Director - Application Security in London employer: eFinancialCareers
As a leading global asset manager based in London, we pride ourselves on fostering a dynamic and inclusive work culture that values innovation and collaboration. Our employees benefit from comprehensive professional development opportunities, competitive compensation packages, and the chance to work with cutting-edge AI tools that enhance their skills and productivity. Join us to be part of a team that not only drives success but also prioritises employee well-being and growth in a vibrant city.
StudySmarter Expert Advice🤫
We think this is how you could land Associate Director - Application Security in London
✨Join Local Tech Meetups
Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at eFinancialCareers or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!
✨Contribute to Open Source Projects
Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to eFinancialCareers.
✨Tap into Online Developer Communities
Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like eFinancialCareers.
✨Explore Job Boards Specifically for Tech Roles
Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like eFinancialCareers that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!
We think you need these skills to ace Associate Director - Application Security in London
Some tips for your application 🫡
Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.
Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at eFinancialCareers.
Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at eFinancialCareers and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!
Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!
How to prepare for a job interview at eFinancialCareers
✨Brush Up on Your Coding Skills
For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.
✨Know Your Tools and Frameworks
Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If eFinancialCareers uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.
✨Showcase Your Projects
Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.
✨Prepare for Behavioural Questions
While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.