At a Glance
- Tasks: Secure and govern enterprise artifact management platforms in a dynamic DevSecOps environment.
- Company: Join a leading global firm committed to innovation and essential intelligence.
- Benefits: Enjoy competitive pay, health coverage, flexible time off, and continuous learning opportunities.
- Other info: Collaborative culture with excellent career growth and global opportunities.
- Why this job: Make a real impact by enhancing security in AI and software supply chains.
- Qualifications: 3-6 years in DevSecOps or application security; strong understanding of AI/ML concepts.
The predicted salary is between 100000 - 130000 £ per year.
The DevSecOps Engineer – Artifact Management & Software Supply Chain Security focuses on securing and governing enterprise artifact and dependency management platforms. This role combines DevSecOps, application security, and cloud security to ensure that build artifacts and dependencies are trusted, curated, and consumed securely across CI/CD pipelines and cloud environments.
Key Responsibilities
- Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments.
- Define and enforce package curation, promotion, and trust models aligned with application security and compliance requirements.
- Implement and govern waiver and approval workflows for dependency and artifact usage, ensuring risk-based decision‑making.
- Partner with AppSec, platform, and engineering teams to standardize secure dependency and artifact consumption patterns.
- Define and maintain repository architectures supporting multiple environments, teams, and trust boundaries.
- Enforce policies ensuring artifact immutability, provenance, versioning, and trusted sourcing.
- Integrate artifact repositories into CI/CD pipelines built on GitHub, Jenkins, and Azure DevOps.
- Embed security controls for AI/ML and GenAI workloads within CI/CD pipelines and developer workflows.
- Define and enforce secure usage patterns for LLMs and AI services, including prompt handling, data protection, and model access controls.
- Implement safeguards against AI-specific threats, including prompt injection, model poisoning, data leakage, and insecure model outputs.
- Integrate AI security scanning and validation into build pipelines, ensuring safe model usage and dependency integrity.
- Collaborate with engineering teams to establish secure-by-design AI application architectures.
- Ensure compliance with enterprise Responsible AI policies (data privacy, bias management, model governance).
- Secure AI-related secrets, tokens, and API access used in pipelines and applications.
- Monitor and respond to security risks introduced by AI/ML components, including third-party models and APIs.
- Contribute to AI risk governance, auditability, and traceability across the SDLC.
- Stay current on emerging AI security threats, vulnerabilities, and regulatory expectations.
- Align artifact and dependency controls with cloud security best practices for deployed applications.
- Monitor usage, risk posture, and effectiveness of artifact controls and drive continuous improvement.
- Develop automation and policy‑as‑code for artifact lifecycle management, approvals, and governance.
- Support security incident investigations related to software supply chain integrity or dependency risk.
- Create documentation, standards, and enablement materials for secure developer adoption.
Required Qualifications
- Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or equivalent experience.
- 3–6 years of experience in DevSecOps, platform security, or software supply chain security.
- Strong hands-on experience with JFrog Artifactory, including deployment and enterprise architecture.
- Experience designing package curation and promotion models.
- Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle.
- Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage.
- Experience integrating AI or ML components into applications or pipelines (preferred hands-on exposure).
- Familiarity with Responsible AI principles and AI governance frameworks.
- Experience implementing waiver and approval workflows for dependencies and artifacts.
- Strong understanding of application security principles and dependency risk management.
- Hands-on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines.
- Experience working in cloud environments (Azure preferred; AWS/GCP acceptable).
- Proficiency with automation and scripting (Python, Groovy, Terraform, etc.).
- Knowledge of modern SDLC and DevSecOps operating models.
Associate Director - Application Security in London employer: OSTTRA
S&P Global is an exceptional employer that prioritises the well-being and growth of its employees, offering a dynamic work culture that fosters collaboration and innovation. With a commitment to continuous learning and a range of comprehensive benefits, including health coverage, flexible downtime, and family-friendly perks, employees are empowered to thrive both personally and professionally. Located in a vibrant environment, S&P Global provides unique opportunities to engage with cutting-edge technology and make a meaningful impact on global markets.
StudySmarter Expert Advice🤫
We think this is how you could land Associate Director - Application Security in London
✨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at events. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Prepare for interviews by researching the company and role. Know their values and how you can contribute. This shows you’re genuinely interested and ready to make an impact!
✨Tip Number 3
Practice makes perfect! Do mock interviews with friends or use online platforms. The more comfortable you are, the better you’ll perform when it counts.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take that extra step!
We think you need these skills to ace Associate Director - Application Security in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Associate Director - Application Security role. Highlight your experience in DevSecOps, application security, and cloud security, as these are key areas we’re looking for.
Showcase Relevant Experience:When detailing your work history, focus on your hands-on experience with JFrog Artifactory and any projects involving AI/ML security. We want to see how your background aligns with our needs!
Be Clear and Concise:Keep your application straightforward and to the point. Use bullet points where possible to make it easy for us to see your qualifications at a glance. We appreciate clarity!
Apply Through Our Website:Don’t forget to submit your application through our official website. This ensures that your application gets to the right place and is reviewed promptly by our team.
How to prepare for a job interview at OSTTRA
✨Know Your Stuff
Make sure you brush up on your knowledge of DevSecOps, application security, and cloud security. Familiarise yourself with tools like JFrog Artifactory and CI/CD pipelines using GitHub, Jenkins, and Azure DevOps. Being able to discuss your hands-on experience confidently will impress the interviewers.
✨Showcase Your Problem-Solving Skills
Prepare to discuss specific challenges you've faced in previous roles related to software supply chain security or AI/ML risks. Think of examples where you implemented solutions for dependency management or secured AI workloads. This will demonstrate your practical experience and critical thinking.
✨Understand the Company’s Values
Get to know the company’s mission and values, especially their focus on integrity, discovery, and partnership. Be ready to explain how your personal values align with theirs and how you can contribute to their goals. This shows that you're not just looking for a job, but a place where you can grow and make an impact.
✨Ask Insightful Questions
Prepare thoughtful questions about the role, team dynamics, and future projects. Inquire about their approach to emerging AI security threats or how they ensure compliance with Responsible AI policies. This not only shows your interest in the position but also your proactive mindset towards continuous improvement.