At a Glance
- Tasks: Secure and govern enterprise artifact management platforms in a dynamic DevSecOps environment.
- Company: Join S&P Global, a leader in financial information and analytics.
- Benefits: Competitive salary, health coverage, flexible time off, and continuous learning opportunities.
- Other info: Diverse and inclusive workplace with excellent career growth potential.
- Why this job: Make a real impact on software security while working with cutting-edge AI technologies.
- Qualifications: Bachelor's degree in relevant field and 3-6 years of experience in DevSecOps or application security.
The predicted salary is between 100000 - 130000 £ per year.
The DevSecOps Engineer – Artifact Management & Software Supply Chain Security focuses on securing and governing enterprise artifact and dependency management platforms. This role combines DevSecOps, application security, and cloud security to ensure that build artifacts and dependencies are trusted, curated, and consumed securely across CI/CD pipelines and cloud environments.
Key Responsibilities
- Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments.
- Define and enforce package curation, promotion, and trust models aligned with application security and compliance requirements.
- Implement and govern waiver and approval workflows for dependency and artifact usage, ensuring risk‑based decision‑making.
- Partner with AppSec, platform, and engineering teams to standardize secure dependency and artifact consumption patterns.
- Define and maintain repository architectures supporting multiple environments, teams, and trust boundaries.
- Enforce policies ensuring artifact immutability, provenance, versioning, and trusted sourcing.
- Integrate artifact repositories into CI/CD pipelines built on GitHub, Jenkins, and Azure DevOps.
- Embed security controls for AI/ML and GenAI workloads within CI/CD pipelines and developer workflows.
- Define and enforce secure usage patterns for LLMs and AI services, including prompt handling, data protection, and model access controls.
- Implement safeguards against AI‑specific threats, including prompt injection, model poisoning, data leakage, and insecure model outputs.
- Integrate AI security scanning and validation into build pipelines, ensuring safe model usage and dependency integrity.
- Collaborate with engineering teams to establish secure‑by‑design AI application architectures.
- Ensure compliance with enterprise Responsible AI policies (data privacy, bias management, model governance).
- Secure AI‑related secrets, tokens, and API access used in pipelines and applications.
- Monitor and respond to security risks introduced by AI/ML components, including third‑party models and APIs.
- Contribute to AI risk governance, auditability, and traceability across the SDLC.
- Stay current on emerging AI security threats, vulnerabilities, and regulatory expectations.
- Align artifact and dependency controls with cloud security best practices for deployed applications.
- Monitor usage, risk posture, and effectiveness of artifact controls and drive continuous improvement.
- Develop automation and policy‑as‑code for artifact lifecycle management, approvals, and governance.
- Support security incident investigations related to software supply chain integrity or dependency risk.
- Create documentation, standards, and enablement materials for secure developer adoption.
Required Qualifications
- Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or equivalent experience.
- 3–6 years of experience in DevSecOps, platform security, or software supply chain security.
- Strong hands‑on experience with JFrog Artifactory, including deployment and enterprise architecture.
- Experience designing package curation and promotion models.
- Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle.
- Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage.
- Experience integrating AI or ML components into applications or pipelines (preferred hands‑on exposure).
- Familiarity with Responsible AI principles and AI governance frameworks.
- Experience implementing waiver and approval workflows for dependencies and artifacts.
- Strong understanding of application security principles and dependency risk management.
- Hands‑on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines.
- Experience working in cloud environments (Azure preferred; AWS/GCP acceptable).
- Proficiency with automation and scripting (Python, Groovy, Terraform, etc.).
- Knowledge of modern SDLC and DevSecOps operating models.
Compensation and Benefits
- Base salary range: $125,000 to $165,000, with an additional annual incentive plan.
- Eligible to receive S&P Global benefits.
- Health & wellness coverage.
- Flexible downtime / time off.
- Continuous learning and development resources.
- Retirement planning and company‑matched student loan contribution.
- Financial wellness programs.
US Candidates Only: Know Your Rights – Workplace discrimination is illegal. Equal Opportunity Employer: S&P Global is an equal opportunity employer and all qualified candidates will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law. If you need an accommodation during the application process due to a disability, please send an email to.
Associate Director - Application Security in London employer: S&P Global Inc.
S&P Global is an exceptional employer that prioritises employee growth and well-being, offering a competitive salary range of $125,000 to $165,000 along with a robust benefits package that includes health coverage, flexible time off, and continuous learning resources. Our collaborative work culture fosters innovation in the rapidly evolving fields of DevSecOps and AI security, making it an ideal environment for professionals looking to make a meaningful impact while advancing their careers in a supportive and inclusive setting.
StudySmarter Expert Advice🤫
We think this is how you could land Associate Director - Application Security in London
✨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at local meetups. A friendly chat can open doors that a CV just can't.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Tailor your answers to show how your skills align with their needs, especially in areas like DevSecOps and application security.
✨Tip Number 3
Showcase your hands-on experience! Bring examples of your work with tools like JFrog Artifactory or CI/CD pipelines to the table. Real-world stories make you memorable.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!
We think you need these skills to ace Associate Director - Application Security in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in DevSecOps and application security. We want to see how your skills align with the role, so don’t hold back on showcasing relevant projects!
Showcase Your Technical Skills:Since this role involves a lot of hands-on work with tools like JFrog Artifactory and CI/CD pipelines, be sure to mention your technical expertise. We love seeing specific examples of how you've used these tools in past roles.
Highlight Collaboration Experience:This position requires working closely with various teams, so share any experiences where you’ve partnered with others to achieve a common goal. We value teamwork and want to know how you can contribute to our collaborative culture.
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to keep track of your application and ensure it gets the attention it deserves. We can’t wait to hear from you!
How to prepare for a job interview at S&P Global Inc.
✨Know Your Stuff
Make sure you brush up on your knowledge of DevSecOps, application security, and cloud security. Familiarise yourself with the specific tools mentioned in the job description, like JFrog Artifactory, GitHub, Jenkins, and Azure DevOps. Being able to discuss your hands-on experience with these tools will show that you're not just a theory person.
✨Showcase Your Problem-Solving Skills
Prepare to discuss real-world scenarios where you've tackled security risks or implemented governance workflows. Think about examples where you’ve had to make risk-based decisions regarding dependencies and artifacts. This will demonstrate your practical understanding of the role and your ability to think critically under pressure.
✨Stay Current on AI Security Trends
Given the focus on AI/ML security in this role, it’s crucial to be aware of the latest threats and vulnerabilities. Research recent incidents related to AI security, such as prompt injection or data leakage, and be ready to discuss how you would address these issues in a CI/CD pipeline.
✨Ask Insightful Questions
Interviews are a two-way street! Prepare thoughtful questions about the company’s approach to secure software supply chains and how they integrate AI security into their processes. This shows your genuine interest in the role and helps you gauge if the company aligns with your values and career goals.