Associate Director - Application Security

Associate Director - Application Security

Full-Time 100000 - 130000 £ / year (est.) No working from home possible
S&P Global

At a Glance

  • Tasks: Secure and govern enterprise artifact management platforms in a dynamic DevSecOps environment.
  • Company: Join S&P Global, a leader in financial information and analytics.
  • Benefits: Enjoy health coverage, flexible time off, and continuous learning opportunities.
  • Other info: Be part of an inclusive team that values diversity and innovation.
  • Why this job: Make a real impact on software security while working with cutting-edge AI technologies.
  • Qualifications: Bachelor's degree in relevant field and 3-6 years of experience in DevSecOps.

The predicted salary is between 100000 - 130000 £ per year.

The DevSecOps Engineer – Artifact Management & Software Supply Chain Security focuses on securing and governing enterprise artifact and dependency management platforms. This role combines DevSecOps, application security, and cloud security to ensure that build artifacts and dependencies are trusted, curated, and consumed securely across CI/CD pipelines and cloud environments.

Key Responsibilities

  • Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments.
  • Define and enforce package curation, promotion, and trust models aligned with application security and compliance requirements.
  • Implement and govern waiver and approval workflows for dependency and artifact usage, ensuring risk‑based decision‑making.
  • Partner with AppSec, platform, and engineering teams to standardize secure dependency and artifact consumption patterns.
  • Define and maintain repository architectures supporting multiple environments, teams, and trust boundaries.
  • Enforce policies ensuring artifact immutability, provenance, versioning, and trusted sourcing.
  • Integrate artifact repositories into CI/CD pipelines built on GitHub, Jenkins, and Azure DevOps.
  • Embed security controls for AI/ML and GenAI workloads within CI/CD pipelines and developer workflows.
  • Define and enforce secure usage patterns for LLMs and AI services, including prompt handling, data protection, and model access controls.
  • Implement safeguards against AI‑specific threats, including prompt injection, model poisoning, data leakage, and insecure model outputs.
  • Integrate AI security scanning and validation into build pipelines, ensuring safe model usage and dependency integrity.
  • Collaborate with engineering teams to establish secure‑by‑design AI application architectures.
  • Ensure compliance with enterprise Responsible AI policies (data privacy, bias management, model governance).
  • Secure AI‑related secrets, tokens, and API access used in pipelines and applications.
  • Monitor and respond to security risks introduced by AI/ML components, including third‑party models and APIs.
  • Contribute to AI risk governance, auditability, and traceability across the SDLC.
  • Stay current on emerging AI security threats, vulnerabilities, and regulatory expectations.
  • Align artifact and dependency controls with cloud security best practices for deployed applications.
  • Monitor usage, risk posture, and effectiveness of artifact controls and drive continuous improvement.
  • Develop automation and policy‑as‑code for artifact lifecycle management, approvals, and governance.
  • Support security incident investigations related to software supply chain integrity or dependency risk.
  • Create documentation, standards, and enablement materials for secure developer adoption.

Required Qualifications

  • Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or equivalent experience.
  • 3–6 years of experience in DevSecOps, platform security, or software supply chain security.
  • Strong hands‑on experience with JFrog Artifactory, including deployment and enterprise architecture.
  • Experience designing package curation and promotion models.
  • Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle.
  • Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage.
  • Experience integrating AI or ML components into applications or pipelines (preferred hands‑on exposure).
  • Familiarity with Responsible AI principles and AI governance frameworks.
  • Experience implementing waiver and approval workflows for dependencies and artifacts.
  • Strong understanding of application security principles and dependency risk management.
  • Hands‑on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines.
  • Experience working in cloud environments (Azure preferred; AWS/GCP acceptable).
  • Proficiency with automation and scripting (Python, Groovy, Terraform, etc.).
  • Knowledge of modern SDLC and DevSecOps operating models.

Associate Director - Application Security employer: S&P Global

S&P Global is an exceptional employer that prioritises employee well-being and professional growth, offering a dynamic work culture in Princeton, New Jersey. With generous health benefits, flexible downtime, and continuous learning opportunities, employees are empowered to thrive both personally and professionally. The company fosters a collaborative environment where innovation in application security and AI governance is at the forefront, making it an ideal place for those seeking meaningful and rewarding careers.

S&P Global

Contact Details:

S&P Global Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Associate Director - Application Security

Tip Number 1

Network like a pro! Reach out to folks in your industry on LinkedIn or at local meetups. A friendly chat can open doors that a CV just can't.

Tip Number 2

Prepare for those interviews! Research the company and role, and think about how your skills fit in. Practise common questions and have your own ready to go.

Tip Number 3

Showcase your skills! If you’ve got projects or contributions to open-source, flaunt them. A portfolio can speak volumes about your capabilities.

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are keen to join us directly.

We think you need these skills to ace Associate Director - Application Security

DevSecOps
Application Security
Cloud Security
Artifact Management
Dependency Management
CI/CD Pipelines
JFrog Artifactory

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in DevSecOps and application security. We want to see how your skills align with the role, so don’t hold back on showcasing relevant projects!

Showcase Your Technical Skills:Don’t forget to mention your hands-on experience with tools like JFrog Artifactory, GitHub, Jenkins, and Azure DevOps. We love seeing specific examples of how you've integrated these into your workflows.

Highlight Your AI Knowledge:Since this role involves AI/ML components, make sure to include any relevant experience or understanding you have of AI security risks and responsible AI principles. This will definitely catch our eye!

Apply Through Our Website:We encourage you to submit your application through our website for a smoother process. It helps us keep everything organised and ensures your application gets the attention it deserves!

How to prepare for a job interview at S&P Global

Know Your Stuff

Make sure you brush up on your knowledge of DevSecOps, application security, and cloud security. Be ready to discuss specific tools like JFrog Artifactory and how you've used them in past projects. The more you can demonstrate your hands-on experience, the better!

Showcase Your Problem-Solving Skills

Prepare to talk about real-world challenges you've faced in securing software supply chains or managing dependencies. Think of examples where you implemented risk-based decision-making or enforced compliance requirements. This will show that you can think critically and act decisively.

Understand AI Security Risks

Since this role involves AI/ML components, make sure you’re familiar with the security risks associated with them, like prompt injection and data leakage. Being able to discuss these topics will set you apart as someone who’s not just technically skilled but also aware of current threats.

Ask Insightful Questions

At the end of the interview, don’t forget to ask questions! Inquire about the company’s approach to secure-by-design architectures or how they handle emerging AI security threats. This shows your genuine interest in the role and helps you gauge if it’s the right fit for you.