DevSecOps Architect — AI Security & Supply Chain

DevSecOps Architect — AI Security & Supply Chain

Full-Time 100000 - 130000 £ / year (est.) No working from home possible
S&P Global

At a Glance

  • Tasks: Design and secure AI systems while managing software supply chains in a dynamic environment.
  • Company: Join S&P Global, a leader in innovative tech solutions with a focus on security.
  • Benefits: Enjoy competitive pay, health coverage, flexible time off, and continuous learning opportunities.
  • Other info: Be part of a diverse team committed to innovation and professional growth.
  • Why this job: Make a real impact in AI security and shape the future of technology.
  • Qualifications: Bachelor's degree and 3-6 years in DevSecOps or related fields required.

The predicted salary is between 100000 - 130000 £ per year.

Key Responsibilities

  • Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments.
  • Define and enforce package curation, promotion, and trust models aligned with application security and compliance requirements.
  • Implement and govern waiver and approval workflows for dependency and artifact usage, ensuring risk‑based decision‑making.
  • Partner with AppSec, platform, and engineering teams to standardize secure dependency and artifact consumption patterns.
  • Define and maintain repository architectures supporting multiple environments, teams, and trust boundaries.
  • Enforce policies ensuring artifact immutability, provenance, versioning, and trusted sourcing.
  • Integrate artifact repositories into CI/CD pipelines built on GitHub, Jenkins, and Azure DevOps.
  • Embed security controls for AI/ML and GenAI workloads within CI/CD pipelines and developer workflows.
  • Define and enforce secure usage patterns for LLMs and AI services, including prompt handling, data protection, and model access controls.
  • Implement safeguards against AI‑specific threats, including prompt injection, model poisoning, data leakage, and insecure model outputs.
  • Integrate AI security scanning and validation into build pipelines, ensuring safe model usage and dependency integrity.
  • Collaborate with engineering teams to establish secure‑by‑design AI application architectures.
  • Ensure compliance with enterprise Responsible AI policies (data privacy, bias management, model governance).
  • Secure AI‑related secrets, tokens, and API access used in pipelines and applications.
  • Monitor and respond to security risks introduced by AI/ML components, including third‑party models and APIs.
  • Contribute to AI risk governance, auditability, and traceability across the SDLC.
  • Stay current on emerging AI security threats, vulnerabilities, and regulatory expectations.
  • Align artifact and dependency controls with cloud security best practices for deployed applications.
  • Monitor usage, risk posture, and effectiveness of artifact controls and drive continuous improvement.
  • Develop automation and policy‑as‑code for artifact lifecycle management, approvals, and governance.
  • Support security incident investigations related to software supply chain integrity or dependency risk.
  • Create documentation, standards, and enablement materials for secure developer adoption.

Required Qualifications

  • Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or equivalent experience.
  • 3–6 years of experience in DevSecOps, platform security, or software supply chain security.
  • Strong hands‑on experience with JFrog Artifactory, including deployment and enterprise architecture.
  • Experience designing package curation and promotion models.
  • Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle.
  • Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage.
  • Experience integrating AI or ML components into applications or pipelines (preferred hands‑on exposure).
  • Familiarity with Responsible AI principles and AI governance frameworks.
  • Experience implementing waiver and approval workflows for dependencies and artifacts.
  • Strong understanding of application security principles and dependency risk management.
  • Hands‑on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines.
  • Experience working in cloud environments (Azure preferred; AWS/GCP acceptable).
  • Proficiency with automation and scripting (Python, Groovy, Terraform, etc.).
  • Knowledge of modern SDLC and DevSecOps operating models.

Equal Opportunity Employer

S&P Global is an equal opportunity employer and all qualified candidates will receive consideration for employment without regard to race/ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law.

DevSecOps Architect — AI Security & Supply Chain employer: S&P Global

S&P Global is an exceptional employer, offering a dynamic work culture that prioritises health and wellness, continuous learning, and family-friendly benefits. As a DevSecOps Architect in Princeton, New Jersey, you will have access to competitive compensation, generous time off, and opportunities for professional growth in a collaborative environment focused on innovation and security in AI and software supply chains.

S&P Global

Contact Details:

S&P Global Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land DevSecOps Architect — AI Security & Supply Chain

Tip Number 1

Network like a pro! Reach out to folks in your industry on LinkedIn or at meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.

Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to DevSecOps and AI security. This gives potential employers a taste of what you can do.

Tip Number 3

Prepare for interviews by practising common questions and scenarios specific to DevSecOps. Think about how you’d tackle real-world problems they might throw at you.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search.

We think you need these skills to ace DevSecOps Architect — AI Security & Supply Chain

DevSecOps
AI Security
Software Supply Chain Security
JFrog Artifactory
Package Curation
AI/ML Concepts
Generative AI

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with DevSecOps, AI security, and software supply chain. We want to see how your skills align with the key responsibilities listed in the job description.

Showcase Relevant Experience:When detailing your past roles, focus on your hands-on experience with tools like JFrog Artifactory, GitHub, Jenkins, and Azure DevOps. We love seeing specific examples of how you've implemented security controls or managed dependencies in your previous jobs.

Highlight Continuous Learning:Mention any recent courses, certifications, or projects related to AI/ML security or DevSecOps practices. We value candidates who are proactive about staying current with emerging threats and technologies.

Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensure you’re considered for this exciting opportunity.

How to prepare for a job interview at S&P Global

Know Your Tech Inside Out

Make sure you’re well-versed in the tools and technologies mentioned in the job description, like JFrog Artifactory, GitHub, Jenkins, and Azure DevOps. Brush up on your knowledge of AI/ML concepts and security risks, as these will likely come up during the interview.

Showcase Your Problem-Solving Skills

Prepare to discuss specific challenges you've faced in previous roles related to DevSecOps or software supply chain security. Think about how you implemented solutions for issues like dependency risk management or secure CI/CD pipelines, and be ready to share those experiences.

Understand the Company’s Security Policies

Familiarise yourself with Responsible AI principles and any relevant compliance requirements. Being able to discuss how you would align with their security policies and contribute to their governance frameworks will show that you’re a good fit for their team.

Ask Insightful Questions

Prepare thoughtful questions about the company’s approach to AI security and how they handle emerging threats. This not only shows your interest in the role but also demonstrates your proactive mindset and understanding of the industry.