At a Glance
- Tasks: Design and implement security controls in CI/CD pipelines for secure software delivery.
- Company: Join a leading tech firm focused on innovative security solutions.
- Benefits: Enjoy competitive pay, health coverage, flexible time off, and continuous learning opportunities.
- Other info: Dynamic work environment with excellent career growth and family-friendly perks.
- Why this job: Make a real impact by embedding security into cutting-edge technology and AI applications.
- Qualifications: Experience in DevSecOps and application security with a strong understanding of AI/ML concepts.
The predicted salary is between 100000 - 130000 £ per year.
The DevSecOps Engineer – CI/CD & Application Security focuses on embedding application security and cloud security controls directly into CI/CD pipelines and developer workflows. This role drives shift‑left security by designing, implementing, and operating automated security guardrails across source code, build, and deployment pipelines in cloud-native environments.
Key Responsibilities
- Design, implement, and operate application security controls integrated into CI/CD pipelines, ensuring secure software delivery by default.
- Embed automated AppSec checks across code, dependencies, builds, and deployment workflows aligned with shift‑left principles.
- Define and maintain secure CI/CD reference architectures and patterns for enterprise cloud-native applications.
- Partner with engineering teams to integrate security seamlessly into developer workflows, minimizing friction and manual intervention.
- Develop reusable pipeline templates, policy controls, and automation to scale AppSec and DevSecOps practices across teams.
- Secure pipeline infrastructure and credentials, protecting against build manipulation, secret leakage, and provenance risks.
- Integrate CI/CD security findings with broader application and cloud security monitoring workflows.
- Investigate and respond to application and pipeline‑related security findings, partnering with Security Operations as required.
- Contribute to cloud security posture by aligning pipeline and application controls with cloud security best practices.
- Embed security controls for AI/ML and GenAI workloads within CI/CD pipelines and developer workflows.
- Define and enforce secure usage patterns for LLMs and AI services, including prompt handling, data protection, and model access controls.
- Implement safeguards against AI‑specific threats, including prompt injection, model poisoning, data leakage, and insecure model outputs.
- Integrate AI security scanning and validation into build pipelines, ensuring safe model usage and dependency integrity.
- Collaborate with engineering teams to establish secure‑by‑design AI application architectures.
- Ensure compliance with enterprise Responsible AI policies (data privacy, bias management, model governance).
- Secure AI‑related secrets, tokens, and API access used in pipelines and applications.
- Monitor and respond to security risks introduced by AI/ML components, including third‑party models and APIs.
- Contribute to AI risk governance, auditability, and traceability across the SDLC.
- Stay current on emerging AI security threats, vulnerabilities, and regulatory expectations.
- Author documentation, standards, and training to drive developer adoption of secure CI/CD and AppSec practices.
- Continuously evaluate emerging application security and software supply chain threats and improve controls accordingly.
Required Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent experience.
- 3–6 years of experience in DevSecOps, Application Security, or Platform Security roles.
- Strong hands‑on experience securing CI/CD pipelines using GitHub, Jenkins, and Azure DevOps.
- Solid understanding of application security concepts (secure coding, dependency risk, pipeline hardening, secrets management).
- Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle.
- Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage.
- Experience integrating AI or ML components into applications or pipelines (preferred hands‑on exposure).
- Familiarity with Responsible AI principles and AI governance frameworks.
- Experience implementing shift‑left AppSec controls in modern SDLCs.
- Experience working in cloud environments (Azure, AWS, or GCP).
- Proficiency with scripting or programming languages (Python, Go, Java, etc.).
- Familiarity with containerized build and deployment models.
- Strong understanding of software supply chain security risks.
Preferred Qualifications
- Experience with policy‑as‑code and automated security governance.
- Knowledge of Kubernetes, container security, and cloud‑native application architectures.
- Experience integrating AppSec signals into enterprise security platforms.
DevSecOps Architect: Secure CI/CD & AppSec employer: S&P Global
S&P Global is an exceptional employer that prioritises employee well-being and professional growth, particularly for the DevSecOps Architect role in Princeton, New Jersey. With a strong focus on health and wellness, flexible downtime, and continuous learning opportunities, employees are empowered to thrive both personally and professionally. The company fosters a collaborative work culture that embraces innovation and inclusivity, making it an ideal place for those seeking meaningful and rewarding careers in application security.
StudySmarter Expert Advice🤫
We think this is how you could land DevSecOps Architect: Secure CI/CD & AppSec
✨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repo showcasing your projects, especially those related to CI/CD and AppSec. This gives potential employers a taste of what you can do.
✨Tip Number 3
Prepare for interviews by practising common DevSecOps questions. Think about how you’d explain your experience with securing CI/CD pipelines and integrating security into workflows.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!
We think you need these skills to ace DevSecOps Architect: Secure CI/CD & AppSec
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the DevSecOps Architect role. Highlight your experience with CI/CD pipelines and application security, as we want to see how you can embed security into developer workflows.
Showcase Your Skills:Don’t hold back on showcasing your hands-on experience with tools like GitHub, Jenkins, and Azure DevOps. We love seeing practical examples of how you've secured CI/CD pipelines in your previous roles.
Be Clear and Concise:When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to see your qualifications and achievements at a glance.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role without any hiccups!
How to prepare for a job interview at S&P Global
✨Know Your Tech Stack
Make sure you’re well-versed in the tools and technologies mentioned in the job description, like GitHub, Jenkins, and Azure DevOps. Brush up on your knowledge of CI/CD pipelines and how to secure them, as this will show that you can hit the ground running.
✨Showcase Your Security Mindset
Prepare to discuss your experience with application security concepts and shift-left principles. Be ready to share specific examples of how you've embedded security into developer workflows or CI/CD processes in past roles. This will demonstrate your proactive approach to security.
✨Understand AI/ML Security Risks
Since the role involves AI/ML components, make sure you’re familiar with the associated security risks like prompt injection and data leakage. Being able to articulate these risks and how to mitigate them will set you apart from other candidates.
✨Prepare Questions for Them
Interviews are a two-way street! Prepare insightful questions about their current security practices, team dynamics, and how they integrate security into their development processes. This shows your genuine interest in the role and helps you assess if it’s the right fit for you.