Lead, Secure Artifacts & DevSecOps

S&P Global

Greater London

On-site

GBP 80,000 - 110,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health & Wellness
Flexible Downtime
Continuous Learning
Invest in Your Future
Family Friendly Perks
Beyond the Basics

Job summary

S&P Global in London is seeking a DevSecOps Engineer to secure and govern artifact management across CI/CD pipelines and cloud environments. You will implement secure-by-design patterns, integrate Artifactory with GitHub, Jenkins, and Azure DevOps, and enforce AI/ML security controls in pipelines.

We value hands-on expertise in platform security, dependency risk management, and modern SDLC practices, with a focus on secure artifact lifecycle, provenance, and compliance.

Qualifications

  • 3–6 years of experience in DevSecOps, platform security, or software supply chain security.
  • Strong hands‑on experience with JFrog Artifactory, including deployment and enterprise architecture.
  • Experience designing package curation and promotion models.
  • Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle.
  • Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage.
  • Experience integrating AI or ML components into applications or pipelines (preferred hands‑on exposure).
  • Familiarity with Responsible AI principles and AI governance frameworks.
  • Experience implementing waiver and approval workflows for dependencies and artifacts.
  • Strong understanding of application security principles and dependency risk management.
  • Hands‑on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines.
  • Experience working in cloud environments (Azure preferred; AWS/GCP acceptable).
  • Proficiency with automation and scripting (Python, Groovy, Terraform, etc.).
  • Knowledge of modern SDLC and DevSecOps operating models.

Responsibilities

  • Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments.
  • Define and enforce package curation, promotion, and trust models aligned with application security and compliance requirements.
  • Implement and govern waiver and approval workflows for dependency and artifact usage, ensuring risk-based decision‑making.
  • Partner with AppSec, platform, and engineering teams to standardize secure dependency and artifact consumption patterns.
  • Define and maintain repository architectures supporting multiple environments, teams, and trust boundaries.
  • Enforce policies ensuring artifact immutability, provenance, versioning, and trusted sourcing.
  • Integrate artifact repositories into CI/CD pipelines built on GitHub, Jenkins, and Azure DevOps.
  • Embed security controls for AI/ML and GenAI workloads within CI/CD pipelines and developer workflows.
  • Define and enforce secure usage patterns for LLMs and AI services, including prompt handling, data protection, and model access controls.
  • Implement safeguards against AI-specific threats, including prompt injection, model poisoning, data leakage, and insecure model outputs.
  • Integrate AI security scanning and validation into build pipelines, ensuring safe model usage and dependency integrity.
  • Collaborate with engineering teams to establish secure-by-design AI application architectures.
  • Ensure compliance with enterprise Responsible AI policies (data privacy, bias management, model governance).
  • Secure AI-related secrets, tokens, and API access used in pipelines and applications.
  • Monitor and respond to security risks introduced by AI/ML components, including third‑party models and APIs.
  • Contribute to AI risk governance, auditability, and traceability across the SDLC.
  • Stay current on emerging AI security threats, vulnerabilities, and regulatory expectations.
  • Align artifact and dependency controls with cloud security best practices for deployed applications.
  • Monitor usage, risk posture, and effectiveness of artifact controls and drive continuous improvement.
  • Develop automation and policy‑as‑code for artifact lifecycle management, approvals, and governance.
  • Support security incident investigations related to software supply chain integrity or dependency risk.
  • Create documentation, standards, and enablement materials for secure developer adoption.

Skills

DevSecOps
Platform security
Dependency risk management
AI/ML security

Education

Bachelor's degree in Computer Science or related

Tools

JFrog Artifactory
GitHub
Jenkins
Azure DevOps
Python
Groovy
Terraform

Job description

S&P Global in London is seeking a DevSecOps Engineer to secure and govern artifact management across CI/CD pipelines and cloud environments. You will implement secure-by-design patterns, integrate Artifactory with GitHub, Jenkins, and Azure DevOps, and enforce AI/ML security controls in pipelines.

We value hands-on expertise in platform security, dependency risk management, and modern SDLC practices, with a focus on secure artifact lifecycle, provenance, and compliance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Leader: Artifact & Supply Chain Security
Senior DevSecOps Leader: Artifact & Supply Chain Security

S&P Global, Inc. • City Of London

On-site
GBP 92,000 - 122,000
Health care coverage
Flexible downtime
Continuous learning
+2
Senior DevSecOps Lead — Artifact & Supply Chain Security
Senior DevSecOps Lead — Artifact & Supply Chain Security

S&P Global, Inc. • Greater London

Hybrid
GBP 90,000 - 130,000
Health care coverage
Continuous learning
Retirement planning
+1
Lead DevSecOps Platform Engineer (CI/CD & Security)
Lead DevSecOps Platform Engineer (CI/CD & Security)

Understanding Recruitment • Greater London

On-site
GBP 90,000 - 140,000
Lead DevSecOps Engineer — Secure CI/CD & IaC Expert
Lead DevSecOps Engineer — Secure CI/CD & IaC Expert

Capgemini • Filton

Hybrid
GBP 90,000 - 120,000
Lead DevSecOps Engineer – Secure CI/CD & Cloud Compliance
Lead DevSecOps Engineer – Secure CI/CD & Cloud Compliance

Capgemini • West of England

On-site
GBP 80,000 - 110,000
DevSecOps Lead: Secure Cloud, CI/CD & Hybrid London
DevSecOps Lead: Secure Cloud, CI/CD & Hybrid London

Oho Group • Greater London

Hybrid
GBP 90,000 - 140,000
Hybrid working in London
Competitive compensation
Lead Security Engineer - Platform & DevSecOps
Lead Security Engineer - Platform & DevSecOps

JPMorganChase • Greater London

On-site
GBP 80,000 - 120,000
Security Engineering Lead: Cloud, AI & DevSecOps
Security Engineering Lead: Cloud, AI & DevSecOps

capco • Greater London

Hybrid
GBP 120,000 - 150,000
Discretionary bonus
Health insurance
Pension
+2
Lead DevSecOps: Build Resilient, Secure Platforms
Lead DevSecOps: Build Resilient, Secure Platforms

Praxis Tech • United Kingdom

On-site
GBP 90,000 - 120,000
Lead DevSecOps Platform Engineer
Lead DevSecOps Platform Engineer

Acceler8 Talent • Greater London

Hybrid
GBP 110,000 - 140,000
Private healthcare
7% pension
Equity
+1