Senior DevSecOps Engineer: Artifact & Supply Chain Security

spgi

Greater London

On-site

GBP 93,000 - 122,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

S&P Global is seeking a DevSecOps Engineer focused on artifact management and software supply chain security in a UK-based or hybrid environment. The role spans securing build artifacts, enforcing trust models, and integrating governance across CI/CD pipelines built on GitHub, Jenkins, and Azure DevOps.

You will partner with AppSec and engineering teams to implement secure-by-design AI workflows. Responsibilities include designing repository architectures, enforcing immutability and

Qualifications

  • 3-6 years of experience in DevSecOps, platform security, or software supply chain security.
  • Strong hands-on experience with JFrog Artifactory, including deployment and enterprise architecture.
  • Experience designing package curation and promotion models.
  • Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle.
  • Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage.
  • Experience integrating AI or ML components into applications or pipelines (preferred hands-on exposure).
  • Familiarity with Responsible AI principles and AI governance frameworks.
  • Experience implementing waiver and approval workflows for dependencies and artifacts.
  • Strong understanding of application security principles and dependency risk management.
  • Hands-on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines.
  • Experience working in cloud environments (Azure preferred; AWS/GCP acceptable).
  • Proficiency with automation and scripting (Python, Groovy, Terraform, etc.).
  • Knowledge of modern SDLC and DevSecOps operating models.

Responsibilities

  • Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments.
  • Define and enforce package curation, promotion, and trust models aligned with application security and compliance requirements.
  • Implement and govern waiver and approval workflows for dependency and artifact usage, ensuring risk-based decision‑making.
  • Partner with AppSec, platform, and engineering teams to standardize secure dependency and artifact consumption patterns.
  • Define and maintain repository architectures supporting multiple environments, teams, and trust boundaries.
  • Enforce policies ensuring artifact immutability, provenance, versioning, and trusted sourcing.
  • Integrate artifact repositories into CI/CD pipelines built on GitHub, Jenkins, and Azure DevOps.
  • Embed security controls for AI/ML and GenAI workloads within CI/CD pipelines and developer workflows.
  • Define and enforce secure usage patterns for LLMs and AI services, including prompt handling, data protection, and model access controls.
  • Implement safeguards against AI‑specific threats, including prompt injection, model poisoning, data leakage, and insecure model outputs.
  • Integrate AI security scanning and validation into build pipelines, ensuring safe model usage and dependency integrity.
  • Collaborate with engineering teams to establish secure‑by‑design AI application architectures.
  • Ensure compliance with enterprise Responsible AI policies (data privacy, bias management, model governance).
  • Secure AI‑related secrets, tokens, and API access used in pipelines and applications.
  • Monitor and respond to security risks introduced by AI/ML components, including third‑party models and APIs.
  • Contribute to AI risk governance, auditability, and traceability across the SDLC.
  • Stay current on emerging AI security threats, vulnerabilities, and regulatory expectations.
  • Align artifact and dependency controls with cloud security best practices for deployed applications.
  • Monitor usage, risk posture, and effectiveness of artifact controls and drive continuous improvement.
  • Develop automation and policy‑as‑code for artifact lifecycle management, approvals, and governance.
  • Support security incident investigations related to software supply chain integrity or dependency risk.
  • Create documentation, standards, and enablement materials for secure developer adoption.

Skills

DevSecOps
JFrog Artifactory
AI/ML security
CI/CD security
Cloud platforms
Automation scripting
Python
Groovy
Terraform
GitHub/Jenkins/Azure DevOps

Tools

GitHub & GitHub Actions
Jenkins
Azure DevOps

Job description

S&P Global is seeking a DevSecOps Engineer focused on artifact management and software supply chain security in a UK-based or hybrid environment. The role spans securing build artifacts, enforcing trust models, and integrating governance across CI/CD pipelines built on GitHub, Jenkins, and Azure DevOps.

You will partner with AppSec and engineering teams to implement secure-by-design AI workflows. Responsibilities include designing repository architectures, enforcing immutability and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Leader: Artifact & Supply Chain Security
Senior DevSecOps Leader: Artifact & Supply Chain Security

S&P Global, Inc. • City Of London

On-site
GBP 92,000 - 122,000
Health care coverage
Flexible downtime
Continuous learning
+2
Senior DevSecOps Lead — Artifact & Supply Chain Security
Senior DevSecOps Lead — Artifact & Supply Chain Security

S&P Global, Inc. • Greater London

Hybrid
GBP 90,000 - 130,000
Health care coverage
Continuous learning
Retirement planning
+1
Senior DevSecOps Lead: Artifacts & AI Security
Senior DevSecOps Lead: Artifacts & AI Security

eFinancialCareers • Greater London

Hybrid
GBP 90,000 - 140,000
Senior DevSecOps Lead: Secure CI/CD & IaC Champion
Senior DevSecOps Lead: Secure CI/CD & IaC Champion

Capgemini • Filton

On-site
GBP 90,000 - 120,000
Disability Confident Employer
Learning for life
Applaud recognition portal
Senior DevSecOps Lead: Secure CI/CD & Cloud Automation
Senior DevSecOps Lead: Secure CI/CD & Cloud Automation

Capgemini • Bristol

On-site
GBP 70,000 - 100,000
Disability Confident Employer (Level 2
Applaud peer recognition portal
Learning for life training & 250,000+
Associate Director - Application Security
Associate Director - Application Security

eFinancialCareers • Greater London

Hybrid
GBP 90,000 - 140,000
Associate Director - Application Security
Associate Director - Application Security

spgi • Greater London

On-site
GBP 93,000 - 122,000
Lead DevSecOps Engineer — Secure CI/CD & IaC Expert
Lead DevSecOps Engineer — Secure CI/CD & IaC Expert

Capgemini • Filton

Hybrid
GBP 90,000 - 120,000
Lead DevSecOps Engineer – Secure CI/CD & Cloud Compliance
Lead DevSecOps Engineer – Secure CI/CD & Cloud Compliance

Capgemini • West of England

On-site
GBP 80,000 - 110,000
DevSecOps Engineer: Hybrid Cloud & Secure Delivery
DevSecOps Engineer: Hybrid Cloud & Secure Delivery

Methods Business and Digital Technology • Ross-on-Wye

On-site
GBP 90,000 - 120,000
LinkedIn Learning access
Management development program
Training