Artifact Security & DevSecOps Lead

S&P Global

New York (NY)

On-site

USD 125,000 - 165,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health & Wellness
Flexible downtime
Continuous learning
Retirement planning & student loan

Job summary

S&P Global is seeking a DevSecOps Engineer focused on Artifact Management & Security for enterprise CI/CD pipelines. You will guard build artifacts, enforce trust models, and integrate secure artifact repositories across cloud environments.

Collaboration with AppSec and engineering teams will be essential to standardize secure consumption patterns. The role emphasizes secure-by-design AI integration, risk-based decision workflows, and governance aligned with Responsible AI policies.

Qualifications

  • 3–6 years of experience in DevSecOps, platform security, or software supply chain security.
  • Hands-on experience with JFrog Artifactory deployment and enterprise architecture.
  • Experience designing package curation and promotion models.
  • Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle.
  • Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage.
  • Experience integrating AI or ML components into applications or pipelines (preferred).
  • Familiarity with Responsible AI principles and AI governance frameworks.
  • Experience implementing waiver and approval workflows for dependencies and artifacts.
  • Strong understanding of application security principles and dependency risk management.
  • Hands-on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines.
  • Experience cloud environments (Azure preferred; AWS/GCP acceptable).
  • Proficiency with automation and scripting (Python, Groovy, Terraform).
  • Knowledge of modern SDLC and DevSecOps operating models.

Responsibilities

  • Design, deploy, and operate artifact repositories across cloud and hybrid environments.
  • Define and enforce package curation, promotion, and trust models for security and compliance.
  • Implement waiver workflows for dependency and artifact usage to drive risk-based decisions.
  • Collaborate with AppSec, platform, and engineering teams to standardize secure consumption patterns.
  • Define repository architectures supporting multiple environments and trust boundaries.
  • Enforce artifact immutability, provenance, and trusted sourcing.
  • Integrate artifact repositories into CI/CD pipelines (GitHub, Jenkins, Azure DevOps).
  • Embed security controls for AI/ML workloads in pipelines and developer workflows.
  • Define secure usage patterns for LLMs and AI services, including data protection and model access controls.
  • Implement safeguards against AI threats like prompt injection and data leakage.
  • Integrate AI security scanning and validation into build pipelines.
  • Contribute to AI risk governance and SDLC traceability.
  • Stay current on emerging AI security threats and regulatory expectations.

Skills

DevSecOps
Platform security
Supply chain security

Tools

JFrog Artifactory
GitHub
Jenkins
Azure DevOps
Python
Groovy
Terraform

Job description

S&P Global is seeking a DevSecOps Engineer focused on Artifact Management & Security for enterprise CI/CD pipelines. You will guard build artifacts, enforce trust models, and integrate secure artifact repositories across cloud environments.

Collaboration with AppSec and engineering teams will be essential to standardize secure consumption patterns. The role emphasizes secure-by-design AI integration, risk-based decision workflows, and governance aligned with Responsible AI policies.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GenAI & Cloud Security Architect
Senior GenAI & Cloud Security Architect

SIDRAM TECHNOLOGIES • New York (NY)

Hybrid
USD 150,000 - 190,000
Senior Application Security Architect | AI-Driven DevSecOps
Senior Application Security Architect | AI-Driven DevSecOps

CVS Health • Georgia

Hybrid
USD 175,000 - 335,000
Security Architect for AI Research Infrastructure
Security Architect for AI Research Infrastructure

Sequent • Berkeley (CA)

On-site
USD 346,000 - 930,000
5 weeks of paid vacation per year
Comprehensive healthcare insurance (m‑
Unlimited sick leave
+1
Strategic AppSec Architect & AI Security Leader
Strategic AppSec Architect & AI Security Leader

CVS Health • Connecticut

Hybrid
USD 175,000 - 335,000
Remote: Senior App Security Architect for AI & DevSecOps
Remote: Senior App Security Architect for AI & DevSecOps

CVS Health • Illinois

Hybrid
USD 175,000 - 335,000
DevSecOps Engineer: Secure CI/CD & Cloud Apps
DevSecOps Engineer: Secure CI/CD & Cloud Apps

ACSC Auto Club Of Southern Calif • United States

On-site
USD 110,000 - 146,000
Health coverage (medical, dental, and視
401(K) retirement plan with company-m
Tuition assistance
+4
Application Security Engineer — DevSecOps & AI
Application Security Engineer — DevSecOps & AI

FSAStore.com • United States

On-site
USD 75,000 - 95,000
Medical, Dental, Vision
401K with company match
Flexible PTO
+2
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Senior AppSec Architect for AI-Driven DevSecOps (Remote)
Senior AppSec Architect for AI-Driven DevSecOps (Remote)

CVS Health • Arizona

Hybrid
USD 175,000 - 335,000
Health benefits
Bonus/equity program
DevSecOps Engineer: Secure CI/CD & Cloud Platforms
DevSecOps Engineer: Secure CI/CD & Cloud Platforms

AAA Auto Club Enterprises • Costa Mesa (CA)

On-site
USD 109,000 - 146,000
Health coverage (medical, dental, vis​
401(K) with company match and Pension
Tuition assistance
+4