Associate Director – Application Security

Jobtailor

New Jersey

On-site

USD 120,000 - 160,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Jobtailor is seeking a security-minded DevSecOps engineer to design, deploy, and operate enterprise artifact repositories across cloud and hybrid environments. You will enforce curation, trust models, and governance for dependencies and artifacts while collaborating with AppSec, platform, and engineering teams.

You will integrate repositories with GitHub, Jenkins, and Azure DevOps pipelines, embed AI/ML security controls, and help establish secure-by-design AI architectures with engineering

Qualifications

  • 3–6 years of experience in DevSecOps, platform security, or software supply chain security.
  • Experience deploying and managing enterprise artifact repositories.

Responsibilities

  • Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments
  • ,
  • ,
  • ,
  • ] ,
  • CoT_job_summary_short

Skills

DevSecOps
Platform security
Software supply chain security
AI governance
Cloud security

Tools

JFrog Artifactory
GitHub
Jenkins
Azure DevOps
Terraform
Python
Groovy

Job description

  • Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments
  • Define and enforce package curation, promotion, and trust models
  • Implement and govern waiver and approval workflows for dependency and artifact usage
  • Partner with AppSec, platform, and engineering teams to standardize secure dependency and artifact consumption
  • Define and maintain repository architectures across environments, teams, and trust boundaries
  • Enforce artifact immutability, provenance, versioning, and trusted sourcing policies
  • Integrate artifact repositories into GitHub, Jenkins, and Azure DevOps CI/CD pipelines
  • Embed security controls for AI/ML and GenAI workloads in CI/CD pipelines and developer workflows
  • Define secure usage patterns for LLMs and AI services
  • Implement safeguards against prompt injection, model poisoning, data leakage, and insecure model outputs
  • Integrate AI security scanning and validation into build pipelines
  • Establish secure-by-design AI application architectures with engineering teams
  • Ensure compliance with Responsible AI policies
  • Secure AI-related secrets, tokens, and API access
  • Monitor and respond to AI/ML security risks
  • Contribute to AI risk governance, auditability, and SDLC traceability
  • Monitor artifact control usage and risk posture and drive continuous improvement
  • Develop automation and policy-as-code for artifact lifecycle management and governance
  • Support security incident investigations involving software supply chain integrity or dependency risk
  • Create documentation, standards, and enablement materials for secure developer adoption
Requirements
  • 3–6 years of experience in DevSecOps, platform security, or software supply chain security
  • Strong hands-on experience with JFrog Artifactory, including deployment and enterprise architecture
  • Experience designing package curation and promotion models
  • Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle
  • Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage
  • Experience integrating AI or ML components into applications or pipelines
  • Familiarity with Responsible AI principles and AI governance frameworks
  • Experience implementing waiver and approval workflows for dependencies and artifacts
  • Strong understanding of application security principles and dependency risk management
  • Hands‑on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines
  • Experience working in cloud environments (Azure preferred; AWS/GCP acceptable)
  • Proficiency with automation and scripting (Python, Groovy, Terraform, etc.)
  • Knowledge of modern SDLC and DevSecOps operating models
Core Competencies

Demonstrates expertise in DevSecOps practices, focusing on secure artifact repository management and AI/ML security integration. Proficient in implementing governance frameworks and automation for software supply chain integrity.

Tools & Technologies
  • JFrog Artifactory
  • GitHub
  • Jenkins
  • Azure DevOps
  • Terraform
  • Python
  • Groovy
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

Jobtailor • Massachusetts

On-site
USD 140,000 - 180,000
Artifactory Admin/DevOps Engineer
Artifactory Admin/DevOps Engineer

Matlen Silver • Charlotte (NC)

On-site
USD 110,000 - 150,000
Principal, AI Security
Principal, AI Security

Jobtailor • Illinois

On-site
USD 180,000 - 260,000
Principal, Product Security
Principal, Product Security

Jobtailor • Illinois

On-site
USD 140,000 - 200,000
Senior Principal Software Engineer – Eng Tools
Senior Principal Software Engineer – Eng Tools

Jobtailor • United States

On-site
USD 140,000 - 190,000
Lead Engineer – AI Security
Lead Engineer – AI Security

Jobtailor • Brooklyn Park (MN)

On-site
USD 120,000 - 150,000
Senior DevOps & Platform Engineer
Senior DevOps & Platform Engineer

Shrive Technologies LLC • Rahway (NJ)

On-site
USD 140,000 - 190,000
Principal Engineer – AI Security
Principal Engineer – AI Security

Jobtailor • Brooklyn Park (MN)

On-site
USD 180,000 - 260,000
Stock options
Engineering, Cybersecurity, Application Security Engineer, Vice President
Engineering, Cybersecurity, Application Security Engineer, Vice President

TPG Careers Page • Fort Worth (TX)

On-site
USD 230,000 - 320,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000