
Associate Director - Application Security
S&P Global4 days ago
Base Salary
$125k - $165k/yr
Responsibilities
- Design, deploy, and operate enterprise artifact repository platforms for cloud and hybrid environments.
- Define package curation, promotion, trust, waiver, and approval models for dependencies and artifacts.
- Maintain repository architectures across multiple environments, teams, and trust boundaries.
- Enforce artifact immutability, provenance, versioning, trusted sourcing, and dependency risk controls.
- Integrate artifact repositories into GitHub, Jenkins, and Azure DevOps pipelines.
- Embed security controls, scanning, validation, secrets protection, and access controls for AI/ML and GenAI workloads.
- Develop safeguards against prompt injection, model poisoning, data leakage, insecure model outputs, and other AI-specific threats.
- Develop automation and policy-as-code for artifact lifecycle management, approvals, and governance.
- Monitor risk posture and respond to incidents involving software supply chain integrity or dependency risk.
- Support Responsible AI governance, auditability, traceability, documentation, standards, and secure developer adoption.
Requirements
- 3–6 years of experience in DevSecOps, platform security, or software supply chain security.
- Strong hands-on experience deploying and architecting JFrog Artifactory in enterprise environments.
- Experience designing package curation and promotion models and implementing dependency and artifact waiver workflows.
- Foundational understanding of AI/ML, Generative AI, LLMs, and model lifecycles.
- Knowledge of AI/ML security risks including prompt injection, data poisoning, model evasion, and data leakage.
- Experience integrating AI or ML components into applications or pipelines is preferred.
- Familiarity with Responsible AI principles and AI governance frameworks.
- Strong understanding of application security and dependency risk management.
- Hands-on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines.
- Experience with cloud environments; Azure is preferred, while AWS and GCP are acceptable.
- Proficiency with automation and scripting, including Python, Groovy, or Terraform.
- Knowledge of modern SDLC and DevSecOps operating models.
Benefits
- Health care coverage and wellness benefits.
- Generous paid time off and flexible downtime.
- Continuous learning resources and career development support.
- Retirement planning, continuing education, company-matched student loan contributions, and financial wellness programs.
- Family-oriented perks, retail discounts, and referral incentive awards.
- Eligible for an annual incentive plan and additional S&P Global benefits.