S&P Global

Associate Director - Application Security

S&P Global
Apply
4 days ago
Hyderābād, India +2 moreStaff+
H1B sponsor

Base Salary

$125k - $165k/yr

Responsibilities

  • Design, deploy, and operate enterprise artifact repository platforms for cloud and hybrid environments.
  • Define package curation, promotion, trust, waiver, and approval models for dependencies and artifacts.
  • Maintain repository architectures across multiple environments, teams, and trust boundaries.
  • Enforce artifact immutability, provenance, versioning, trusted sourcing, and dependency risk controls.
  • Integrate artifact repositories into GitHub, Jenkins, and Azure DevOps pipelines.
  • Embed security controls, scanning, validation, secrets protection, and access controls for AI/ML and GenAI workloads.
  • Develop safeguards against prompt injection, model poisoning, data leakage, insecure model outputs, and other AI-specific threats.
  • Develop automation and policy-as-code for artifact lifecycle management, approvals, and governance.
  • Monitor risk posture and respond to incidents involving software supply chain integrity or dependency risk.
  • Support Responsible AI governance, auditability, traceability, documentation, standards, and secure developer adoption.

Requirements

  • 3–6 years of experience in DevSecOps, platform security, or software supply chain security.
  • Strong hands-on experience deploying and architecting JFrog Artifactory in enterprise environments.
  • Experience designing package curation and promotion models and implementing dependency and artifact waiver workflows.
  • Foundational understanding of AI/ML, Generative AI, LLMs, and model lifecycles.
  • Knowledge of AI/ML security risks including prompt injection, data poisoning, model evasion, and data leakage.
  • Experience integrating AI or ML components into applications or pipelines is preferred.
  • Familiarity with Responsible AI principles and AI governance frameworks.
  • Strong understanding of application security and dependency risk management.
  • Hands-on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines.
  • Experience with cloud environments; Azure is preferred, while AWS and GCP are acceptable.
  • Proficiency with automation and scripting, including Python, Groovy, or Terraform.
  • Knowledge of modern SDLC and DevSecOps operating models.

Benefits

  • Health care coverage and wellness benefits.
  • Generous paid time off and flexible downtime.
  • Continuous learning resources and career development support.
  • Retirement planning, continuing education, company-matched student loan contributions, and financial wellness programs.
  • Family-oriented perks, retail discounts, and referral incentive awards.
  • Eligible for an annual incentive plan and additional S&P Global benefits.
Contact me