- Design, deploy, and operate enterprise artifact repository platforms supporting cloud and hybrid environments
- Define and enforce package curation, promotion, and trust models
- Implement and govern waiver and approval workflows for dependency and artifact usage
- Partner with AppSec, platform, and engineering teams to standardize secure dependency and artifact consumption
- Define and maintain repository architectures across environments, teams, and trust boundaries
- Enforce artifact immutability, provenance, versioning, and trusted sourcing policies
- Integrate artifact repositories into GitHub, Jenkins, and Azure DevOps CI/CD pipelines
- Embed security controls for AI/ML and GenAI workloads in CI/CD pipelines and developer workflows
- Define secure usage patterns for LLMs and AI services
- Implement safeguards against prompt injection, model poisoning, data leakage, and insecure model outputs
- Integrate AI security scanning and validation into build pipelines
- Establish secure-by-design AI application architectures with engineering teams
- Ensure compliance with Responsible AI policies
- Secure AI-related secrets, tokens, and API access
- Monitor and respond to AI/ML security risks
- Contribute to AI risk governance, auditability, and SDLC traceability
- Monitor artifact control usage and risk posture and drive continuous improvement
- Develop automation and policy-as-code for artifact lifecycle management and governance
- Support security incident investigations involving software supply chain integrity or dependency risk
- Create documentation, standards, and enablement materials for secure developer adoption
Requirements
- 3–6 years of experience in DevSecOps, platform security, or software supply chain security
- Strong hands-on experience with JFrog Artifactory, including deployment and enterprise architecture
- Experience designing package curation and promotion models
- Foundational understanding of AI/ML and Generative AI concepts, including LLMs and model lifecycle
- Knowledge of AI/ML security risks such as prompt injection, data poisoning, model evasion, and data leakage
- Experience integrating AI or ML components into applications or pipelines
- Familiarity with Responsible AI principles and AI governance frameworks
- Experience implementing waiver and approval workflows for dependencies and artifacts
- Strong understanding of application security principles and dependency risk management
- Hands‑on experience integrating repositories with GitHub, Jenkins, and Azure DevOps pipelines
- Experience working in cloud environments (Azure preferred; AWS/GCP acceptable)
- Proficiency with automation and scripting (Python, Groovy, Terraform, etc.)
- Knowledge of modern SDLC and DevSecOps operating models
Core Competencies
Demonstrates expertise in DevSecOps practices, focusing on secure artifact repository management and AI/ML security integration. Proficient in implementing governance frameworks and automation for software supply chain integrity.
Tools & Technologies
- JFrog Artifactory
- GitHub
- Jenkins
- Azure DevOps
- Terraform
- Python
- Groovy
Associate Director – Application Security in nj at Unknown Company
This position is listed as full time and hybrid.