Sr. Manager, DevSecOps
Job description
About the role
DoubleVerify is on the lookout for a Senior Manager to join our DevSecOps team. This role is in guiding our engineers to weave security practices into our DevOps workflows, continuous integration and delivery (CI/CD) pipelines, and artificial intelligence/machine learning (AI/ML) processes. The selected candidate will play a crucial role in ensuring that software delivery is both secure and efficient, while also nurturing a security-first mindset throughout the software development lifecycle.
Key facts
What you'll do
- Lead and mentor several DevSecOps teams, focusing on the recruitment and development of senior engineers to create high-performing units dedicated to security in both traditional and AI-driven projects.
- Safeguard AI/ML pipelines by implementing security measures to protect deployment environments from threats such as prompt injection and data poisoning.
- Create governance frameworks specifically for AI security, establishing policies for the use of large language models (LLMs) and managing risks associated with the AI supply chain.
- Automate the security scanning of AI artifacts and incorporate these checks into CI/CD pipelines, alongside traditional security tools.
- Manage identity and access protocols for AI workloads, ensuring that services and APIs are properly authenticated and encrypted.
- Supervise incident response efforts related to AI security threats, including adversarial attacks and unauthorized access to AI services.
- Ensure adherence to compliance standards such as SOC 2 and ISO 27001 by automating the collection of evidence, particularly in the context of AI governance.
- Formulate and execute a DevSecOps strategy that aligns with organizational objectives and incorporates best practices in AI security.
- Design security architectures that span various teams and infrastructure domains, with a particular focus on AI-specific architectures.
- Drive continuous enhancements in security automation and tooling across diverse workloads.
- Establish metrics to evaluate team performance, security posture, and exposure to AI-related risks.
- Foster a culture of security awareness among engineering, data science, and product teams.
- Collaborate with senior leadership to shape security strategies and cross-departmental initiatives.
Requirements
- A minimum of 5-6 years of experience in Cybersecurity, DevOps, or DevSecOps, with a demonstrated history of leading teams of five or more engineers across various infrastructure domains.
- Proven experience managing teams across multiple functional areas, with authority over processes, tools, and priorities.
- Strong communication skills to effectively convey timelines, scopes, and technical issues to senior management.
- Experience in leading critical incidents and providing strategic guidance during significant security events.
- Accountability for resource allocation and budget management for teams.
Nice to have
- Familiarity with AI/ML security, including knowledge of LLM security, model security, and defenses against adversarial machine learning.
- Understanding of responsible AI frameworks and risk assessment methodologies.
- Expertise in securing model training environments and conducting AI artifact scanning.
Skills & tools
- AI/ML Security: Proficient in LLM security, model protection, and adversarial ML defense strategies.
- AI Governance: Knowledgeable about responsible AI frameworks and risk assessment processes.
- Pipeline Security: Skilled in securing model training environments and implementing AI artifact scanning.
- Identity & Access Management: Competent in API security and token management for AI services.
- Network Security: Familiar with firewalls, intrusion detection systems, and traffic analysis techniques.
- Cloud Platforms: Experienced with GCP, AWS, and OCI, emphasizing security controls.
- CI/CD Tools: Proficient in GitHub Actions, GitLab CI, or Jenkins.
- Container Security: Knowledgeable in Kubernetes and Docker security practices.
- Infrastructure-as-Code: Familiar with Terraform, Ansible, or Crossplane methodologies.
Practical notes
A Bachelor's degree in Computer Science, Information Systems, or a related field is a prerequisite for this position.
The starting salary for this role will be influenced by various factors, including qualifications, experience, location, and internal equity considerations. The anticipated salary range for this position is between $153,000 and $260,000. Additionally, this role is eligible for bonuses, equity, and comprehensive benefits.
We encourage candidates who may not meet every single requirement to apply, as we value diverse experiences and backgrounds.