Back to jobs
New

Senior Manager, DevSecOps

NYC Global HQ

Senior Manager, DevSecOps

What you'll do

We are looking for a Senior Manager, DevSecOps to lead a group of engineers working across multiple teams integrating security into our DevOps, CI/CD, IaC pipelines, and AI/ML workloads, ensuring secure, compliant, and efficient software delivery across the organization.

As a DevSecOps Sr. Manager at DoubleVerify, you will oversee technical design and execution across multiple functional areas while providing strategic leadership on DevSecOps best practices, cloud-native security, AI/ML security, and automation. You will lead teams of 2-5+ DevSecOps and security engineers across multiple infrastructure areas, fostering a culture of security throughout the software development lifecycle (SDLC) and AI/ML pipelines.

This role requires balancing technical depth in areas such as Infrastructure-as-Code (IaC), container security, and AI security with strategic leadership to drive security initiatives across the organization. The ideal candidate will serve as a technical leader who can architect secure solutions for both traditional and AI workloads, develop their teams' capabilities, and work cross-functionally with engineering teams to embed security practices into every stage of development, deployment, and AI model lifecycle.

Who we are

DoubleVerify is a big data and analytics company. We track and analyze tens of billions of ads every day for the biggest brands in the world like Apple, Nike, AT&T, Disney, Vodafone, and most of the Fortune 500 companies. If you ever saw an Ad online via Web, Mobile, or CTV device then there are chances that it was analyzed by us.

We operate at a massive scale, our backend handles over 100B+ events per day, we analyze and process those events in real-time while making decisions on the environment where the ad is running and all the user interactions during the Ad display lifecycle. We verify that all Ads are Fraud Free, Brand Safe, in the right Geo and highly likely to be viewed and engaged, all that in  in under 10ms.

We are global, we have R&D centers in New York, Paris, London, Munich, Belgium, and more. If you like to solve big data challenges and want to help us build a better industry then your place is with us.

We in DoubleVerify believe that giving hiring people with a broad range of technical skillsets results in the highest satisfaction for our engineers and a strong return on investment for the company. We want people who love the idea of building secure automation tools and platforms that enable our developers to ship code safely and efficiently.

Responsibilities will include:

  • Manage and lead multiple DevSecOps teams, mentor and hire senior DevSecOps and security engineers, building high-performing teams focused on security excellence across traditional and AI workloads.
  • Secure AI/ML pipelines and infrastructure by implementing security controls for model deployment environments, ensuring protection against AI-specific threats such as prompt injection, data poisoning, and model extraction.
  • Establish AI security governance frameworks including policies for LLM usage, RAG (Retrieval Augmented Generation) systems security, MCP (Model Context Protocol) security, and AI supply chain risk management.
  • Implement automated security scanning for AI artifacts including model files, training datasets, and AI-generated code, integrating these checks into CI/CD pipelines alongside traditional SAST, DAST, and SCA tools.
  • Oversee security for AI workload identity and access management, ensuring proper authentication, authorization, and encryption for AI services, APIs, and vector databases used in RAG systems.
  • Lead AI security incident response for threats specific to AI/ML systems including adversarial attacks, model theft, data leakage through LLM outputs, and unauthorized AI service usage.
  • Ensure adherence to compliance standards such as SOC 2, ISO 27001, SOX, and MRC by automating compliance evidence collection, with special focus on AI governance and responsible AI principles.
  • Define and execute DevSecOps strategy aligned with business objectives, security requirements, and emerging AI security best practices across the organization.
  • Create architecture designs for security systems and services spanning multiple teams and infrastructure areas, including AI-specific security architectures.
  • Drive continuous improvement of security automation, AI security tooling, and processes across traditional and AI workloads.
  • Establish security metrics and KPIs to measure team effectiveness, security posture, and AI risk exposure.
  • Foster a culture of security awareness and AI security best practices across engineering, data science, and product teams.
  • Collaborate with senior/executive management regularly on security strategy, AI risk management, and cross-organizational security initiatives.

Who you are

Experience & Leadership:

  • 5-6+ years of experience in Cybersecurity/DevOps, or DevSecOps, with proven experience leading security teams of ~5+ engineers across multiple infrastructure areas.
  • Leads teams of two or more functional areas with authority over team processes, tools, and priorities; decisions may jeopardize business activities.
  • Regularly interacts with senior/executive management, communicating timeline, scope, and technical concerns to all stakeholders.
  • Leads Sev1/2 incidents for team's areas of responsibility and provides strategic direction during major security events.
  • Exercises supervision over costs, methods, and staffing with responsibility for resource utilization and budget for teams; may have subordinate supervisors or team leads.
  • Bachelor's degree in Computer Science, Information Systems, or equivalent experience in a related field.

 

DevSecOps Technical Expertise:

  • AI/ML Security: LLM security (prompt injection, jailbreaking, data leakage), model security, AI supply chain security, adversarial ML defense, RAG system security, vector database security, MCP security.
  • AI Governance & Compliance: Responsible AI frameworks, AI risk assessment, model governance, AI audit trails, privacy-preserving ML techniques.
  • AI Pipeline Security: Securing model training environments, ML pipeline security, model versioning and provenance, AI artifact scanning, AI workload isolation.
  • AI Identity & Access: AI service authentication, API security for AI endpoints, token management for LLM services, workload identity for AI inference.
  • Network Security: Firewalls, segmentation, intrusion detection/prevention systems, AI traffic analysis.
  • Encryption and Cryptography: TLS/SSL, certificate management, encryption at rest and in transit, secure model storage.
  • Identity and Access Management: IAM, Keycloak, Teleport, Workload Identity, AI service accounts.
  • Operating System Security: Hardening, patch management, compliance frameworks.
  • Application Security: Container security, Kubernetes security policies, SAST, DAST, SCA tools, AI-generated code scanning.
  • Threat Intelligence and Analysis: Vulnerability scanning, AI threat detection, adversarial attack detection.
  • Incident Response and Forensics: Security incident handling, AI-specific incident investigation, model forensics.
  • Risk Management and Compliance: SOC2, ISO 27001, SOX, AI governance frameworks, audit preparation and evidence collection.
  • Security Architecture and Design: Zero Trust principles, defense in depth strategies, AI security architecture patterns.
  • Automation and Scripting: Security automation, ACME, certbot, Python, Bash, AI security tooling automation.
  • Cloud Security: GCP, AWS, OCI security controls and best practices, AI service security configurations.

 

Platform & Tooling:

  • AI/ML Platforms: Vertex AI, SageMaker, Azure ML security configurations, LLM API security (OpenAI, Anthropic, Google AI), vector database security (Qdrant, Pinecone, Weaviate, ChromaDB).
  • AI Security Tools: AI red teaming tools, prompt injection detection, model scanning tools, AI observability and monitoring platforms, AI governance platforms.
  • AI Development Tools: LangChain security, LlamaIndex security, AI agent framework security, model registry security, MLflow security.
  • Cloud Platforms: GCP, AWS, OCI with expertise in cloud-native security controls, AI service configurations, and AI workload security.
  • CI/CD: GitHub Actions, GitLab CI, or Jenkins, and Harness with AI security integrations.
  • Container Orchestration: Kubernetes and Docker, with focus on container security and AI workload orchestration.
  • Infrastructure-as-Code (IaC): Terraform, Ansible, or Crossplane for both traditional and AI infrastructure.

 

Leadership & Management:

 

  • Creates architecture designs for systems and services spanning multiple teams and infrastructure areas.
  • Researches new technologies and evaluates for adoption, particularly in AI security domain.
  • Provides blueprints for new services and capabilities across teams.
  • Creates epics and prioritizes work across multiple teams with strong expertise in primary specialization and working knowledge of others.
  • Excellent communication and stakeholder management skills with ability to influence cross-functional teams and senior leadership.
  • Proven ability to balance technical execution with strategic planning, team development, and business objectives.

Resume Keywords

Highest

 

DevSecOps AI Security LLM Security Security CI/CD Infrastructure as Code (IaC) Cloud Security Application Security Vulnerability Management Compliance Automation SOC 2 ISO 27001

 

Medium

 

AI/ML Security Model Security RAG Security Prompt Injection SAST DAST SCA Container Security Kubernetes Security Threat Modeling Terraform Ansible AWS GCP Vertex AI SageMaker

 

Low

Vector Database Security AI Governance Adversarial ML Model Provenance SonarQube Snyk Aqua Security Twistlock Puppet Harness PCI HIPAA LangChain MLflow



The successful candidate’s starting salary will be determined based on a number of non-discriminating factors, including qualifications for the role, level, skills, experience, location, and balancing internal equity relative to peers at DV.
The estimated salary range for this role based on the qualifications set forth in the job description is between $131,000 - $260,000 This role will also be eligible for bonus/commission (as applicable), equity, and benefits.
The range above is for the expectations as laid out in the job description; however, we are often open to a wide variety of profiles, and recognize that the person we hire may be more or less experienced than this job description as posted.

Not-so-fun fact: Research shows that while men apply to jobs when they meet an average of 60% of job criteria, women and other marginalized groups tend to only apply when they check every box. So if you think you have what it takes but you’re not sure that you check every box, apply anyway!

 

Create a Job Alert

Interested in building your career at DoubleVerify? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...

Let us know where you saw DV

Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in DoubleVerify’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.