yoinka

Director, Cybersecurity Engineering Lead

BlackRock

New York, NYStaff
Sign in to applyVerified 2h ago
Location
New York, NY
Work model
On-Site
Level
Staff
Posted
14h ago

Skills

CI/CDCybersecurity

About this role

About this role The Aladdin Platform Engineering – Engineering Services team builds the platforms, pipelines, and developer tooling that thousands of engineers across BlackRock use every day to design, build, and ship software. Security is engineered into that path rather than inspected at the end of it: the same teams that own build systems, artifact repositories, and deployment pipelines also own the guardrails, evidence, and automated controls that make secure delivery the default. You will lead the cybersecurity engineering function inside this group, working alongside platform engineering, product management, risk, and the firm’s information security organization to protect a large, cloud-native, AI-enabled, highly regulated financial services firm. Your role and impact As Director for Cybersecurity Engineering, you’ll set the technical strategy for how security is built into software delivery and cloud infrastructure at scale. Software supply chain integrity is your first principle: every artifact the firm ships should carry verifiable provenance, and every release should be attested — signed, traceable to its source and build environment, and admissible as evidence without anyone assembling it after the fact. You’ll lead BlackRock toward that future state, moving the organization from periodic inspection of what was built to continuous, cryptographic proof of how it was built, with trust decisions made against attestations rather than assumptions. You’ll treat DevSecOps as the operating principle that makes this achievable — policy as code, automated enforcement in continuous integration and delivery pipelines, and time-boxed exceptions with audit-ready evidence generated automatically. You’ll extend that same provenance and trust model to AI-assisted development and agentic workflows, where model-generated code, prompt injection, and non-human identities create new classes of exposure and demand policy-driven defense in depth.

Your responsibilities

No matter your role at BlackRock, you’ll be expected to apply sound judgement and critical thinking to solve complex problems, stay curious and adaptable as the business evolves, and take end-to-end ownership of outcomes that matter to clients. The scope of this role also includes the following responsibilities: Own the software supply chain security strategy end to end — source integrity, dependency and artifact provenance, software bills of materials, signing, and verifiable build attestation across the firm’s technology estate Secure the build and release path itself, hardening build systems, artifact repositories, and deployment pipelines as high-value targets, and enforcing trust decisions at admission based on attested provenance rather than implicit trust Define and implement the security model for agentic and AI-assisted workflows — least-privilege identities for agents, bounded model and data access, provenance for machine-generated code, and guardrails that hold as autonomy increases Embed automated controls across the delivery lifecycle, including threat modeling, static and dynamic analysis, software composition analysis, and container and infrastructure-as-code scanning, with clear rules for what blocks versus warns Partner with information security, risk, and audit to translate regulatory and control requirements into engineered, continuously evidenced guardrails, and report progress, coverage, and residual risk to senior technology and business leaders Build, lead, and mentor a team of security engineers, and grow a network of security champions embedded in delivery teams You have… 10+ years in security engineering, platform engineering, or application security, including experience leading teams in a large, regulated enterprise Deep, hands-on understanding of software supply chain security — build provenance and attestation, artifact signing and verification, dependency risk, and secure software development lifecycle

Director, Cybersecurity Engineering Lead at BlackRock, New York, NY | Yoinka