Global Head of DevOps Services
Chubb
Global Head of DevSecOpsPosition OverviewChubb is seeking an exceptional leader to build and scale our DevSecOps function globally. You'll own the intersection of security, reliability, and developer velocity—architecting automation and enforcement mechanisms that make security invisible to developers while maintaining absolute control and visibility. This is a hands-on technical leadership role for someone who codes, influences, and drives organizational transformation.You'll report directly to the Global Head of Engineering and own the strategic vision for security automation, deployment verification, compliance enforcement, and developer enablement across Chubb's engineering organization. You need to be well versed in AI-enabled software engineering and agentic AI DevSecOps design, deployment and operations. Key ResponsibilitiesAutomation & EnforcementDesign and implement foundational DevSecOps platforms that automate security policy enforcement across CI/CD pipelines, infrastructure-as-code, container registries, and deployment systemsBuild verification systems that provide real-time evidence of compliance, vulnerability remediation, and security posture—eliminating manual auditsEstablish automation-first culture: every security control must be code-driven, testable, and self-serviceLead technical architecture decisions for secrets management, supply chain security, and artifact signingAI native software engineering expertDeveloper ExperienceMake security frictionless: design tools and workflows so developers want to follow security practicesOwn the "shift left" strategy—move security testing, scanning, and validation to local development and early CI stagesBuild dashboards, APIs, and CLIs that give developers transparency into their security posture without overwhelming themChampion zero-friction onboarding: new engineers should inherit secure defaults with minimal trainingHands-On Technical LeadershipCode regularly in your areas of leverage Pair with teams on high-impact automation projects; stay in the trenches on the hardest technical problemsOwn critical-path infrastructure: build and maintain your team's CI/CD platforms, secrets systems, and policy enginesDrive incident response for security and reliability issues; be the expert responder, not just the directorOrganizational Influence & ChangePartner with engineering leaders to shift security ownership: security is not a gate, it's engineering cultureCommunicate transparently about risk, tradeoffs, and implementation status—especially when timelines slip or priorities conflictEnforce standards without being perceived as a blocker; design policies that developers will adopt voluntarilyBuild a high-impact, lean team (likely 8–15 leads) that punches well above its weightCompliance & RiskOwn the evidence and documentation for SOC 2, ISO 27001, and regulatory audits—automate away manual compliance workDrive continuous verification of security controls; eliminate the painful spring auditsPartner with Enterprise Risk and Legal on policy, but ensure the technical implementation is soundWhat We're Looking ForTechnical Chops12+ years of software engineering and DevOps experience; 5+ years building or scaling security/compliance automation at significant scale (100+ engineers)Strong coding skills across multiple languages; comfortable shipping production code and debugging in productionDeep hands-on knowledge of: Kubernetes/container orchestration, CI/CD systems (GitHub Actions, Jenkins, Ansible are a must), policy-as-code (OPA), infrastructure-as-code, secrets managementExperience designing and owning high-availability, high-observability systems that must earn trustLeadership & InfluenceProven track record of building and scaling engineering teams through hiring, mentorship, and technical directionAbility to influence without authority: cross-functional alignment with product, infra, and risk teamsComfort in ambiguity; can prioritize ruthlessly and say "no" to protect team capacityTrack record of driving organizational change in security/compliance without frictionMindsetAutomation obsessive: if it's done manually more than twice, it's a problemTransparency and directness: you communicate bad news early, explain tradeoffs, and own mistakesDeveloper-first thinking: you remember what it's like to be blocked by security and you solve for thatLearning hunger: security and DevOps evolve constantly; you stay sharp and drive continuous improvement Chubb is a world leader in insurance. With operations in 54 countries, Chubb provides commercial and personal property and casualty insurance, personal accident and supplemental health insurance, reinsurance, and life insurance to a diverse group of clients. The company is distinguished by its extensive product and service offerings, broad distribution capabilities, exceptional financial strength, underwriting excellence, superior claims handling expertise and local operations globally. At Chubb, we are committed to equal employment opportunity and compliance with all laws and regulations pertaining to it. Our policy is to provide employment, training, compensation, promotion, and other conditions or opportunities of employment, without regard to race, color, religious creed, sex, gender, gender identity, gender expression, sexual orientation, marital status, national origin, ancestry, mental and physical disability, medical condition, genetic information, military and veteran status, age, and pregnancy or any other characteristic protected by law. Performance and qualifications are the only basis upon which we hire, assign, promote, compensate, develop and retain employees. Chubb prohibits all unlawful discrimination, harassment and retaliation against any individual who reports discrimination or harassment. Required5+ years in DevSecOps, platform engineering, or security engineering roles at scale (100+ engineers)Production experience with Kubernetes and container securityHands-on experience with policy-as-code, scanning (SAST, DAST, SCA), and secrets managementExperience designing and communicating compliance/audit evidence to non-technical stakeholdersBachelor's degree in Computer Science, Engineering, or equivalent professional experiencePreferredExperience at a regulated industry (financial services, healthcare, insurance)Background in incident response or security operationsOpen source contributions in DevSecOps or infrastructure toolingFamiliarity with zero-trust architecture or advanced threat detectionFamiliarity with financial services compliance (SOC 2, PCI, NIST)What Success Looks Like (Year 1)Security scan and policy checks are fully automated in all CI/CD pipelines; zero manual approval gatesDeveloper experience surveys show
Reference: WJ-5640_467365