Overview
This position for a Senior DevSecOps Engineer focuses on integrating agentic AI into a major UK's wealth management business while enhancing their middle-office operations. The contractor will work closely with security architecture and engineering teams to implement early controls for AI workloads and ensure secure integration practices with third-party vendors, adapting to evolving requirements. The role includes significant involvement in shaping security measures as the delivery model matures and reports directly to the security architecture team.
Responsibilities
- Implement controls for agentic workloads, including identity management and audit trails.
- Engineer and test defenses against AI-related security threats.
- Build and operate access control systems for AI model and tool usage.
- Threat model AI systems based on established guidance.
- Provide security engineering insights for middle-office provider selection and integration.
- Ensure compliance with internal data handling standards and regulatory requirements.
- Collaborate with delivery teams to embed security practices during sprints.
- Develop reusable security patterns and tooling guidance for AI and integration changes.
Requirements
- Substantial hands-on experience in security engineering within cloud environments, preferably AWS.
- In-depth understanding of LLM and agentic AI security risks and their mitigations.
- Strong knowledge of OAuth2, OIDC, API security, and token exchange.
- Experience conducting technical security assessments of third-party suppliers.
- Proven threat modeling experience on actual systems.
- Proficiency in Python for building and testing security measures.
- Familiarity with evolving requirements in a dynamic supplier landscape.
- Desirable knowledge of Amazon Bedrock and financial services middle office operations.