Overview
We are seeking a Senior DevOps/DevSecOps Engineer to join a major UK wealth management firm in their transformation projects involving agentic AI and middle-office operations. This role will focus on implementing security controls for AI workloads and integrating security measures into the new middle-office platform while collaborating with various teams to ensure that security considerations are integrated into the development process. The engineer will work closely with security architecture and engineering teams and will have the opportunity to shape security protocols as the new provider and delivery model are developed.
Responsibilities
- Implement security controls for agentic workloads, including OAuth token exchanges and least-privilege policies.
- Engineer defenses against various AI-related security vulnerabilities.
- Design and operate access controls for AI model usage and enforce data-residency standards.
- Conduct threat modeling for AI systems and translate insights into actionable backlog items.
- Provide security engineering support during middle-office provider selection and integration.
- Ensure compliance with internal data handling standards and regulatory requirements.
- Collaborate with delivery teams to integrate security practices into their workflows.
- Produce reusable security patterns and tooling guidance for adoption in development.
Requirements
- Significant hands-on experience in security engineering, preferably in AWS environments.
- Proficient understanding of LLM and agentic AI security risks and relevant controls.
- Strong knowledge of OAuth2, OIDC, and API security.
- Experienced in conducting technical assessments of third-party suppliers.
- Demonstrated ability in threat modeling on actual systems.
- Proficient in Python or similar languages for implementing security measures.
- Comfortable navigating evolving requirements within the supplier ecosystem.
- Familiarity with NIST AI RMF, ISO/IEC 42001, and relevant compliance frameworks is advantageous.