DevOps Engineer

Sanderson

Greater London

Hybrid

GBP 90,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Sanderson seeks a Senior DevSecOps Engineer to secure agentic AI workloads and the middle-office integration in a UK wealth-management context. The role sits within security architecture and engineering, bridging AI enablement, supplier selection, and delivery.

You will shape the evolving provider model and ensure robust security controls across multiple domains. The position requires hands-on cloud security, proficiency with AWS, familiarity with LLM risk controls, and strong threat modelling

Qualifications

  • Hands-on security engineering in cloud environments (AWS preferred).
  • Engineering-level understanding of LLM and agentic AI risks and controls.

Responsibilities

  • Implement agentic AI security controls: identity, delegated authority, audit trails.
  • Test defences against prompt injection and unsafe tool usage.
  • Design integration security for providers: authentication, encryption, key ownership, logging.
  • Ensure data flows meet FCA outsourcing and resilience requirements.
  • Deliver security evidence to governance and architecture records.
  • Create reusable security patterns for delivery teams.

Skills

AWS security
OAuth2/OIDC
Threat modelling
Python coding
Vendor security
LLM security
Bedrock integration

Tools

Bedrock

Job description

Senior DevSecOps Engineer – Agentic AI & Middle Office Transformation
  • London, 1 day per week on site, flexible to fully remote
  • 1 stage interview
  • Candidates must be UK Based Residents

A major UK wealth management business is bringing agentic AI into both its delivery practices and its middle-office operations, while also selecting a new middle-office platform provider. Both changes alter the trust model: agents act with delegated authority, and a third party will process data underpinning client assets and the ledger. This role makes sure the controls for both are designed early and implemented properly as the provider and delivery model mature.

The role reports into security architecture and engineering, and sits between AI enablement, supplier selection and integration delivery. The provider decision and parts of the delivery model are still forming, so there is genuine scope to shape them.

What you will do
Agentic AI security
  • Implement controls for agentic workloads: agent identity and delegated authority via OAuth token exchange, least-privilege tool scopes, human approval for consequential actions, and attributable audit trails of agent actions.
  • Engineer and adversarially test defences against prompt injection, excessive agency, sensitive data leakage and unsafe tool use.
  • Build and operate controls around model and tool access, including MCP gateway policy, model access through Amazon Bedrock with region and data-residency enforcement, and restrictions on computer-use capabilities.
  • Threat model AI systems using MAESTRO and OWASP guidance for LLM and agentic applications, turning the output into backlog items rather than documents.
  • Contribute engineering evidence to AI governance and architecture decision records, aligned to NIST AI RMF and ISO/IEC 42001.
  • Build reusable security control patterns spanning employee, client-facing and SaaS AI use cases, including AI coding assistants and enterprise LLM platforms.
Middle office and vendor assurance
  • Provide the security engineering input into middle-office provider selection: technical due diligence, architecture review, and testing supplier claims rather than accepting questionnaire answers at face value.
  • Design and implement integration security for the selected provider — authentication, connectivity, encryption and key ownership, data minimisation, logging, and a workable exit position.
  • Make sure middle-office data flows across the ledger, holdings and market data meet internal data handling standards, integrity expectations for client asset records, and FCA outsourcing and operational resilience requirements.
Delivery
  • Work inside the agentic and middle-office delivery teams so security decisions happen during the sprint rather than after it.
  • Work with data teams on classification, entitlements and access boundaries for middle-office data.
  • Produce CAB-ready evidence for AI and integration changes.
  • Produce AI security patterns, reusable tooling guidance and agent control requirements that delivery teams can adopt consistently.
What you will bring
  • Substantial hands-on security engineering experience in cloud environments, AWS preferred, including securing third-party and SaaS integrations.
  • A practical, engineering-level understanding of LLM and agentic AI risks and the controls that address them.
  • Strong OAuth2 and OIDC, token exchange, workload identity and API security knowledge.
  • Experience carrying out technical security assessments of suppliers.
  • Threat modelling experience on real systems.
  • Enough coding ability, Python preferred, to build and test guardrails yourself.
  • Comfort working where requirements and the supplier landscape are still settling.
  • Amazon Bedrock, Model Context Protocol and agent frameworks.
  • Spec-driven development and contributing security acceptance criteria to product requirements.
  • Financial services middle or back office: settlements, reconciliations, ledgers and client asset (CASS) considerations.
  • OWASP Top 10 for LLM Applications, MAESTRO and structured threat modelling tooling.
  • NIST AI RMF, ISO/IEC 42001 and EU AI Act awareness.
  • AWS Certified Security – Specialty, CCSK, CISSP or an AI security credential.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Platform Engineer
Platform Engineer

Sanderson • Greater London

Hybrid
GBP 70,000 - 100,000
Principal AI Security Software Engineer
Principal AI Security Software Engineer

SGI • Greater London

On-site
GBP 134,000 - 148,000
Principal AI Security Software Engineer
Principal AI Security Software Engineer

Source Technology Limited • Greater London

On-site
GBP 189,000 - 208,000
Security Architect (Agentic Identity & Access)
Security Architect (Agentic Identity & Access)

Intellias • Greater London

On-site
GBP 120,000 - 180,000
Senior AI Security Engineer
Senior AI Security Engineer

Experis - ManpowerGroup • Greater London

Hybrid
GBP 25,461,000 - 27,583,000
Hybrid work model
Senior AI Security Engineer
Senior AI Security Engineer

Experis • Greater London

Hybrid
GBP 111,000 - 120,000
Senior AI Security Engineer
Senior AI Security Engineer

Experis UK • Greater London

Hybrid
GBP 111,000 - 120,000
Solution Architect (Agentic Identity & Access Security)
Solution Architect (Agentic Identity & Access Security)

Intellias • Greater London

On-site
GBP 120,000 - 190,000
Agentic / LLM systems exposure
MCP integration
Just-in-time delegation
+3
Senior DevSecOps Engineer – AI Security & Middle Office
Senior DevSecOps Engineer – AI Security & Middle Office

Sanderson • Greater London

Hybrid
GBP 90,000 - 120,000
AI Security Architect
AI Security Architect

Polo • City Of London

On-site
GBP 75,000 - 85,000