Platform Engineer

Sanderson

Greater London

Hybrid

GBP 70,000 - 100,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Sanderson in London is seeking a Senior DevOps / DevSecOps Engineer to secure agentic AI workloads and middle-office integrations. The role sits within security architecture and engineering, bridging AI enablement and supplier delivery, with significant influence on governance and controls.

You will implement OAuth2-based access, test against prompt injection, design MCP gateway policies, and ensure data residency while aligning with NIST AI RMF and ISO standards.

Qualifications

  • Hands-on security engineering in cloud environments (AWS preferred).
  • Experience with risk-based AI/LLM security controls.
  • Proficient in OAuth2/OIDC and API security.
  • Ability to perform security assessments of suppliers.
  • Familiar with threat modelling and MAESTRO/OWASP guidance.

Responsibilities

  • Define agentic AI security controls and audit trails.
  • Threat model AI systems and derive backlog items.
  • Lead security input for middle-office provider selection.
  • Design secure integration with provider—auth, encryption, data minimisation.
  • Produce CAB-ready evidence and reusable AI security patterns.

Skills

Cloud security
LLM risk
OAuth2/OIDC
Vendor security
Threat modelling
Python coding
AI frameworks
Security governance

Tools

AWS
Amazon Bedrock
MAESTRO tooling

Job description

Senior DevOps / DevSecOps Engineer – Agentic AI & Middle Office Transformation

  • London, 1 day per week on site, flexible to fully remote
  • 1 stage interview
  • Candidates must be UK Based Residents

A major UK wealth management business is bringing agentic AI into both its delivery practices and its middle-office operations, while also selecting a new middle-office platform provider. Both changes alter the trust model: agents act with delegated authority, and a third party will process data underpinning client assets and the ledger. This role makes sure the controls for both are designed early and implemented properly as the provider and delivery model mature.

The role reports into security architecture and engineering, and sits between AI enablement, supplier selection and integration delivery. The provider decision and parts of the delivery model are still forming, so there is genuine scope to shape them.

What you will do
Agentic AI security
  • Implement controls for agentic workloads: agent identity and delegated authority via OAuth token exchange, least-privilege tool scopes, human approval for consequential actions, and attributable audit trails of agent actions.
  • Engineer and adversarially test defences against prompt injection, excessive agency, sensitive data leakage and unsafe tool use.
  • Build and operate controls around model and tool access, including MCP gateway policy, model access through Amazon Bedrock with region and data-residency enforcement, and restrictions on computer-use capabilities.
  • Threat model AI systems using MAESTRO and OWASP guidance for LLM and agentic applications, turning the output into backlog items rather than documents.
  • Contribute engineering evidence to AI governance and architecture decision records, aligned to NIST AI RMF and ISO/IEC 42001.
  • Build reusable security control patterns spanning employee, client-facing and SaaS AI use cases, including AI coding assistants and enterprise LLM platforms.
Middle office and vendor assurance
  • Provide the security engineering input into middle-office provider selection: technical due diligence, architecture review, and testing supplier claims rather than accepting questionnaire answers at face value.
  • Design and implement integration security for the selected provider — authentication, connectivity, encryption and key ownership, data minimisation, logging, and a workable exit position.
  • Make sure middle-office data flows across the ledger, holdings and market data meet internal data handling standards, integrity expectations for client asset records, and FCA outsourcing and operational resilience requirements.
Delivery
  • Work inside the agentic and middle-office delivery teams so security decisions happen during the sprint rather than after it.
  • Work with data teams on classification, entitlements and access boundaries for middle-office data.
  • Produce CAB-ready evidence for AI and integration changes.
  • Produce AI security patterns, reusable tooling guidance and agent control requirements that delivery teams can adopt consistently.
What you will bring
  • Substantial hands-on security engineering experience in cloud environments, AWS preferred, including securing third-party and SaaS integrations.
  • A practical, engineering-level understanding of LLM and agentic AI risks and the controls that address them.
  • Strong OAuth2 and OIDC, token exchange, workload identity and API security knowledge.
  • Experience carrying out technical security assessments of suppliers.
  • Threat modelling experience on real systems.
  • Enough coding ability, Python preferred, to build and test guardrails yourself.
  • Comfort working where requirements and the supplier landscape are still settling.
  • Amazon Bedrock, Model Context Protocol and agent frameworks.
  • Spec-driven development and contributing security acceptance criteria to product requirements.
  • Financial services middle or back office: settlements, reconciliations, ledgers and client asset (CASS) considerations.
  • OWASP Top 10 for LLM Applications, MAESTRO and structured threat modelling tooling.
  • NIST AI RMF, ISO/IEC 42001 and EU AI Act awareness.
  • AWS Certified Security – Specialty, CCSK, CISSP or an AI security credential.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevOps Engineer
DevOps Engineer

Sanderson • Greater London

Hybrid
GBP 90,000 - 120,000
Principal AI Security Software Engineer
Principal AI Security Software Engineer

SGI • Greater London

On-site
GBP 134,000 - 148,000
Principal AI Security Software Engineer
Principal AI Security Software Engineer

Source Technology Limited • Greater London

On-site
GBP 189,000 - 208,000
Security Architect (Agentic Identity & Access)
Security Architect (Agentic Identity & Access)

Intellias • Greater London

On-site
GBP 120,000 - 180,000
Senior AI Security Engineer
Senior AI Security Engineer

Experis - ManpowerGroup • Greater London

Hybrid
GBP 25,461,000 - 27,583,000
Hybrid work model
Senior AI Security Engineer
Senior AI Security Engineer

Experis • Greater London

Hybrid
GBP 111,000 - 120,000
AI Security Architect
AI Security Architect

Polo • City Of London

On-site
GBP 75,000 - 85,000
AI Security Architect
AI Security Architect

PoloWorks • Greater London

On-site
GBP 75,000 - 85,000
Senior AI Security Engineer
Senior AI Security Engineer

Experis UK • Greater London

Hybrid
GBP 111,000 - 120,000
AI Governance Engineering Lead
AI Governance Engineering Lead

Janus Henderson Group • Greater London

Hybrid
GBP 90,000 - 140,000
Hybrid working
Health and wellbeing benefits
Volunteer time
+3