IT & Software

DevOps Engineer

Sanderson

Remote · Nationwide · United Kingdom

Senior DevSecOps Engineer – Agentic AI & Middle Office Transformation


  • £1,000 per day, Outside IR35
  • London, 1 day per week on site, flexible to fully remote
  • 1 stage interview
  • Candidates must be UK Based Residents


A major UK wealth management business is bringing agentic AI into both its delivery practices and its middle-office operations, while also selecting a new middle-office platform provider. Both changes alter the trust model: agents act with delegated authority, and a third party will process data underpinning client assets and the ledger. This role makes sure the controls for both are designed early and implemented properly as the provider and delivery model mature.


The role reports into security architecture and engineering, and sits between AI enablement, supplier selection and integration delivery. The provider decision and parts of the delivery model are still forming, so there is genuine scope to shape them.


What you will do


Agentic AI security:

  • Implement controls for agentic workloads: agent identity and delegated authority via OAuth token exchange, least-privilege tool scopes, human approval for consequential actions, and attributable audit trails of agent actions.
  • Engineer and adversarially test defences against prompt injection, excessive agency, sensitive data leakage and unsafe tool use.
  • Build and operate controls around model and tool access, including MCP gateway policy, model access through Amazon Bedrock with region and data-residency enforcement, and restrictions on computer-use capabilities.
  • Threat model AI systems using MAESTRO and OWASP guidance for LLM and agentic applications, turning the output into backlog items rather than documents.
  • Contribute engineering evidence to AI governance and architecture decision records, aligned to NIST AI RMF and ISO/IEC 42001.
  • Build reusable security control patterns spanning employee, client-facing and SaaS AI use cases, including AI coding assistants and enterprise LLM platforms.


Middle office and vendor assurance:

  • Provide the security engineering input into middle-office provider selection: technical due diligence, architecture review, and testing supplier claims rather than accepting questionnaire answers at face value.
  • Design and implement integration security for the selected provider — authentication, connectivity, encryption and key ownership, data minimisation, logging, and a workable exit position.
  • Make sure middle-office data flows across the ledger, holdings and market data meet internal data handling standards, integrity expectations for client asset records, and FCA outsourcing and operational resilience requirements.


Delivery

  • Work inside the agentic and middle-office delivery teams so security decisions happen during the sprint rather than after it.
  • Work with data teams on classification, entitlements and access boundaries for middle-office data.
  • Produce CAB-ready evidence for AI and integration changes.
  • Produce AI security patterns, reusable tooling guidance and agent control requirements that delivery teams can adopt consistently.


What you will bring


Essential:

  • Substantial hands-on security engineering experience in cloud environments, AWS preferred, including securing third-party and SaaS integrations.
  • A practical, engineering-level understanding of LLM and agentic AI risks and the controls that address them.
  • Strong OAuth2 and OIDC, token exchange, workload identity and API security knowledge.
  • Experience carrying out technical security assessments of suppliers.
  • Threat modelling experience on real systems.
  • Enough coding ability, Python preferred, to build and test guardrails yourself.
  • Comfort working where requirements and the supplier landscape are still settling.


Desirable:

  • Amazon Bedrock, Model Context Protocol and agent frameworks.
  • Spec-driven development and contributing security acceptance criteria to product requirements.
  • Financial services middle or back office: settlements, reconciliations, ledgers and client asset (CASS) considerations.
  • OWASP Top 10 for LLM Applications, MAESTRO and structured threat modelling tooling.
  • NIST AI RMF, ISO/IEC 42001 and EU AI Act awareness.
  • AWS Certified Security – Specialty, CCSK, CISSP or an AI security credential.


Reference: WJ-747_30283510

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.