Lead DevSecOps Engineer
AECOM
In this role you lead security for AI-driven products and platforms from design to production, focusing on secure-by-design practices and risk reduction without slowing delivery. You will own security sign-off for new features, drive threat modelling and CVE remediation, and oversee testing and incident response with cross-functional teams. You’ll shape the security strategy for AI/LLM capabilities, third‑party dependencies, and the cloud stack, influencing engineers and leaders. This position offers high-visibility impact on sustainable infrastructure and the future of AI-enabled building design.
Pay / Benefits- medical, dental, vision
- life and disability benefits
- paid time off and leaves of absence
- voluntary benefits and perks
- flexible work options
- retirement savings plan and employee stock purchase plan
- Run security reviews of new product designs through to launch, using threat modelling to assess architecture and data flows
- Own security for AI and LLM features, define guardrails and testing approaches to mitigate risks
- Secure AI supply chain, assess third-party models, vector stores, and training data usage
- Maintain CVE remediation across the platform, triage vulnerabilities, and coordinate patching with engineering
- Maintain and tune CI/CD security tooling (SAST, SCA, secret scanning, container, IaC) with GitHub Actions and Terraform
- Manage and scoper pen tests, coordinate with external testers, and track remediation to closure
- Strengthen cloud and identity security across Azure and GCP, including IAM, networking, secrets management
- Lead security incident response and post‑incident reviews, keeping runbooks up to date
- Establish a security champions program across engineering teams to share ownership of security
- Hands-on security engineering or related roles with technical leadership
- Experience leading security reviews and threat modelling with clear sign-off decisions
- Vulnerability management and incident response experience including CVE triage
- Maintaining and tuning security scanning tooling in CI/CD (SAST, SCA, secret, container, IaC) with GitHub Actions and Terraform
- End-to-end penetration testing management
- Strong cloud security knowledge in Azure and/or GCP (IAM, networking, secrets)
- Ability to articulate risk and influence engineers and leaders
- Experience in fast-moving teams within a large organization with governance processes
- Clear risk communication
- Influencing without authority
- Collaborative problem-solving
- Threat modelling
- CVE triage and remediation
- SAST, SCA, secret scanning, container security, IaC security
Reference: WJ-747_31002031