NineTech
Application Security Engineer/AI Security

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Application Security Engineer – Agentic AI / DevSecOps
6 MONTH CONTRACT
£600 P/D
REMOTE
About the Role
We are seeking an experienced Application Security Engineer to join a leading financial services organisation and help drive the secure adoption of Generative AI, Large Language Models (LLMs) and Agentic AI across the software development lifecycle.
The role is focused on shift-left Application Security and DevSecOps, with particular emphasis on securing AI-assisted development, AI-generated code, and AI-driven vulnerability remediation. You will work closely with software engineering, DevOps, cloud, architecture, data, and security teams to embed security into development pipelines and establish secure patterns for emerging AI technologies.
Key Responsibilities
- Embed Application Security and DevSecOps practices throughout the SDLC, from design and development through testing, deployment, and production.
- Integrate and automate SAST, DAST, SCA, secrets scanning, API, container, and Infrastructure-as-Code security within CI/CD pipelines.
- Partner with developers and architects to identify vulnerabilities, conduct threat modelling, and implement secure-by-design solutions.
- Review AI-generated and AI-assisted code for vulnerabilities, insecure coding practices, dependency risks, secrets exposure, and data leakage.
- Develop workflows for AI-assisted vulnerability remediation, including automated recommendations, code changes, testing, and validation.
- Establish appropriate human-in-the-loop controls to validate AI-generated security fixes before deployment.
- Define security guardrails for the use of AI coding assistants, GenAI development tools, and AI-enabled engineering platforms.
- Assess and secure LLM applications, RAG solutions, vector databases, model APIs, and AI platforms.
- Perform security assessments of Agentic AI systems, including agents interacting with APIs, enterprise applications, databases, cloud services, and external tools.
- Identify and mitigate AI-specific threats including prompt injection, indirect prompt injection, sensitive-data leakage, excessive agency, insecure output handling, privilege escalation, and unauthorised actions.
- Design appropriate identity, authentication, authorisation, and least-privilege controls for AI agents and their tools.
- Develop security guardrails, monitoring, and detection capabilities for agentic workflows.
- Automate vulnerability discovery, prioritisation, remediation, and verification using Python or other suitable programming languages.
- Support secure cloud-native development across AWS, Azure, and/or GCP, including APIs, microservices, containers, and Kubernetes.
- Implement software supply-chain security practices covering dependencies, artifacts, SBOMs, and third-party components.
- Conduct application and AI security reviews and provide practical remediation guidance to engineering teams.
- Develop security standards, reference architectures, threat models, and reusable security patterns.
- Work with Risk, Compliance, Privacy, and Architecture teams to ensure AI-enabled applications meet organisational and regulatory requirements.
- Monitor emerging LLM, GenAI, and Agentic AI attack techniques and translate them into effective security controls.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential Experience
- Strong professional experience in Application Security, Product Security, DevSecOps, or Software Security Engineering.
- Strong programming/software development experience in one or more of Python, Java, JavaScript/TypeScript, Go, C#, or C/C++.
- Hands-on experience embedding security into CI/CD pipelines and developer workflows.
- Strong knowledge of OWASP Top 10, secure coding, and modern application vulnerabilities.
- Experience with SAST, DAST, SCA, secrets scanning, API security, container security, and IaC security.
- Strong understanding of REST APIs, microservices, cloud-native architectures, and Git-based development.
- Experience working directly with developers to investigate and remediate vulnerabilities.
- Practical understanding of Generative AI and LLM application security.
- Knowledge of AI-generated code, prompt injection, RAG security, and LLM application threats.
- Understanding of Agentic AI, AI agents, function/tool calling, and agent permissions.
- Strong understanding of IAM, authentication, authorisation, secrets management, and least-privilege principles.
- Excellent analytical, troubleshooting, and problem-solving skills.
Desirable Experience
- Experience securing enterprise GenAI or Agentic AI platforms.
- Experience with LLM security testing or AI red teaming.
- Familiarity with OWASP Top 10 for LLM Applications, OWASP GenAI Security, MITRE ATLAS, and NIST AI RMF.
- Experience with RAG, vector databases, embeddings, LLM gateways, and model APIs.
- Experience with MCP (Model Context Protocol) or similar agent-to-tool integration technologies.
- Experience with Kubernetes, Docker, and cloud security.
- Terraform or other Infrastructure-as-Code experience.
- Software supply-chain security and SBOM implementation.
- Experience within banking, financial services, or another highly regulated environment.
- Relevant certifications such as CISSP, CSSLP, OSCP, GIAC, or cloud-security certifications.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Key Competencies
- Application Security: Strong understanding of vulnerabilities, secure coding, and application architecture.
- DevSecOps: Ability to integrate security seamlessly into engineering and CI/CD processes.
- AI Security: Understanding of LLM, GenAI, and Agentic AI risks and security controls.
- Software Engineering: Ability to read, analyse, and review application code.
- Automation: Ability to build security automation and integrate controls into developer workflows.
- Threat Modelling: Ability to identify attack paths, trust boundaries, and appropriate mitigations.
- Risk-Based Thinking: Ability to prioritise vulnerabilities according to technical, business, and regulatory risk.
- Collaboration: Comfortable working with engineering, architecture, DevOps, cloud, data, AI, and security teams.
- Communication: Able to translate complex security issues into clear, practical recommendations.
Key Deliverables
The successful candidate will contribute to:
- Increased adoption of shift-left AppSec across engineering teams.
- Automated security controls integrated into CI/CD pipelines.
- Improved detection, prioritisation, and remediation of application vulnerabilities.
- Secure adoption of AI-assisted development and AI-generated code.
- Controlled and validated AI-assisted vulnerability remediation.
- Security guardrails for LLM and Agentic AI applications.
- Secure patterns for AI agents accessing enterprise systems and data.
- Threat models and security assessments for AI/LLM solutions.
- Automated application-security and vulnerability-management capabilities.
- Reusable AppSec and AI security standards, patterns, and reference architectures.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location