Rodeo
Get started

Sanderson

Senior DevSecOps Engineer - AI & Agentic Security

England
£100 – £148/hr
Posted 1 day ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Senior DevSecOps Engineer – Agentic AI & Middle Office Transformation

£1,000 per day, Outside IR35
London, 1 day per week on site, flexible to fully remote
1 stage interview
Candidates must be UK Based Residents

A major UK wealth management business is bringing agentic AI into both its delivery practices and its middle-office operations, while also selecting a new middle-office platform provider. Both changes alter the trust model: agents act with delegated authority, and a third party will process data underpinning client assets and the ledger. This role makes sure the controls for both are designed early and implemented properly as the provider and delivery model mature.

The role reports into security architecture and engineering, and sits between AI enablement, supplier selection and integration delivery. The provider decision and parts of the delivery model are still forming, so there is genuine scope to shape them.

What you will do

Agentic AI security:

  • Implement controls for agentic workloads: agent identity and delegated authority via OAuth token exchange, least-privilege tool scopes, human approval for consequential actions, and attributable audit trails of agent actions.
  • Engineer and adversarially test defences against prompt injection, excessive agency, sensitive data leakage and unsafe tool use.
  • Build and operate controls around model and tool access, including MCP gateway policy, model access through Amazon Bedrock with region and data-residency enforcement, and restrictions on computer-use capabilities.
  • Threat model AI systems using MAESTRO and OWASP guidance for LLM and agentic applications, turning the output into backlog items rather than documents.
  • Contribute engineering evidence to AI governance and architecture decision records, aligned to NIST AI RMF and ISO/IEC 42001.
  • Build reusable security control patterns spanning employee, client-facing and SaaS AI use cases, including AI coding assistants and enterprise LLM platforms.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Middle office and vendor assurance:

  • Provide the security engineering input into middle-office provider selection: technical due diligence, architecture review, and testing supplier claims rather than accepting questionnaire answers at face value.
  • Design and implement integration security for the selected provider — authentication, connectivity, encryption and key ownership, data minimisation, logging, and a workable exit position.
  • Make sure middle-office data flows across the ledger, holdings and market data meet internal data handling standards, integrity expectations for client asset records, and FCA outsourcing and operational resilience requirements.

Delivery:

  • Work inside the agentic and middle-office delivery teams so security decisions happen during the sprint rather than after it.
  • Work with data teams on classification, entitlements and access boundaries for middle-office data.
  • Produce CAB-ready evidence for AI and integration changes.
  • Produce AI security patterns, reusable tooling guidance and agent control requirements that delivery teams can adopt consistently.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

What you will bring

Essential:

  • Substantial hands-on security engineering experience in cloud environments, AWS preferred, including securing third-party and SaaS integrations.
  • A practical, engineering-level understanding of LLM and agentic AI risks and the controls that address them.
  • Strong OAuth2 and OIDC, token exchange, workload identity and API security knowledge.
  • Experience carrying out technical security assessments of suppliers.
  • Threat modelling experience on real systems.
  • Enough coding ability, Python preferred, to build and test guardrails yourself.
  • Comfort working where requirements and the supplier landscape are still settling.

Desirable:

  • Amazon Bedrock, Model Context Protocol and agent frameworks.
  • Spec-driven development and contributing security acceptance criteria to product requirements.
  • Financial services middle or back office: settlements, reconciliations, ledgers and client asset (CASS) considerations.
  • OWASP Top 10 for LLM Applications, MAESTRO and structured threat modelling tooling.
  • NIST AI RMF, ISO/IEC 42001 and EU AI Act awareness.
  • AWS Certified Security – Specialty, CCSK, CISSP or an AI security credential.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

England, United Kingdom

Sign up to applySee more jobs like this