Architect and deploy the secure technical framework that governs the security controls for how our developers and scientists use agentic AI, including AI coding assistants, autonomous agents, and LLM-integrated tooling.
Given that these systems can autonomously access data, execute code, and interact with external services, the guardrails you design will need to address a substantially broader attack surface than traditional AI tooling, and must hold up in a context where the underlying data is among the most sensitive we handle.
Be the primary technical security voice in decisions around the use and deployment of externally developed AI, ensuring the right controls are in place from the onset.
Continuously mature automated security controls into CI/CD pipelines and infrastructure-as-code deployments, championing the DevSecOps culture across a large engineering organisation.
Take hands-on ownership of our core security technology stack, including Wiz, CrowdStrike, Google SecOps, and Tailscale, ensuring these platforms are correctly configured, tuned, and integrated.
Drive continuous technical delivery of strategic security initiatives, systematically identifying, triaging, and closing gaps across our cloud environments, internal networks, and developer workflows.
Provide technical oversight of the security of the data pipelines feeding our internal AI systems and, critically, the permissions and access boundaries of agentic AI systems reaching out into other environments, enforcing the principle of least privilege, maintaining audit trails, and ensuring sensitive data and code integrity is handled with the rigour required.
Complement the work of our existing biometric and product focused Red Team by owning security coverage of the DevSecOps surface, the build pipeline, internal toolchain, cloud environments and developer infrastructure.
Act as the primary technical security partner to our GRC-focused InfoSec Manager, translating governance and compliance mandates into concrete, automated engineering controls.
Represent the technical security function in external audits. This includes presenting evidence of controls, articulating the security posture of our cloud and AI environments to auditors, and working closely with the InfoSec Manager to ensure the technical substance behind our compliance position is clearly and credibly communicated.
Requirements
A foundational background in software engineering or DevOps before moving into a dedicated security role: you understand how code is written, tested, and deployed, and that experience is central to how you approach security problems.
Proven, hands-on experience securing modern cloud infrastructure and containerised environments, with a solid understanding of infrastructure-as-code principles and the security implications of how infrastructure is defined and provisioned.
Proficiency in deploying and administering enterprise security platforms, ideally with direct experience managing tools spanning CNAPP, EDR, SIEM, and zero-trust networking.
A heavy and active user of AI in both professional and personal contexts, including agentic AI tools and coding assistants, with a grounded understanding of the evolving AI threat landscape, including model supply chain risks, prompt injection, data exfiltration, agent misuse, and LLM-specific attack vectors.
Scripting and automation capability, particularly in Python, to build internal tooling, automate security checks, and reduce reliance on manual processes across the security function.
Prior experience or a demonstrated practical interest in securing AI workloads, data pipelines, and machine learning environments.
The communication skills to collaborate effectively with highly technical stakeholders, champion security initiatives without hindering developer productivity, and translate risk into language that resonates with both engineering peers and business leadership, including the confidence to present technical security evidence clearly in formal external audit settings.
Tech Stack
Cloud
Python
Benefits
25 days Annual Leave, plus 8 Bank Holidays (more holiday with service
up to an extra 5 days off per year based on your continuous service)
Growth Shares allocated after passing probation (6 months of service)
Salary sacrifice schemes including: Pension, Cycle To Work and Electric Car Scheme
Nursery Sacrifice Scheme
Work Overseas Perk
Work globally for up to 2 weeks
Life Assurance
SmartHealth
Access to private GP, Psychologist, Nutritionist along with tailored fitness plans for both you and your family
Benefit from personalized 1:1 career coaching with our in-house Occupational Psychologist
Award winning L&D platform with personal allocated training budgets
Enhanced paid family leave
Pension
5% employee, 3% employer
Flexible hybrid working environment
Free Barista Coffee/Tea, biscuits with fruit in the WeWork office
Free access to WeWork discounts and free online well-being sessions
Vitality Health
a range of options available on this below
The Vitality Programme includes a number of reward benefits that all employees have access to as part of the plan, for example: Private Health cover including Dental, Optical, and Audiology
50% off monthly gym memberships
Apple watches significantly discounted based member vitality status
Half price trainers with Runners Need
Weekly rewards – Free coffee with Café Nero
Monthly rewards – Free Cinema ticket
Discounts on travel with Expedia (hotels) and Mr & Mrs Smith with discounts getting greater throughout the year based on a members vitality status
Amazon prime free months based on activity
Up to 25% cashback at Waitrose when buying healthy foods
75% off stays at Champneys Health Spas
Allen Carr’s £299 no smoking programme for free
Access to Vitality Healthy Mind with 30% off Headspace subscriptions and the ability to earn Vitality points for using Buddhify, Calm and Headspace
Discounts on Weight Watchers
50%-80% off Comprehensive Private Health screenings