BaruEngineering

Lead DevSecOps Engineer

AECOM

London4h ago

Lamar sekarang

Tentang peran ini

Job Description

In AECOM’s AI Engineering team, your work will help protect technology that directly shapes the physical world around us. We build AI-driven products that change how infrastructure and buildings are designed and engineered, reducing waste, cutting CO₂, and making the built environment more efficient and sustainable. This role ensures those products and the platforms behind them are secure by design.

With our AI Engineering team we’ve created a unique setup: a lean, highly technical team with the speed and ownership of a start up, backed by the scale, resources, and domain expertise of one of the world’s leading engineering firms.

There has never been a better time to be at AECOM. We are leading the industry’s AI transformation, and with our people and technology we deliver excellence and innovate with impact.

We invite you to bring your bold ideas and big dreams to solve the world’s most complex challenges. We're one global team driven by our common purpose to deliver a better world. Join us.

What You’ll Do

As part of our AI Engineering team, you will be the security lead for our products and platform, from first design review through to production. You will review and sign off on new products and features, own the security of our AI and LLM-powered capabilities, drive CVE remediation, maintain the scanning tooling that gives engineers fast feedback, run our penetration testing programme, and lead our response when incidents happen, all while working closely with engineers to reduce risk without slowing delivery.

You will report directly to the CIO and hold the authority to make security sign-off decisions on new products and features. There is also room to grow the security team as our products and platform scale, and you will play a key part in shaping it.

  • Run security reviews of new products from design through to launch, using threat modelling to assess architecture, data flows, and third-party dependencies, documenting findings, and agreeing proportionate remediation with product teams
  • Own security for our AI and LLM-powered features, threat modelling risks such as prompt injection, sensitive data leakage through prompts and outputs, insecure agent tool use, and abuse of model endpoints, and defining the guardrails and testing approaches to address them
  • Secure our AI supply chain, assessing third-party models and model providers, vector stores, and the data used for training and retrieval
  • Hold security sign-off authority for new products and features, setting clear, risk-based release criteria so that low-risk changes ship quickly and higher-risk changes receive deeper review
  • Own CVE remediation across the platform, triaging vulnerabilities in code, dependencies, container images, and cloud infrastructure by real-world exploitability, and working with engineering teams to patch within agreed timeframes
  • Maintain our security scanning tooling, keeping SAST, SCA, secret, container, and Infrastructure as Code scanning in CI/CD up to date and well tuned so that engineers get timely, actionable feedback with minimal noise
  • Manage our penetration testing programme, scoping engagements, coordinating with external testers, leading the review of findings, and tracking remediation through to verified closure
  • Strengthen cloud and identity security across Azure and GCP, including identity and ac cess management, networking, secrets and key management, logging, and cloud security posture
  • Lead the response to security incidents and actively exploited vulnerabilities, coordinating containment, remediation, and post-incident reviews, and keeping incident runbooks up to date
  • Establish and run a security champions programme across engineering teams, building shared ownership of security

Must-Have Qualifications

  • Demonstrated hands-on experience in security engineering, application or product security, DevSecOps, or related roles, including technical leadership
  • Proven experience leading security reviews and threat modelling of new products and features, and making clear, proportionate sign-off decisions
  • Strong experience in vulnerability management and incident response, including CVE triage, risk-based prioritisation, and driving remediation across codebases, containers, and cloud infrastructure
  • Hands-on experience maintaining and tuning security scanning tooling in CI/CD pipelines (e.g. SAST, SCA, secret, container, and IaC scanning), ideally with GitHub Actions and Terraform
  • Experience managing penetration tests end to end, from scoping and vendor coordination to reviewing findings and verifying fixes
  • Solid understanding of cloud security in Microsoft Azure and/or GCP, including identity and access management, networking, and secrets management
  • Ability to explain risk clearly and influence engineers, product owners, and leaders
  • A track record of working at pace in fast-moving teams, making sound security decisions quickly without becoming a blocker to delivery
  • Experience in a large global organisation, working across regions, business units, and enterprise governance and compliance processes

Preferred Skills

  • Experience securing AI/ML and LLM-based applications, including familiarity with the OWASP Top 10 for LLM Applications or MITRE ATLAS
  • Experience securing containerised workloads and software supply chains, such as SBOMs and artifact signing
  • Experience applying security and compliance frameworks such as NIST, CIS, ISO 27001, or SOC 2 in regulated or enterprise environments
  • Relevant certifications such as OSCP, CISSP, GWAPT, Microsoft Certified Azure Security Engineer Associate, or equivalent

Our Hiring Process

  • 25-minute screening call
  • Take-home challenge: A hands-on task to assess your problem-solving and technical skills
  • Combined technical and cultural interview (in-person)
  • Technical Interview: 1-hour with 2 of our engineers to discuss your solution to the take-home challenge
  • Culture fit: 30-minute meeting with our leadership team

Why Join Us?

  • Work on real-world problems where AI creates measurable impact.
  • Be part of a team where your work matters, and your ideas become real.
  • Collaborate with sharp, driven colleagues in a culture of trust, ownership, and high standards.
  • Contribute to making the built environment smarter and more sustainable.

At AECOM, we are committed to maintaining a secure and trustworthy recruitment process and take any fraudulent hiring activity seriously. To support this commitment, all newly hired employees are required to attend an in-person Day 1 onboarding at an AECOM office location as a condition of employment.

About AECOM

AECOM is proud to offer comprehensive benefits to meet the diverse needs of our employees. Depending on your employment status, AECOM benefits may include medical, dental, vision, life, AD&D, disability benefits, paid time off, leaves of absences, voluntary benefits, perks, flexible work options, well-being resources, employee assistance program, business travel insurance, service recognition awards, retirement savings plan, and employee stock purchase plan.

AECOM is the global infrastructure leader, committed to delivering a better world. As a trusted professional services firm powered by deep technical abilities, we solve our clients’ complex challenges in water, environment, energy, transportation and buildings. Our teams partner with public- and private-sector clients to create innovative, sustainable and resilient solutions throughout the project lifecycle — from advisory, planning, design and engineering to program and construction management.

AECOM is a Fortune 500 firm that had revenue of $16.1 billion in fiscal year 2025. Learn more at aecom.com.

What makes AECOM a great place to work

You will be part of a global team that champions your growth and career ambitions. Work on groundbreaking projects—both in your local community and on a global scale—that are transforming our industry and shaping the future. With cutting-edge technology and a network of experts, you’ll have the resources to make a real impact. Our award-winning training and development programs are designed to expand your technical expertise and leadership skills, helping you build the career you’ve always envisioned.

Here, you’ll find a welcoming workplace built on respect, collaboration and community—where you have the freedom to grow in a world of opportunity.

We are a Disability Confident Employer and will offer an interview to applicants who have a disability or long-term condition, who meet the minimum/essential criteria for the role. Please let us know using this email address ReasonableAccommodationsUKI@aecom.com if you would like to apply through the Disability Confident Interview Scheme.

All your information will be kept confidential according to EEO guidelines.

Company Description

Work with Us. Change the World.

At AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world's trusted infrastructure consulting firm, partnering with clients to solve the world’s most complex challenges and build legacies for future generations.

There has never been a better time to be at AECOM. With accelerating infrastructure investment worldwide, our services are in great demand. We invite you to bring your bold ideas and big dreams and become part of a global team of over 50,000 planners, designers, engineers, scientists, digital innovators, program and construction managers and other professionals delivering projects that create a positive and tangible impact around the world.

We're one global team driven by our common purpose to deliver a better world. Join us.

Sumber: halaman karir pemberi kerja sendiri.

Pekerjaan serupa