Description
Company
JOB DESCRIPTION
Jefferies, the global investment banking firm, has served companies and investors for almost 60 years.
Headquartered in New York with its European head office in London, the firm provides clients with capital markets and financial advisory services, institutional brokerage and securities research, and asset management.
Jefferies provides research and execution services in equity, fixed income, foreign exchange, and a full range of investment banking services including underwriting, merger & acquisition, restructuring and recapitalisation and other advisory services, with businesses operating in the Americas, Europe and Asia.
Job Description
Global Information Security is building internal engineering capability to apply generative AI and automation across the security function.
This is a senior hands-on engineering role supporting both the Security Operations Centre and the wider security domains: identity, privileged access, network and cloud security, data protection, and vulnerability management.
The position is London-anchored to provide global coverage across the APAC afternoon and Americas morning.
This is an engineering role: we are looking for a software engineer who has shipped AI-backed systems in production and can own them as services.
Key Responsibilities
Design, build and operate AI-assisted automation services across the security function, owning them as production services with testing, monitoring, alerting, error handling and rollback.
Deliver automation supporting security operations, including alert triage and enrichment, case summarisation, evidence collection, detection tuning, threat intelligence synthesis, and repetitive investigative workflows.
Partner with pillar leads to deliver AI and automation capability across the wider security domains, including access review and certification support, entitlement analysis and role mining, privileged session analysis and PAM onboarding, posture finding triage, firewall and segmentation rule rationalisation, configuration drift detection, data classification and DLP event triage, and vulnerability prioritisation and contextualisation.
Develop LLM and agent-based workflows integrated with SIEM, EDR, SOAR, IGA, PAM, CSPM, DLP, ticketing and threat intelligence platforms via supported APIs.
Set the global AI Security and automation roadmap in partnership with the Head of Cyber Operations and pillar leads; arbitrate competing demand across domains and determine which workflows warrant automation and which do not.
Establish engineering standards for AI-assisted tooling across the security organisation in partnership with the Head of App & AI Security, covering prompt and tool-definition review, agent permission scoping, and output validation.
Engineer guardrails as a primary requirement: least-privilege service identities, human-in-the-loop checkpoints for consequential actions, full audit logging of agent decisions, and defences against prompt injection and tool-definition poisoning.
Build reusable platform components, shared integration patterns, evaluation harnesses, prompt and tool libraries so capability compounds across domains rather than being rebuilt for each team.
Define and report measures of effectiveness, including analyst and engineer time recovered, cycle time, and quality and error rates.
Mentor engineers in the Pune capability centre as automation delivery scales and document to a standard supportable by a follow-the-sun team.
Required Qualifications
8+ years professional software engineering with production ownership.
Advanced Python, including asynchronous programming, API integration, automated testing and CI/CD.
Demonstrated production experience building LLM-backed or agentic systems: retrieval, tool and function calling, orchestration, and evaluation or regression testing of non-deterministic outputs.
Working knowledge of security operations tooling and workflow — SIEM, EDR, SOAR, case management, threat intelligence.
Practical familiarity with at least two additional security domains from identity and access management, privileged access, network or cloud security, or data protection, with the demonstrated ability to learn new domains quickly.
Cloud engineering experience (AWS or Azure), containerisation and infrastructure-as-code.
Secure development practice: secrets management, least-privilege service identity, input validation, output encoding.
Demonstrated delivery across multiple time zones for distributed stakeholders.
Preferred Qualifications
Financial services or comparable regulated industry experience, with working knowledge of audit, evidence and change-control requirements.
Familiarity with agentic AI failure modes - prompt injection, tool poisoning, excessive agency - and current mitigations.
Detection engineering exposure: detection-as-code, Sigma, MITRE ATT&CK mapping.
Hands-on experience with enterprise IGA, PAM or CSPM platforms.
Experience transitioning vendor-managed automation to internally owned capability.
Open-source contribution, published research or conference speaking.
Candidate Profile
The successful candidate will operate with significant autonomy, translating problem statements into delivered capability without a pre-defined backlog.
They will hold technical authority across regional teams and pillar leads, balance competing demand from multiple security domains, and be expected to make and defend judgments about where AI is and is not appropriate in a security workflow.
About Us
Jefferies is a leading global, full-service investment banking and capital markets firm that provides advisory, sales and trading, research, and wealth and asset management services.
With more than 40 offices around the world, we offer insights and expertise to investors, companies, and governments.
At Jefferies, we believe that diversity fosters creativity, innovation and thought leadership through the infusion of new ideas and perspectives.
We have made a commitment to building a culture that provides opportunities for all employees regardless of our differences and supports a workforce that is reflective of the communities where we work and live.
As a result, we are able to pool our collective insights and intelligence to provide fresh and innovative thinking for our clients.
Jefferies is an equal employment opportunity employer, and takes affirmative action to ensure that all qualified applicants will receive consideration for employment without regard to race, creed, color, national origin, ancestry, religion, gender, pregnancy, age, physical or mental disability, marital status, sexual orientation, gender identity or expression, veteran or military status, genetic information, reproductive health decisions, or any other factor protected by applicable law.
We are committed to hiring the most qualified applicants and complying with all federal, state, and local equal employment opportunity laws.
As part of this commitment, Jefferies will extend reasonable accommodations to individuals with disabilities, as required by applicable law.