Summary
✨ AI‑Generated
Design and build security foundations for autonomous AI agents operating across a large, highly regulated enterprise environment. You will shape platform security architecture, governance, controls, and scalable security capabilities while addressing the risks introduced by generative AI and agentic systems.
Highlights
Senior security role focused on building security foundations for autonomous AI agents in a highly regulated enterprise, with significant scope across platform security, governance, scalability, and emerging AI technologies.
Description
Senior Security Engineer – Agentic AI & Platform Security
About the Client
Our client is a leading global investment management company headquartered in London, managing more than $228 billion in assets and serving institutional investors, pension funds, wealth managers, and other sophisticated clients worldwide.
The organization specializes in quantitative investing, alternative investments, systematic trading strategies, and technology-driven asset management.
Data science, machine learning, and artificial intelligence are core components of its investment, research, and technology strategies.
As part of a strategic collaboration, we are supporting two foundational capabilities required to enable safe, scalable, and governed AI adoption across the enterprise:
Agentic SecurityAI-Ready Data Foundations
Position Overview
We are seeking a Senior Security Engineer to design and build the security foundations required for autonomous AI agents operating across a large, highly regulated financial technology environment.
The runtime security model for agentic AI is still being established.
This role will help define how autonomous agents authenticate, obtain appropriately scoped access, interact with enterprise resources, and operate safely without inheriting excessive user privileges or relying on long-lived credentials.
The fundamental challenge is controlling what an AI agent can reach.
An agent operating with unrestricted user context or persistent credentials can create an effectively unlimited security blast radius.
Your role will be to design and implement the controls that close this gap.
This is a hands-on senior engineering position for a security engineer who remains deeply technical and actively develops production software.
You will operate at the intersection of:
Enterprise Identity & Access ManagementPlatform EngineeringInfrastructure SecurityInfrastructure as CodeCloud-native and on-premises infrastructureAgentic AI securityYou will build IaC-driven, self-service identity patterns, credential flows, security controls, and onboarding standards that make the secure approach the easiest approach for engineering teams.
Key Responsibilities
Platform & Software Engineering
Design, develop, and maintain production-grade Python services, libraries, APIs, and command-line tooling that form the internal infrastructure platform.Extend existing platform capabilities using robust software engineering practices rather than relying on ad-hoc scripts.Build reusable abstractions and self-service capabilities for infrastructure and security workflows.Develop automated workflows that improve engineering productivity while maintaining strong security controls.Agentic AI Security & IAM
Design identity and access patterns for autonomous AI agents, workloads, services, and applications.Establish secure authentication and authorization mechanisms for agentic workloads.Implement least-privilege and scoped-access models to minimize the potential blast radius of compromised or misbehaving agents.Design secure credential and secret-management workflows, with a preference for short-lived and appropriately scoped credentials.Develop standards for agent onboarding, identity provisioning, access requests, authorization, and lifecycle management.Establish auditable mechanisms for tracking infrastructure and agent access.Help define security patterns for AI agents interacting with enterprise systems, services, and data.Infrastructure & Automation
Build and maintain Infrastructure as Code using Terraform and Ansible.Replace manual infrastructure processes with reproducible, version-controlled, and reviewable workflows.Design self-service infrastructure provisioning while ensuring appropriate security guardrails.Work with on-premises compute, storage, networking, and virtualization infrastructure.Manage and scale infrastructure as platform adoption increases, balancing performance, reliability, security, and cost.Containers & Kubernetes
Build and secure workloads running on Docker and Kubernetes.Understand workload scheduling, configuration, resource allocation, service identity, and runtime permissions.Implement secure patterns for workload access to infrastructure and enterprise resources.Apply appropriate isolation and authorization controls to containerized workloads.CI/CD & DevOps
Design and maintain CI/CD pipelines using technologies such as GitLab CI, GitHub Actions, or Jenkins.Automate testing, packaging, validation, and deployment of platform components.Implement staged rollouts and safe deployment practices.Ensure infrastructure and application changes are subject to appropriate testing and peer review.Observability & Reliability
Build observability into platform services through metrics, structured logging, tracing, dashboards, and alerting.Work with technologies such as Prometheus, Grafana, and OpenTelemetry, or equivalent tooling.Use telemetry to diagnose complex distributed-system failures.Own production incidents from initial triage through root-cause analysis and permanent remediation.Ensure recurring issues result in engineering or configuration changes that prevent future incidents.Security by Default
Embed security controls directly into the platform so consuming engineering teams inherit secure defaults automatically.Implement and maintain:Secrets managementIdentity and access controlsLeast-privilege authorizationNetwork isolationDependency and supply-chain securityInfrastructure change auditingSecure software development practicesIdentify security risks such as overly broad permissions, unpinned dependencies, exposed credentials, and insecure infrastructure configurations.Engineering Collaboration
Partner with engineering teams to understand their workflows, challenges, and infrastructure requirements.Translate recurring engineering pain points into reusable platform capabilities.Gather requirements and convert them into clear technical designs.Write documentation, standards, and onboarding guidance that teams can independently follow.Explain architectural and security decisions clearly to both technical and non-technical stakeholders.Evaluate emerging technologies and engineering patterns and incorporate those that