Deloitte - Recruitment

DevSecOps Engineer (Pipeline Security) - AI

Deloitte - Recruitment · City of London, England, United Kingdom

Business Consulting and Services · 10,001+ employees

Mar 20
Senior (5-10 yrs) Contractor United Kingdom
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The DevSecOps Engineer will embed security controls into developer workflows, specifically focusing on securing AI-generated code and Claude Code integration. Responsibilities include designing secure CI/CD pipelines, integrating SAST tools, and implementing secrets scanning to ensure robust security posture.

What they look for

DevSecOps Pipeline Security AI Security SAST Secrets Scanning CI/CD Jenkins GitLab CI Azure DevOps Python Bash HashiCorp Vault GitGuardian Cloud Security Automation Container Security

Requirements

Candidates must have proven experience in DevSecOps engineering, pipeline security, and automation within CI/CD environments. Proficiency in scripting languages like Python or Bash and familiarity with cloud platforms and AI development security challenges are essential.

Full description

Job Role: DevSecOps Engineer (Pipeline Security) - AI

Contract Duration: 6 months

Location: London / Sheffield (Hybrid - 3 days on site)

Daily Rate: Inside IR35

Job Summary:

We are seeking a skilled DevSecOps Engineer to join our team on a 6-month contract basis. The role focuses on embedding robust security controls into developer workflows that utilize Claude Code, with a particular emphasis on securing AI-generated code. You will be responsible for integrating Static Application Security Testing (SAST), secrets scanning, and designing secure CI/CD pipelines to ensure the integrity and security of AI development processes.

Key Responsibilities:

  • Embed security controls within developer

workflows leveraging Claude Code for AI development.

  • Integrate and maintain SAST tools specifically

targeting AI-generated code to identify vulnerabilities early.

  • Implement secrets scanning mechanisms to prevent

sensitive data exposure in code repositories and pipelines.

  • Design, build, and optimize secure CI/CD

pipelines that align with best practices in DevSecOps.

  • Collaborate closely with development, security,

and AI teams to ensure seamless security integration without hindering productivity.

  • Conduct security assessments and provide

recommendations to improve pipeline security posture.

  • Stay current with emerging security threats and

AI development trends to proactively enhance security measures.

Required Qualifications and Skills:

  • Proven experience in DevSecOps engineering,

particularly in pipeline security and automation.

  • Strong knowledge of CI/CD tools and platforms

(e.g., Jenkins, GitLab CI, Azure DevOps).

  • Experience with SAST tools and integrating them

into development workflows.

  • Familiarity with secrets management and scanning

tools (e.g., HashiCorp Vault, GitGuardian).

  • Understanding of AI development workflows and

challenges related to AI-generated code security.

  • Proficiency in scripting and automation (e.g.,

Python, Bash).

  • Good understanding of cloud platforms (AWS,

Azure, or GCP) and their security features.

  • Strong problem-solving skills and ability to work

collaboratively in cross-functional teams.

Preferred Qualifications:

  • Experience working with Claude Code or similar AI

code generation tools.

  • Knowledge of container security and orchestration

platforms (e.g., Docker, Kubernetes).

  • Familiarity with compliance frameworks relevant

to financial services or regulated industries.

Soft Skills:

  • Excellent communication skills to articulate

security concepts to technical and non-technical stakeholders.

  • Proactive mindset with a strong focus on

continuous improvement and security innovation.

  • Ability to manage priorities effectively in a

fast-paced, hybrid working environment.

Additional Information:

  • This is a hybrid role requiring 3 days per week

onsite in London or Sheffield.

  • IR35 regulations apply; the contractor will be

engaged under a deemed employment status.

  • Opportunity to work on cutting-edge AI security

challenges within a leading financial services environment.