About the Role
We are seeking a skilled DevSecOps Engineer to join our team on a 6-month contract basis. The role focuses on embedding robust security controls into developer workflows that utilize Claude Code, with a particular emphasis on securing AI-generated code. You will be responsible for integrating Static Application Security Testing (SAST), secrets scanning, and designing secure CI/CD pipelines to ensure the integrity and security of AI development processes.
Responsibilities
- Embed security controls within developer workflows leveraging Claude Code for AI development.
- Integrate and maintain SAST tools specifically targeting AI-generated code to identify vulnerabilities early.
- Implement secrets scanning mechanisms to prevent sensitive data exposure in code repositories and pipelines.
- Design, build, and optimize secure CI/CD pipelines that align with best practices in DevSecOps.
- Collaborate closely with development, security, and AI teams to ensure seamless security integration without hindering productivity.
- Conduct security assessments and provide recommendations to improve pipeline security posture.
- Stay current with emerging security threats and AI development trends to proactively enhance security measures.
Requirements
- Proven experience in DevSecOps engineering, particularly in pipeline security and automation.
- Strong knowledge of CI/CD tools and platforms (e.g., Jenkins, GitLab CI, Azure DevOps).
- Experience with SAST tools and integrating them into development workflows.
- Familiarity with secrets management and scanning tools (e.g., HashiCorp Vault, GitGuardian).
- Understanding of AI development workflows and challenges related to AI-generated code security.
- Proficiency in scripting and automation (e.g., Python, Bash).
- Good understanding of cloud platforms (AWS, Azure, or GCP) and their security features.
- Strong problem-solving skills and ability to work collaboratively in cross-functional teams.
- Experience working with Claude Code or similar AI code generation tools.
- Knowledge of container security and orchestration platforms (e.g., Docker, Kubernetes).
- Familiarity with compliance frameworks relevant to financial services or regulated industries.
- Excellent communication skills to articulate security concepts to technical and non-technical stakeholders.
- Proactive mindset with a strong focus on continuous improvement and security innovation.
- Ability to manage priorities effectively in a fast-paced, hybrid working environment.
Skills
- DevSecOps
- Pipeline Security
- Automation
- CI/CD
- Jenkins
- GitLab CI
- Azure DevOps
- SAST
- Secrets Management
- Secrets Scanning
- HashiCorp Vault
- GitGuardian
- AI Development Workflows
- AI-Generated Code Security
- Scripting
- Python
- Bash
- Cloud Platforms
- AWS
- Azure
- GCP
- Container Security
- Docker
- Kubernetes
- Claude Code
Location
- London
- Sheffield
Work Type
- Hybrid
- Contract
Experience Level
- 6 months contract duration
Salary/Compensations
- Inside IR35
About the Company
- Opportunity to work on cutting-edge AI security challenges within a leading financial services environment.
