{"id":2034126,"url":"https://alion.io/job/aecom-lead-devsecops-engineer-2","title":"Lead DevSecOps Engineer","company":{"id":3394,"name":"AECOM","domain":"aecom.com","url":"https://alion.io/company/aecom","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SmartRecruiters","truth_index":{"grade":"B","score":81,"open_postings":383,"ghost_share":0,"stale_share":0.757,"repost_share":0,"time_to_fill_p50_days":40,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":91000,"max_usd":183000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":18},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"CVE","optional":false},{"name":"Function Calling","optional":false},{"name":"GCP","optional":false},{"name":"GitHub Actions","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Terraform","optional":false},{"name":"Tool Use","optional":false},{"name":"ISO 27001","optional":true},{"name":"OWASP Top 10","optional":true},{"name":"SOC 2","optional":true}],"status":"live","first_seen_at":"2026-10-07T12:25:32Z","employer_posted_date":"2026-10-07","last_verified_at":"2026-10-11T00:32:33Z","board_verified":true,"closed_at":null,"days_open":3,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":3},"description":"Work with Us. Change the World.\nAt AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world's trusted infrastructure consulting firm, partnering with clients to solve the world’s most complex challenges and build legacies for future generations.\nThere has never been a better time to be at AECOM. With accelerating infrastructure investment worldwide, our services are in great demand. We invite you to bring your bold ideas and big dreams and become part of a global team of over 50,000 planners, designers, engineers, scientists, digital innovators, program and construction managers and other professionals delivering projects that create a positive and tangible impact around the world.\nWe're one global team driven by our common purpose to deliver a better world. Join us.\n In AECOM’s AI Engineering team, your work will help protect technology that directly shapes the physical world around us. We build AI-driven products that change how infrastructure and buildings are designed and engineered, reducing waste, cutting CO₂, and making the built environment more efficient and sustainable. This role ensures those products and the platforms behind them are secure by design.\nWith our AI Engineering team we’ve created a unique setup: a lean, highly technical team with the speed and ownership of a start up, backed by the scale, resources, and domain expertise of one of the world’s leading engineering firms.\nThere has never been a better time to be at AECOM. We are leading the industry’s AI transformation, and with our people and technology we deliver excellence and innovate with impact.\nWe invite you to bring your bold ideas and big dreams to solve the world’s most complex challenges. We're one global team driven by our common purpose to deliver a better world. Join us.\nWhat You’ll Do\nAs part of our AI Engineering team, you will be the security lead for our products and platform, from first design review through to production. You will review and sign off on new products and features, own the security of our AI and LLM-powered capabilities, drive CVE remediation, maintain the scanning tooling that gives engineers fast feedback, run our penetration testing programme, and lead our response when incidents happen, all while working closely with engineers to reduce risk without slowing delivery.\nYou will report directly to the CIO and hold the authority to make security sign-off decisions on new products and features. There is also room to grow the security team as our products and platform scale, and you will play a key part in shaping it.\nRun security reviews of new products from design through to launch, using threat modelling to assess architecture, data flows, and third-party dependencies, documenting findings, and agreeing proportionate remediation with product teams\nOwn security for our AI and LLM-powered features, threat modelling risks such as prompt injection, sensitive data leakage through prompts and outputs, insecure agent tool use, and abuse of model endpoints, and defining the guardrails and testing approaches to address them\nSecure our AI supply chain, assessing third-party models and model providers, vector stores, and the data used for training and retrieval\nHold security sign-off authority for new products and features, setting clear, risk-based release criteria so that low-risk changes ship quickly and higher-risk changes receive deeper review\nOwn CVE remediation across the platform, triaging vulnerabilities in code, dependencies, container images, and cloud infrastructure by real-world exploitability, and working with engineering teams to patch within agreed timeframes\nMaintain our security scanning tooling, keeping SAST, SCA, secret, container, and Infrastructure as Code scanning in CI/CD up to date and well tuned so that engineers get timely, actionable feedback with minimal noise\nManage our penetration testing programme, scoping engagements, coordinating with external testers, leading the review of findings, and tracking remediation through to verified closure\nStrengthen cloud and identity security across Azure and GCP, including identity and ac cess management, networking, secrets and key management, logging, and cloud security posture\nLead the response to security incidents and actively exploited vulnerabilities, coordinating containment, remediation, and post-incident reviews, and keeping incident runbooks up to date\nEstablish and run a security champions programme across engineering teams, building shared ownership of security\n Must-Have Qualifications\nDemonstrated hands-on experience in security engineering, application or product security, DevSecOps, or related roles, including technical leadership\nProven experience leading security reviews and threat modelling of new products and features, and making clear, proportionate sign-off decisions\nStrong experience in vulnerability management and incident response, including CVE triage, risk-based prioritisation, and driving remediation across codebases, containers, and cloud infrastructure\nHands-on experience maintaining and tuning security scanning tooling in CI/CD pipelines (e.g. SAST, SCA, secret, container, and IaC scanning), ideally with GitHub Actions and Terraform\nExperience managing penetration tests end to end, from scoping and vendor coordination to reviewing findings and verifying fixes\nSolid understanding of cloud security in Microsoft Azure and/or GCP, including identity and access management, networking, and secrets management\nAbility to explain risk clearly and influence engineers, product owners, and leaders\nA track record of working at pace in fast-moving teams, making sound security decisions quickly without becoming a blocker to delivery\nExperience in a large global organisation, working across regions, business units, and enterprise governance and compliance processes\nPreferred Skills\nExperience securing AI/ML and LLM-based applications, including familiarity with the OWASP Top 10 for LLM Applications or MITRE ATLAS\nExperience securing containerised workloads and software supply chains, such as SBOMs and artifact signing\nExperience applying security and compliance frameworks such as NIST, CIS, ISO 27001, or SOC 2 in regulated or enterprise environments\nRelevant certifications such as OSCP, CISSP, GWAPT, Microsoft Certified Azure Security Engineer Associate, or equivalent\n Our Hiring Process\n25-minute screening call\nTake-home challenge: A hands-on task to assess your problem-solving and technical skills\nCombined technical and cultural interview (in-person)Technical Interview: 1-hour with 2 of our engineers to discuss your solution to the take-home challenge\nCulture fit: 30-minute meeting with our leadership team\n\nWhy Join Us?\nWork on real-world problems where AI creates measurable impact.\nBe part of a team where your work matters, and your ideas become real.\nCollaborate with sharp, driven colleagues in a culture of trust, ownership, and high standards.\nContribute to making the built environment smarter and more sustainable.\nAt AECOM, we are committed to maintaining a secure and trustworthy recruitment process and take any fraudulent hiring activity seriously. To support this commitment, all newly hired employees are required to attend an in-person Day 1 onboarding at an AECOM office location as a condition of employment.\nAbout AECOM\nAECOM is proud to offer comprehensive benefits to meet the diverse needs of our employees. Depending on your employment status, AECOM benefits may include medical, dental, vision, life, AD&D, disability benefits, paid time off, leaves of absences, voluntary benefits, perks, flexible work options, well-being resources, employee assistance program, business travel insurance, service recognition awards, retirement savings plan, and employee stock purchase plan.\nAECOM is the global infrastructure leader, committed to delivering a better world. As a trusted professional services firm powered by deep technical abilities, we solve our clients’ complex challenges in water, environment, energy, transportation and buildings. Our teams partner with public- and private-sector clients to create innovative, sustainable and resilient solutions throughout the project lifecycle - from advisory, planning, design and engineering to program and construction management. AECOM is a Fortune 500 firm that had revenue of $16.1 billion in fiscal year 2025. Learn more at aecom.com.\nWhat makes AECOM a great place to work\nYou will be part of a global team that champions your growth and career ambitions. Work on groundbreaking projects-both in your local community and on a global scale-that are transforming our industry and shaping the future. With cutting-edge technology and a network of experts, you’ll have the resources to make a real impact. Our award-winning training and development programs are designed to expand your technical expertise and leadership skills, helping you build the career you’ve always envisioned. Here, you’ll find a welcoming workplace built on respect, collaboration and community-where you have the freedom to grow in a world of opportunity.\nWe are a Disability Confident Employer and will offer an interview to applicants who have a disability or long-term condition, who meet the minimum/essential criteria for the role. Please let us know using this email address  if you would like to apply through the Disability Confident Interview Scheme.\nAll your information will be kept confidential according to EEO guidelines.","description_format":"text","description_chars":9688,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":["Flexible schedule","Retirement plans"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps","Architecture","Management Consulting","Construction"],"lifecycle":[{"event":"open","at":"2026-10-07T15:19:06Z"}],"visa":[{"country":"GB","licensed_sponsor":true,"evidence":"Licensed UK visa sponsor (Senior or Specialist Worker, Skilled Worker)","filings_12m":null,"filings_prev_12m":null,"green_card_filings_12m":null,"median_offered_wage_usd":null,"route":"Global Business Mobility: Senior or Specialist Worker; Skilled Worker","cap_exempt":false,"checked_at":"2026-10-10T06:21:00+00:00","sources":["UK Home Office: register of licensed sponsors (workers)"],"filings_for_role_12m":0}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":2,"expected_fill_days":40,"reasons":["conf:1","stale_co","velocity","win:early","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/aecom-lead-devsecops-engineer-2","json_url":"https://alion.io/job/aecom-lead-devsecops-engineer-2.json","meta":{"generated_at":"2026-10-11T02:53:48Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":236,"day_limit":5000,"remaining_today":4764,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3394},"rest":"https://alion.io/mcp/rest/get_company?id=3394"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Faecom-lead-devsecops-engineer-2"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Faecom-lead-devsecops-engineer-2"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Faecom-lead-devsecops-engineer-2"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/aecom-lead-devsecops-engineer-2\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Faecom-lead-devsecops-engineer-2"}]}