Lead DevSecOps Engineer
AECOM · London, HOLBEIN GARDENS, United Kingdom
- Senior
- Full-time
- Posted 2026-09-22
- Confirmed live on 25 September 2026
Job description
Job Description
In AECOM’s AI Engineering team, your work will help deliver technology that directly shapes the physical world around us. We build AI-driven products that change how infrastructure and buildings are designed and engineered, reducing waste, cutting CO₂, and making the built environment more efficient and sustainable. This role ensures those products and the platforms behind them are reliable, scalable, and secure by design.
With our AI Engineering team we’ve created a unique setup: a lean, highly technical team with the speed and ownership of a start up, backed by the scale, resources, and domain expertise of one of the world’s leading engineering firms.
There has never been a better time to be at AECOM. We are leading the industry’s AI transformation, and with our people and technology we deliver excellence and innovate with impact.
We invite you to bring your bold ideas and big dreams to solve the world’s most complex challenges. We're one global team driven by our common purpose to deliver a better world. Join us.
What You’ll Do
As part of our AI Engineering team, you will lead the DevSecOps capabilities that help engineers build, release, and operate services across our multi-cloud platform. You will shape CI/CD, Infrastructure as Code, observability, reliability, cloud governance, and secure engineering across Microsoft Azure and Google Cloud Platform (GCP). You will also manage cloud-vendor service reviews, security advisories, escalations, and roadmap discussions.
• Evolve CI/CD pipelines and reusable workflows that enable fast, reliable, and repeatable testing and deployment, with automated quality and security controls
• Build observability and operational readiness through monitoring, logging, tracing, runbooks, and incident response, improving the reliability and performance of production services
• Define and track service reliability objectives, and recovery requirements for production services, using incident reviews to drive continuous improvement.
• Embed proportionate security into engineering workflows and cloud environments, including platform security reviews, threat modelling, access and secrets management, automated scanning, and vulnerability remediation
• Monitor cloud security posture across Azure and GCP, helping teams prioritise misconfigurations, vulnerabilities, and remediation work according to risk
• Manage technical and service relationships with Microsoft, Google Cloud, and other critical vendors, leading service reviews, security advisory responses, escalations, and roadmap and cost discussions
• Partner with platform, product, and AI/ML engineers on architecture decisions, mentor colleagues, and make clear trade-offs across developer experience, reliability, performance, cost, and security
Qualifications
Must-Have Qualifications
• Demonstrated hands-on experience across DevOps, SRE, platform engineering, DevSecOps, or related roles, with experience guiding technical decisions or mentoring colleagues
• Experience building and maintaining CI/CD pipelines and release automation, ideally with GitHub Actions or similar tooling
• Hands-on experience with Infrastructure as Code and cloud platform automation using Terraform
• Demonstrated ownership of production reliability, including observability, service-level objectives, incident management, post-incident reviews, capacity planning, and disaster-recovery testing.
• Practical experience carrying out security reviews and implementing controls across identity, secrets management, software supply chains, and vulnerability management
• Experience working directly with cloud providers or technology vendors, ideally including Microsoft or Google Cloud, on service reviews, escalations, or roadmap discussions
• Practical experience monitoring and optimising cloud expenditure across large Azure or GCP environments.
Preferred Skills
• Experience building internal developer platforms or self-service cloud capabilities
• Experience applying image scanning, artefact signing, or software provenance controls to containerised workloads
• Familiarity with cloud security posture management, policy-as-code, security monitoring, or compliance automation
• Experience supporting AI/ML workloads and SaaS platforms in production
Additional Information
Our Hiring Process
• 25-minute screening call
• Take-home challenge: A hands-on task to assess your problem-solving and technical skills
• Combined technical and cultural interview (in-person)
• Technical Interview: 1-hour with 2 of our engineers to discuss your solution to the take-home challenge
• Culture fit: 30-minute meeting with our leadership team
Why Join Us?
• Work on real-world problems where AI creates measurable impact.
• Be part of a team where your work matters, and your ideas become real.
• Collaborate with sharp, driven colleagues in a culture of trust, ownership, and high standards.
• Contribute to making the built environment smarter and more
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at AECOM
- Principal Modeler- BIM - Highways & Site Civils (AutoCAD / Civil 3D / ORD) · Bengaluru, KA, India
- Senior Designer - BIM Substation · Bengaluru, KA, India
- Deputy Modeler to Lead Modeler- BIM - Highways & Site Civils (AutoCAD / Civil 3D / ORD) · Gurugram, HARYANA, India
- Designer - BIM (ELV) · Gurugram, HARYANA, India
- Senior Designer - BIM (Bridges) · Bengaluru, KA, India
- Resident Safety Officer (Construction) · Hong Kong, , Hong Kong
- Principal Mechanical Engineer · Sydney, NSW, Australia
- Civil Designer/Drafter – General Civil · Fortitude Valley, QLD, Australia