DevSecOps Architect - Director
Mizuho International Plc · London (Lon), GB · United Kingdom · Hybrid
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Profile Summary
The DevSecOps architect will enable delivery of:
A published, adopted paved-road pipeline with a measurable proportion of the estate migrated onto it.
Security controls automated into the pipeline with audit evidence generated automatically.
Test automation strategy implementation, with coverage and gate compliance reported per release train.
Governed AI-assisted engineering adoption, and an approved lifecycle and control framework for AI systems in production.
Own the architecture of how software is built, tested, secured and released across the engineering estate — and extend that architecture in two directions: applying AI to accelerate the software lifecycle, and applying lifecycle discipline to AI systems themselves. The role is equally about engineering leverage and about control.
Duties and Responsibilities
Pipeline and delivery architecture:
Define the reference CI/CD architecture: branching model, build standards, artefact management, environment promotion, release patterns and rollback.
Drive convergence of fragmented toolchains onto a supported, paved-road platform, with a clear deprecation path for legacy pipelines.
Establish deployment and change automation that satisfies audit and change-management requirements without manual gates.
Test automation:
Own the test automation strategy across unit, integration, contract, end-to-end, performance and resilience testing.
Define test data management architecture, including masking, synthetic generation and environment refresh.
Set coverage and quality gates, and make test results a first-class input to release decisions.
Drive shift-left testing and service virtualisation to reduce dependency on scarce integrated environments.
Security integration:
Embed security controls into the pipeline: SAST, DAST, SCA, container and IaC scanning, secrets detection, and SBOM generation.
Design the software supply chain security model — artefact provenance, signing, dependency governance, base image hardening.
Define policy-as-code and automated control evidence, so that compliance is produced by the pipeline rather than assembled for audit.
Partner with Information Security to translate policy into enforceable, developer-usable controls with low false-positive burden.
AI for SDLC:
Define the architecture and guardrails for AI-assisted engineering: coding assistants, agentic development tooling, automated code review, test generation and documentation.
Establish controls for AI-generated code — provenance, review obligations, IP and licensing risk, and data boundaries.
Define adoption measurement: what productivity uplift is claimed, how it is evidenced, and how quality is protected.
SDLC for AI:
Define the delivery lifecycle for AI and machine learning systems: data lineage, feature and model versioning, evaluation, approval, deployment, monitoring and rollback.
Establish evaluation and regression testing for…