About this role
Profile Summary
The DevSecOps architect will enable delivery of:
- A published, adopted paved-road pipeline with a measurable proportion of the estate migrated onto it.
- Security controls automated into the pipeline with audit evidence generated automatically.
- Test automation strategy implementation, with coverage and gate compliance reported per release train.
- Governed AI-assisted engineering adoption, and an approved lifecycle and control framework for AI systems in production.
Own the architecture of how software is built, tested, secured and released across the engineering estate — and extend that architecture in two directions: applying AI to accelerate the software lifecycle, and applying lifecycle discipline to AI systems themselves. The role is equally about engineering leverage and about control.
Duties and Responsibilities
Pipeline and delivery architecture:
- Define the reference CI/CD architecture: branching model, build standards, artefact management, environment promotion, release patterns and rollback.
- Drive convergence of fragmented toolchains onto a supported, paved-road platform, with a clear deprecation path for legacy pipelines.
- Establish deployment and change automation that satisfies audit and change-management requirements without manual gates.
Test automation:
- Own the test automation strategy across unit, integration, contract, end-to-end, performance and resilience testing.
- Define test data management architecture, including masking, synthetic generation and environment refresh.
- Set coverage and quality gates, and make test results a first-class input to release decisions.
- Drive shift-left testing and service virtualisation to reduce dependency on scarce integrated environments.
Security integration:
- Embed security controls into the pipeline: SAST, DAST, SCA, container and IaC scanning, secrets detection, and SBOM generation.
- Design the software supply chain security model — artefact provenance, signing, dependency governance, base image hardening.
- Define policy-as-code and automated control evidence, so that compliance is produced by the pipeline rather than assembled for audit.
- Partner with Information Security to translate policy into enforceable, developer-usable controls with low false-positive burden.
AI for SDLC:
- Define the architecture and guardrails for AI-assisted engineering: coding assistants, agentic development tooling, automated code review, test generation and documentation.
- Establish controls for AI-generated code — provenance, review obligations, IP and licensing risk, and data boundaries.
- Define adoption measurement: what productivity uplift is claimed, how it is evidenced, and how quality is protected.
SDLC for AI:
- Define the delivery lifecycle for AI and machine learning systems: data lineage, feature and model versioning, evaluation, approval, deployment, monitoring and rollback.
- Establish evaluation and regression testing for non-deterministic systems, including prompt and model change management.
- Architect the control framework for AI systems in line with model risk management and emerging AI regulation, covering explainability, human oversight, drift monitoring and incident handling.
- Define the reference architecture for AI platform components: model gateway, retrieval layer, guardrails, observability and audit trail.
Qualifications, Skills and Experience
- Significant experience architecting CI/CD and DevSecOps platforms at enterprise scale in a regulated environment.
- Demonstrable delivery of a test automation strategy that changed release frequency or defect escape rate — with evidence.
- Deep practical security integration experience across the pipeline, including supply chain controls.
- Hands-on exposure to production AI/ML or LLM systems, including how they are evaluated, deployed and monitored.
Technical skills:
- CI/CD: Azure DevOps, GitHub Actions, GitLab, Jenkins; artefact repositories; GitOps and progressive delivery
- Testing: Playwright, Selenium, Cypress, JUnit/pytest, Pact or equivalent contract testing, JMeter/k6, chaos and resilience tooling
- Security: SonarQube, Snyk, Checkmarx, Veracode, Trivy, secrets management (HashiCorp Vault, cloud-native equivalents), OPA/policy-as-code, SBOM and SLSA concepts.
- Platform: Kubernetes, containers, Terraform, service mesh, observability stacks
- AI/ML: MLOps and LLMOps tooling, model registries, vector stores and retrieval architectures, evaluation frameworks, agent frameworks, AI gateway patterns
Desirable:
- Experience operating under model risk management (e.g. SR 11-7) or preparing for the EU AI Act.
- Background in platform engineering and internal developer platform design.
- Experience defining engineering metrics (DORA or equivalent) and using them to drive change.
Key Behaviours and Competencies:
- Credibility with engineers and architects, with the ability to influence technical direction, challenge constructively and build consensus across diverse technology teams.
- Outcome-focused, with a passion for improving developer experience, engineering productivity, software quality and security through automation and standardisation.
- Pragmatic and collaborative leader, able to balance innovation, risk and delivery priorities while driving lasting organisational change and capability uplift.
What Mizuho Can Offer You
Here at Mizuho, there are fantastic progression opportunities and clear paths to promotion. We will give you ample opportunity to affect change and to help grow our business.
In addition to the great opportunity outlined above we are also currently able to offer:
- Competitive starting salary, plus discretionary bonus
- Non-contributory pension
- 27 days’ annual leave
- Core working hours*
- Hybrid working - office and home based*
- Virtual GP
- Wellbeing benefits, including Mental Health Allies and First Aiders
*For applicable roles only
At Mizuho, we embrace flexible ways of working when the role permits. We offer different working arrangements like part-time, job-sharing and hybrid (office and home) working. Our purpose-led culture and global infrastructure help us connect, collaborate, and work together in agile ways to meet all our business needs.
We are committed to supporting equality and diversity, and seek to create a workplace that is fully inclusive. We welcome applications from all sections of the community that we operate in and from all ethnic backgrounds, sexual orientation, beliefs, gender identities and disabilities
If you require more information about our equal opportunities policy or wish to discuss any accessibility requirements or reasonable adjustments please contact the recruitment team – [email protected] and we will be happy to help.
