Skip to main content

Senior DevSecOps Engineer

4 × 8hr days100% payHybrid · London, UK
  • Location:London
  • Type:Permanent
  • Job#16886

Our client is an established open banking infrastructure provider, building secure connectivity between banks and the software platforms that businesses and consumers rely on every day. Its technology powers payment initiation, bank data access, and a suite of pre-built financial products, and it counts some of the world's most recognised names in payments, accounting software, and technology among its customers.

As one of the earlier movers in the open banking space, the company has helped shape industry standards and continues to invest heavily in the reliability and security of its platform as it scales across multiple regulated markets.

The Role

As Senior DevSecOps Engineer, you will be a key driver in embedding security into every phase of the software development lifecycle. You'll join a high-impact team responsible for securing a highly available, multi-tenant platform built on cloud-native infrastructure (GCP and Kubernetes), taking a proactive and automated approach to establishing the company's foundational security posture and ensuring it meets and exceeds the standards required of a regulated financial services provider.

Key Responsibilities

  • Own security tooling: select, integrate, and maintain security tools across environments and CI/CD pipelines.

  • Engineer security guardrails: design, implement, and enforce automated security policies across the cloud estate and pipeline.

  • Harden the cloud platform: strengthen IAM policies, network security, and resource configuration across the GCP environment.

  • Automate compliance: work with compliance and governance stakeholders to translate requirements into automated, verifiable infrastructure practices.

  • Manage vulnerabilities and patching: run the end-to-end process for identifying, triaging, and remediating vulnerabilities across infrastructure, applications, and dependencies.

  • Empower developers: build and maintain golden-path templates for secure service deployment, enabling teams to ship confidently without compromising security.

  • Support incident response: contribute expertise to the security incident response function, helping manage and resolve security events swiftly.

Your Profile

Essential:

  • Deep, practical experience designing, managing, and securing high-availability infrastructure within GCP.

  • Proficiency in API security: reviewing, defining patterns for, and upskilling engineers on secure API design.

  • Expert knowledge of hardening Kubernetes (GKE) clusters, including network policies, container runtime security, and secrets management.

  • Solid skills in writing, securing, and testing infrastructure as code using Terraform or OpenTofu.

  • Hands-on experience deploying and managing security tooling (e.g. Aqua Security, Falco, Prisma Cloud, or similar CSPM/CWPP/CNAPP solutions).

  • Proficiency in at least one language relevant to security automation (Python, Golang, or Shell).

  • Proven ability to build secure, repeatable CI/CD pipelines (e.g. GitLab CI, GitHub Actions) with mandatory security checks built in.

Desirable:

  • Experience working within FinTech-related certifications or frameworks such as SOC2, ISO 27001, PCI DSS, DORA, or similar regulated environments.

  • Relevant certifications such as Google Cloud Professional Security Engineer, CKS (Certified Kubernetes Security Specialist), or CISSP.

Early Success

Within your first 6–12 months, success looks like establishing the golden-path templates and automated guardrails that let feature teams deploy securely and independently, embedding compliance checks into everyday delivery, and building strong working relationships with engineering and governance stakeholders that position you as a trusted voice on the company's security posture.

Why Join

  • Genuine ownership: a foundational security role with real scope to shape the company's security posture from the ground up.

  • Meaningful scale: secure infrastructure that underpins financial products used by major payments, software, and technology platforms.

  • Regulated, high-stakes environment: work at the sharp end of financial services security, where the standards genuinely matter.

  • A high-impact, security-first team culture, with strong buy-in from engineering leadership.

  • See All Jobs