Lead DevSecOps Engineer

Bloom & Wild — Netherlands · Posted ~5 days ago

Lead Full-time Remote

Skills

DevSecOps cloud security security governance AWS GCP Terraform PostgreSQL security roadmap development OWASP SAMM Fargate ECS Ruby on Rails Angular Datadog

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Lead security engineering for a modern European technology organization as its first dedicated DevSecOps leader. You will define a long-term security roadmap, establish governance and secure engineering standards, manage security vendors, and embed security into the default development workflow across AWS and GCP environments.

Highlights

First-in-function leadership opportunity with ownership of enterprise-wide security strategy, a 12–18 month security roadmap, governance, and secure engineering practices across a modern cloud technology estate.

Description

📍 Location: UK, Netherlands, or Remote (Europe) 🛠️ Tech Stack: AWS (Fargate/ECS), GCP, Ruby on Rails, Angular, PostgreSQL, Terraform, Datadog About Tech At Bloom & Wild Group 💐 We’re Europe’s largest direct-to-consumer flower and gifting business (incorporating Bloom & Wild, bloomon, and Bergamotte). Our 65+ person Tech team builds the software powering our e-commerce platforms, production, and delivery logistics across Europe. You can read lo The Role As our first Lead DevSecOps Engineer, you’ll own security across our product and technology estate. Operating at the Lead level and reporting into our Engineering Director, you'll act as a deep subject matter specialist, defining our 12–18 month security roadmap and embedding security into our "paved road" so doing the secure thing is the fast, default option for every engineer. You'll split your time roughly between: Strategic Security Roadmap & Governance: Defining priorities (OWASP SAMM audits), managing vendors, responsible disclosures, and advising leadership on risk trade-offs with commercial clarity. Shift-Left Controls & Developer Experience: Partnering with DX to build security into CI/CD pipelines (code/dependency scanning, secrets management, policy-as-code, feature flagging). AI-First Security & Hands-On Engineering: Hardening authentication, securing agentic AI workflows against prompt injection and data leakage, and using agentic coding tools (e.g. Claude Code, Cursor) to accelerate remediation. What We're Looking For... Deep experience embedding security into fast-moving product engineering environments across AWS (ECS/Fargate) and GCP. Expertise in infrastructure-as-code, CI/CD security, least-privilege identity, policy-as-code, and continuous monitoring. Real, personal experience using agentic coding tools to accelerate security workflows, and a strong awareness of how to secure AI systems themselves. Ability to operate as an individual contributor/expert without a team beneath you, influencing squads and translating technical risk for senior stakeholders with candour and clarity. Don't check every box? Please apply anyway! We hire for potential and diverse perspectives over exhaustive checklists. Perks & Benefits ✨ Flexibility: Core hours (10–4), hybrid or remote working, plus up to 45 days per year to work abroad. 🌴 Time Off: 25 days holiday + birthday + flexible bank holidays + a volunteering day + a day for wedding or moving house + the option to buy more annual leave 🌱 Growth & Support: Health cash plan, equity option, flexible training framework, workplace nursery scheme, and generous product discounts How We Hire Initial Chat (30-min call with our Talent Acquisition Manager) Manager Interview (Deep dive on security strategy, posture, and squad partnership with our Engineering Director ) Technical Session (Live technical exercise with Platform & Engineering team members) Final Chat with our Chief Product & Tech Officer (Need interview adjustments? Just let us know in your application, we're happy to support you however you need.) We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.