Senior DevSecOps Engineer

Monument Technology — United Kingdom · Posted ~3 hours ago

Senior Full-time Hybrid

Skills

DevSecOps Cloud infrastructure Cybersecurity CI/CD Infrastructure automation Cloud Containers

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior DevSecOps position focused on designing, securing, and operating cloud-native technology platforms. The role involves automation, infrastructure improvements, and collaboration across engineering teams.

Highlights

Hybrid senior engineering role focused on secure cloud-native platforms, automation, and modern financial technology infrastructure.

Description

Role: Senior DevSecOps Engineer Location: London (Oxford Circus) Hybrid: 1-2 days per week in the office About Monument Technology Limited Monument Technology provides everything needed to build and run a bank with an open, configurable, end-to-end banking platform as a service which uses best-in-class components to empower small and medium-sized banks around the world to thrive in the digital age. Monument Technology takes the proven, end to end platform developed for Monument Bank, the leading bank for the mass affluent, and makes it available to financial institutions in the UK and globally as a licensed Banking Platform as a Service. Our platform is a full-stack ‘bank or building-society-in-a-box’, delivering all the functionality needed to run and grow a modern, digital-led financial institution, including native mobile app and web experience, servicing, core and all the back-end technologies, integrated in a single, cloud-native solution (“Bank-in-a-Box”). Monument Technology provides everything in one solution, taking care of all third-party contracts and integrations as well as ongoing maintenance and future platform enhancements - all for one annual licence fee, allowing our customers to embrace the most modern technology available, without any of the complexity. THE ROLE We’re looking for a hands-on Senior DevSecOps Engineer to own the security engineering and DevSecOps quality of our AWS estate. Because Monument Technology sells a banking platform to other banks, our security posture is a commercial precondition, not simply an internal control. This role exists to make security engineering an automated, evidenced property of the platform rather than a manual, person-dependent activity. You’ll design and enhance our AWS architecture with a view to extending it across multiple cloud providers, configure and tune AWS and third-party security tooling, and lead AWS security projects end to end. You’ll provide security expertise to the delivery teams, review and make recommendations on AWS changes, releases and new functionality, and drive continuous improvement of our security position through automated scanning and monitoring. Just as important is the influencing side of the role: working collaboratively with onshore and offshore Scrum teams to champion good DevSecOps and security engineering practice, and working with our managed Security Operations Centre (SOC), security product and penetration testing providers. There are no direct reports at the moment, though this may change as the company expands. HOW YOU’LL MAKE AN IMPACT Own the security engineering and DevSecOps quality of the AWS estate, taking day-to-day ownership of AWS security tooling including GuardDuty, Security Hub, WAF and CloudTrail.Design and enhance the AWS architecture with a view to extending it across multiple cloud providers, leading AWS security projects end to end.Express controls in code and continuously monitor the security position, driving a measurable reduction in the open security findings backlog through automated scanning and monitoring.Embed security review as a standard step in the change and release process, and tighten pipeline gates with integrated code quality and security tooling such as SonarCloud.Provide security expertise to delivery teams, reviewing and making recommendations on AWS changes, releases and new functionality.Champion good DevSecOps practice across onshore and offshore Scrum teams by making the secure path the easy path, using paved roads, templates and automated gates over mandates.Work with the managed Security Operations Centre (SOC), security product vendors and penetration testing providers to strengthen the platform’s security assurance.Take ownership of Monument Technology environments and communicate with the team and external clients about environment activities and client-facing security assurance.Contribute credibly to extending the platform to a second cloud provider, becoming the recognised technical authority on cloud security and DevOps for the platform. WE LOOK FOR PEOPLE WITH Hands-on AWS engineering in a multi-account AWS Organisation is essential, including EC2, EKS, S3, EFS, RDS, DynamoDB, ElastiCache, API Gateway, Lambda, WAF, CloudFormation and Control Tower.Cloud security engineering experience securing AWS environments using WAF, GuardDuty, Security Hub, Shield, CloudTrail, CloudWatch, X-Ray, KMS, Secrets Manager and Cognito.Infrastructure as Code fluency with Terraform and CloudFormation, writing modules from scratch and having migrated an existing estate into code.Strong Kubernetes configuration and troubleshooting across Dockerfiles, manifests and Helm charts, supporting a microservice architecture on EKS.DevSecOps tooling and CI/CD experience with Jenkins, GitHub Actions, ArgoCD and Bitbucket Pipelines, with code quality and security gates integrated.Scripting and automation in Bash and/or Python, and comfort delivering in an agile environment alongside Product Owners and engineering teams.Financial services or comparable regulated-sector experience operating secure, resilient and performant cloud-hosted platform services, with the credibility to champion good practice with onshore and offshore Scrum teams.Desirable: equivalent depth in a second public cloud (Azure or GCP); Microsoft 365 and Active Directory security engineering; experience building reusable module libraries or landing zones; relevant Kubernetes certification; observability tooling such as Prometheus, Grafana or Coralogix; and experience supporting a SaaS or BaaS platform serving external bank clients.There is no formal degree requirement; AWS Security Specialty, CKA/CKS or equivalent certifications are a plus rather than a filter. OUR CULTURE AND VALUES Our culture and values align with our mission to truly understand and offer exceptional service to our clients. The Monument Technology team is passionate about building more than a bank and more than a technology platform. We are driven to create solutions that respect our clients’ time, complexity and ambition. We are guided by integrity, attentiveness, a sense of community and innovation. We build trusted relationships through collaboration, attention to detail and a commitment to continuous improvement. Through inclusive thinking and purposeful innovation, we enable our clients and colleagues to achieve more.