Summary
✨ AI‑Generated
A DevSecOps engineering role focused on embedding security into software delivery, managing cloud infrastructure protection, and automating compliance controls.
Highlights
Foundational security role with ownership of cloud security practices, automation, compliance, and secure delivery processes.
Description
DevSecOps Engineer, Fintech, GCP, London (Hybrid), Up to £90k
A regulated fintech is looking for a DevSecOps Engineer to build security into every stage of the SDLC on a highly available, multi-tenant platform built on GCP and Kubernetes.
This is a foundational role: you'll define the security posture from the ground up, automate compliance, harden the infrastructure, and make secure delivery the default for every engineer.
What you'll be doing:
Owning the security toolchain: choosing, integrating, and maintaining tools across environments and CI/CDDesigning automated guardrails and policy enforcement across the cloud estateHardening GCP, covering IAM, network security, and resource configurationConverting compliance requirements into automated, auditable controlsManaging vulnerability and patching end to endCreating "golden path" templates that let feature teams move quickly and securelyContributing to incident response when issues arise
What you'll bring:
Extensive hands-on experience securing high-availability GCP environmentsStrong API security skills, including reviewing APIs, defining patterns, and coaching other engineersExpert GKE knowledge, including network policies, container runtime security, and secrets managementProficiency with Infrastructure as Code (Terraform or OpenTofu)Experience with Aqua Security, Falco, Prisma Cloud, or comparable CSPM/CWPP/CNAPP toolingConfident scripting in Python, Go, or ShellProven experience building secure CI/CD pipelines with enforced checks (GitLab CI, GitHub Actions)
Nice to have:
Exposure to SOC2, ISO 27001, PCI DSS, or DORAGCP Professional Security Engineer, CKS, or CISSP certification