Lead DevSecOps Engineer
Bloom & Wild GroupOnline Flower company
London, United KingdomLead
General Catalyst
Index Ventures
Novator
Latitude Ventures
D4 Ventures
Burda Principal Investments
Software Engineering
About the role
TL;DR
Lead DevSecOps Engineer to own and embed security across the tech estate.
- •As the first Lead DevSecOps Engineer, you will own security across the product and technology estate.
- •You will define the 12-18 month security roadmap and embed security into the "paved road" so doing the secure thing is the fast, default option for every engineer.
- •Key Responsibilities Define strategic security roadmap and governance, including OWASP SAMM audits and vendor management.
- •Implement shift-left controls and improve developer experience by integrating security into CI/CD pipelines.
- •Focus on AI-first security, hardening authentication, securing AI workflows, and using agentic coding tools for remediation.
- •Requirements Deep experience embedding security into fast-moving product engineering environments across AWS (ECS/Fargate) and GCP.
- •Expertise in infrastructure-as-code, CI/CD security, least-privilege identity, policy-as-code, and continuous monitoring.
- •Real experience using agentic coding tools and awareness of how to secure AI systems.
- •Ability to operate as an individual contributor, influencing squads and translating technical risk for senior stakeholders.
Required skills
AWSGoogle CloudTerraformCI/CDOWASPECS
Nice-to-have skills
Ruby on RailsAngularPostgreSQLDatadog
Domain expertise
ecommerce
Benefits & perks
Core hours (10–4), Hybrid or remote working, Up to 45 days per year to work abroad, 25 days holiday + birthday + flexible bank holidays + a volunteering day + a day for wedding or moving house + the option to buy more annual leave, Health cash plan, Equity option, Flexible training framework, Workplace nursery scheme, Generous product discounts
Tech stack
AWSGoogle CloudRuby on RailsAngularPostgreSQLTerraformDatadogECSCI/CDOWASP