Назад
Company hidden
24 часа назад

Lead DevSecOps Engineer

Формат работы
remote (только Europe)/hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
UK/Netherlands
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead DevSecOps Engineer (AWS/GCP/AI Security): Owning security across the product and technology estate while defining a 12–18 month security roadmap and embedding controls into engineering workflows with an accent on cloud security, CI/CD protection, and secure AI systems. Focus on hardening authentication, defending agentic AI workflows against prompt injection and data leakage, and accelerating remediation through agentic coding tools.

Location: UK, Netherlands, or remote from Europe; hybrid or remote working available

Company

A Europe-wide direct-to-consumer flower and gifting business operating Bloom & Wild, bloomon, and Bergamotte, with technology supporting e-commerce, production, and delivery logistics.

What you will do

  • Own security across the product and technology estate as the first Lead DevSecOps Engineer.
  • Define and deliver a 12–18 month security roadmap, including OWASP SAMM audits, vendor management, responsible disclosures, and leadership risk advice.
  • Embed security into CI/CD pipelines through code and dependency scanning, secrets management, policy-as-code, and feature flagging.
  • Harden authentication and cloud infrastructure across AWS ECS/Fargate and GCP.
  • Secure agentic AI workflows against prompt injection and data leakage while using agentic coding tools to accelerate remediation.
  • Influence engineering squads and translate technical risk for senior stakeholders as an individual contributor and subject matter expert.

Requirements

  • Deep experience embedding security into fast-moving product engineering environments across AWS and GCP.
  • Expertise in infrastructure-as-code, CI/CD security, least-privilege identity, policy-as-code, and continuous monitoring.
  • Personal experience using agentic coding tools such as Claude Code or Cursor for security workflows.
  • Strong understanding of securing AI systems, including agentic workflows.
  • Ability to operate independently without a team beneath you, influence squads, and communicate technical risk clearly.
  • Must be based in the UK, Netherlands, or Europe for the remote arrangement.

Culture & Benefits

  • Core working hours are 10:00–16:00, with hybrid or remote flexibility.
  • Up to 45 days per year working abroad.
  • 25 days of holiday, birthday leave, flexible bank holidays, a volunteering day, and additional leave-buying options.
  • Health cash plan, equity option, flexible training framework, workplace nursery scheme, and product discounts.

Hiring process

  • 30-minute introductory call with the Talent Acquisition Manager.
  • Manager interview focused on security strategy, posture, and squad partnership.
  • Live technical exercise with Platform and Engineering team members, followed by a final conversation with the Chief Product & Tech Officer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →