24 часа назад
Lead DevSecOps Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead DevSecOps Engineer (AWS/GCP/AI Security): Owning security across the product and technology estate while defining a 12–18 month security roadmap and embedding controls into engineering workflows with an accent on cloud security, CI/CD protection, and secure AI systems. Focus on hardening authentication, defending agentic AI workflows against prompt injection and data leakage, and accelerating remediation through agentic coding tools.
Location: UK, Netherlands, or remote from Europe; hybrid or remote working available
Company
A Europe-wide direct-to-consumer flower and gifting business operating Bloom & Wild, bloomon, and Bergamotte, with technology supporting e-commerce, production, and delivery logistics.
What you will do
- Own security across the product and technology estate as the first Lead DevSecOps Engineer.
- Define and deliver a 12–18 month security roadmap, including OWASP SAMM audits, vendor management, responsible disclosures, and leadership risk advice.
- Embed security into CI/CD pipelines through code and dependency scanning, secrets management, policy-as-code, and feature flagging.
- Harden authentication and cloud infrastructure across AWS ECS/Fargate and GCP.
- Secure agentic AI workflows against prompt injection and data leakage while using agentic coding tools to accelerate remediation.
- Influence engineering squads and translate technical risk for senior stakeholders as an individual contributor and subject matter expert.
Requirements
- Deep experience embedding security into fast-moving product engineering environments across AWS and GCP.
- Expertise in infrastructure-as-code, CI/CD security, least-privilege identity, policy-as-code, and continuous monitoring.
- Personal experience using agentic coding tools such as Claude Code or Cursor for security workflows.
- Strong understanding of securing AI systems, including agentic workflows.
- Ability to operate independently without a team beneath you, influence squads, and communicate technical risk clearly.
- Must be based in the UK, Netherlands, or Europe for the remote arrangement.
Culture & Benefits
- Core working hours are 10:00–16:00, with hybrid or remote flexibility.
- Up to 45 days per year working abroad.
- 25 days of holiday, birthday leave, flexible bank holidays, a volunteering day, and additional leave-buying options.
- Health cash plan, equity option, flexible training framework, workplace nursery scheme, and product discounts.
Hiring process
- 30-minute introductory call with the Talent Acquisition Manager.
- Manager interview focused on security strategy, posture, and squad partnership.
- Live technical exercise with Platform and Engineering team members, followed by a final conversation with the Chief Product & Tech Officer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
20 часов назад
Security Engineering Manager (AI/Cybersecurity)
Valor Capital Group
6 дней назад
Infrastructure Security Engineer (AI)
Databricks
7 дней назад
Senior Specialist Solutions Engineer (Platform Security & Cloud Infrastructure)
6 дней назад
Security Architect (Cybersecurity)
Teleport
6 дней назад
Senior Software Engineer (Security)
3 дня назад