DevSecOps Engineer, London, Hybrid, Up to £90k base, Fintech, GCP
DevSecOps Engineer | London (Hybrid) | Up to £90k | Fintech | GCP
We're hiring a DevSecOps Engineer to embed security across the entire SDLC for a highly available, multi-tenant platform running on GCP and Kubernetes. You'll set the foundational security posture for a regulated fintech environment — automating compliance, hardening infrastructure, and making it easy for engineers to ship securely by default.
What you'll be doing:
- Owning security tooling — selecting, integrating, and maintaining it across our environments and CI/CD pipelines
- Engineering automated guardrails and policies across the cloud estate
- Hardening our GCP environment — IAM, network security, resource config
- Turning compliance requirements into automated, verifiable practices
- Running end-to-end vulnerability and patch management
- Building "golden path" templates so feature teams can ship fast, safely
- Supporting incident response when things do go wrong
What you'll bring:
- Deep, hands-on experience securing high-availability GCP infrastructure
- API security chops — reviewing, patterning, and upskilling other engineers
- Expert-level GKE — network policies, container runtime security, secrets management
- Solid IaC skills (Terraform or OpenTofu)
- Experience with tools like Aqua Security, Falco, Prisma Cloud, or similar CSPM/CWPP/CNAPP
- Scripting fluency — Python, Go, or Shell
- A track record of building secure CI/CD pipelines with mandatory checks (GitLab CI, GitHub Actions)
Nice to have:
- SOC2, ISO 27001, PCI DSS, or DORA exposure
- GCP Professional Security Engineer, CKS, or CISSP