Senior DevSecOps Engineer

Payments & Cards Network

Greater London

On-site

GBP 100,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Payments & Cards Network in London is seeking a Senior DevSecOps Engineer to embed security throughout the SDLC for a cloud-native, multi-tenant platform built on GCP and Kubernetes.

You will own security tooling, automate guardrails, harden IAM and network configurations, and translate compliance requirements into automated infrastructure practices while partnering with engineering and governance teams.

Qualifications

  • Deep, practical experience designing, managing, and securing high-availability infrastructure within GCP.
  • Proficiency in API security: reviewing, defining patterns for, and upskilling engineers on secure API design.
  • Expert knowledge of hardening Kubernetes (GKE) clusters, including network policies, container runtime security, and secrets management.
  • Solid skills in writing, securing, and testing infrastructure as code using Terraform or OpenTofu.
  • Hands-on experience deploying and managing security tooling (e.g. Aqua Security, Falco, Prisma Cloud, or similar CSPM/CWPP/CNAPP solutions).
  • Proficiency in at least one language relevant to security automation (Python, Golang, or Shell).
  • Proven ability to build secure, repeatable CI/CD pipelines (e.g. GitLab CI, GitHub Actions) with mandatory security checks built in.

Responsibilities

  • Own security tooling: select, integrate, and maintain security tools across environments and CI/CD pipelines.
  • Engineer security guardrails: design, implement, and enforce automated security policies across the cloud estate and pipeline.
  • Harden the cloud platform: strengthen IAM policies, network security, and resource configuration across the GCP environment.
  • Automate compliance: work with compliance and governance stakeholders to translate requirements into automated, verifiable infrastructure practices.
  • Manage vulnerabilities and patching: run the end-to-end process for identifying, triaging, and remediating vulnerabilities across infrastructure, applications, and dependencies.
  • Empower developers: build and maintain golden-path templates for secure service deployment, enabling teams to ship confidently without compromising security.
  • Support incident response: contribute expertise to the security incident response function, helping manage and resolve security events swiftly.

Skills

GCP security
Kubernetes hardening
Terraform/OpenTofu
Security tooling
CI/CD security
API security
Python/Golang
IAM security
Vulnerability management

Tools

Aqua Security
Falco
Prisma Cloud
CSPM tools
GitHub Actions
GitLab CI
OpenTofu

Job description

Our client is an established open banking infrastructure provider, building secure connectivity between banks and the software platforms that businesses and consumers rely on every day. Its technology powers payment initiation, bank data access, and a suite of pre‑built financial products, and it counts some of the world’s most recognised names in payments, accounting software, and technology among its customers.

As one of the earlier movers in the open banking space, the company has helped shape industry standards and continues to invest heavily in the reliability and security of its platform as it scales across multiple regulated markets.

The Role

As Senior DevSecOps Engineer, you will be a key driver in embedding security into every phase of the software development lifecycle. You’ll join a high-impact team responsible for securing a highly available, multi-tenant platform built on cloud-native infrastructure (GCP and Kubernetes), taking a proactive and automated approach to establishing the company’s foundational security posture and ensuring it meets and exceeds the standards required of a regulated financial services provider.

Key Responsibilities
  • Own security tooling: select, integrate, and maintain security tools across environments and CI/CD pipelines.
  • Engineer security guardrails: design, implement, and enforce automated security policies across the cloud estate and pipeline.
  • Harden the cloud platform: strengthen IAM policies, network security, and resource configuration across the GCP environment.
  • Automate compliance: work with compliance and governance stakeholders to translate requirements into automated, verifiable infrastructure practices.
  • Manage vulnerabilities and patching: run the end-to-end process for identifying, triaging, and remediating vulnerabilities across infrastructure, applications, and dependencies.
  • Empower developers: build and maintain golden-path templates for secure service deployment, enabling teams to ship confidently without compromising security.
  • Support incident response: contribute expertise to the security incident response function, helping manage and resolve security events swiftly.
Your Profile
Essential:
  • Deep, practical experience designing, managing, and securing high-availability infrastructure within GCP.
  • Proficiency in API security: reviewing, defining patterns for, and upskilling engineers on secure API design.
  • Expert knowledge of hardening Kubernetes (GKE) clusters, including network policies, container runtime security, and secrets management.
  • Solid skills in writing, securing, and testing infrastructure as code using Terraform or OpenTofu.
  • Hands‑on experience deploying and managing security tooling (e.g. Aqua Security, Falco, Prisma Cloud, or similar CSPM/CWPP/CNAPP solutions).
  • Proficiency in at least one language relevant to security automation (Python, Golang, or Shell).
  • Proven ability to build secure, repeatable CI/CD pipelines (e.g. GitLab CI, GitHub Actions) with mandatory security checks built in.
Desirable:
  • Experience working within FinTech-related certifications or frameworks such as SOC2, ISO 27001, PCI DSS, DORA, or similar regulated environments.
  • Relevant certifications such as Google Cloud Professional Security Engineer, CKS (Certified Kubernetes Security Specialist), or CISSP.
Early Success

Within your first 6–12 months, success looks like establishing the golden-path templates and automated guardrails that let feature teams deploy securely and independently, embedding compliance checks into everyday delivery, and building strong working relationships with engineering and governance stakeholders that position you as a trusted voice on the company’s security posture.

Why Join
  • Genuine ownership: a foundational security role with real scope to shape the company’s security posture from the ground up.
  • Meaningful scale: secure infrastructure that underpins financial products used by major payments, software, and technology platforms.
  • Regulated, high-stakes environment: work at the sharp end of financial services security, where the standards genuinely matter.
  • A high-impact, security-first team culture, with strong buy-in from engineering leadership.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer
Senior DevSecOps Engineer

PCN Media • Greater London

On-site
GBP 90,000 - 130,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Space Executive • Greater London

On-site
GBP 70,000 - 120,000
Senior Security Engineer
Senior Security Engineer

Atarus • England

On-site
GBP 70,000 - 90,000
Budget for certifications
Opportunities for continuous learning
Clear progression to Staff / Principal Security Engineer
GCP DevSecOps Engineer
GCP DevSecOps Engineer

Marshall Wolfe • Greater London

Hybrid
GBP 90,000 - 130,000
SecOps Engineer
SecOps Engineer

Apache Associates • City Of London

On-site
GBP 90,000 - 130,000
Office in City of London (4 days on‑si
Lead Security Engineer
Lead Security Engineer

Winston Fox • Greater London

On-site
GBP 70,000 - 95,000
Senior Security Engineer
Senior Security Engineer

Spendesk • Greater London

On-site
GBP 90,000 - 120,000
Devops Engineer
Devops Engineer

Glocomms • City Of London

On-site
GBP 50,000 - 80,000
Security Engineer
Security Engineer

Selby Jennings • City Of London

On-site
GBP 90,000 - 130,000
Senior DevSecOps Engineer — Cloud Security & Automation
Senior DevSecOps Engineer — Cloud Security & Automation

PCN Media • Greater London

On-site
GBP 90,000 - 130,000