Senior DevSecOps Engineer

PCN Media

Greater London

On-site

GBP 90,000 - 130,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PCN Media is seeking a Senior DevSecOps Engineer to embed security across the SDLC in a cloud-native, multi-tenant platform built on GCP and Kubernetes. You will own security tooling, guardrails, and automated compliance, helping the product teams ship securely in a regulated financial services context.

You will collaborate with governance and engineering, strengthening IAM, network security, and secret management, while delivering golden-path templates and incident response support.

Qualifications

  • Deep, practical experience securing high-availability cloud infrastructure (GCP).
  • Proficiency designing secure APIs and guiding engineers on secure design patterns.
  • Kubernetes security hardening including IAM, network policies, and secrets management.

Responsibilities

  • Own security tooling: select, integrate, and maintain tools across environments and CI/CD pipelines.
  • Engineer security guardrails: design and enforce automated security policies across cloud and pipelines.
  • Harden the cloud platform: strengthen IAM, network security, and resource configuration in GCP.

Skills

GCP security
Kubernetes security
Terraform/OpenTofu
CI/CD security
Python/Golang/Shell
API security

Tools

Aqua Security
Falco
Prisma Cloud
GCP IAM

Job description

CyberSec/IT Risk

Senior DevSecOps Engineer
  • Location
  • Type
  • London - United Kingdom
  • Permanent

Our client is an established open banking infrastructure provider, building secure connectivity between banks and the software platforms that businesses and consumers rely on every day. Its technology powers payment initiation, bank data access, and a suite of pre-built financial products, and it counts some of the world's most recognised names in payments, accounting software, and technology among its customers.

As one of the earlier movers in the open banking space, the company has helped shape industry standards and continues to invest heavily in the reliability and security of its platform as it scales across multiple regulated markets.

The Role

As Senior DevSecOps Engineer, you will be a key driver in embedding security into every phase of the software development lifecycle. You'll join a high-impact team responsible for securing a highly available, multi-tenant platform built on cloud-native infrastructure (GCP and Kubernetes), taking a proactive and automated approach to establishing the company's foundational security posture and ensuring it meets and exceeds the standards required of a regulated financial services provider.

Key Responsibilities
  • Own security tooling: select, integrate, and maintain security tools across environments and CI/CD pipelines.
  • Engineer security guardrails: design, implement, and enforce automated security policies across the cloud estate and pipeline.
  • Harden the cloud platform: strengthen IAM policies, network security, and resource configuration across the GCP environment.
  • Automate compliance: work with compliance and governance stakeholders to translate requirements into automated, verifiable infrastructure practices.
  • Manage vulnerabilities and patching: run the end-to-end process for identifying, triaging, and remediating vulnerabilities across infrastructure, applications, and dependencies.
  • Empower developers: build and maintain golden-path templates for secure service deployment, enabling teams to ship confidently without compromising security.
  • Support incident response: contribute expertise to the security incident response function, helping manage and resolve security events swiftly.
Your Profile
Essential
  • Deep, practical experience designing, managing, and securing high-availability infrastructure within GCP.
  • Proficiency in API security: reviewing, defining patterns for, and upskilling engineers on secure API design.
  • Expert knowledge of hardening Kubernetes (GKE) clusters, including network policies, container runtime security, and secrets management.
  • Solid skills in writing, securing, and testing infrastructure as code using Terraform or OpenTofu.
  • Hands-on experience deploying and managing security tooling (e.g. Aqua Security, Falco, Prisma Cloud, or similar CSPM/CWPP/CNAPP solutions).
  • Proficiency in at least one language relevant to security automation (Python, Golang, or Shell).
  • Proven ability to build secure, repeatable CI/CD pipelines (e.g. GitLab CI, GitHub Actions) with mandatory security checks built in.
Desirable
  • Experience working within FinTech-related certifications or frameworks such as SOC2, ISO 27001, PCI DSS, DORA, or similar regulated environments.
  • Relevant certifications such as Google Cloud Professional Security Engineer, CKS (Certified Kubernetes Security Specialist), or CISSP.

Early Success: Within your first 6–12 months, success looks like establishing the golden-path templates and automated guardrails that let feature teams deploy securely and independently, embedding compliance checks into everyday delivery, and building strong working relationships with engineering and governance stakeholders that position you as a trusted voice on the company's security posture.

Why Join
  • Genuine ownership: a foundational security role with real scope to shape the company's security posture from the ground up.
  • Meaningful scale: secure infrastructure that underpins financial products used by major payments, software, and technology platforms.
  • Regulated, high-stakes environment: work at the sharp end of financial services security, where the standards genuinely matter.
  • A high-impact, security-first team culture, with strong buy-in from engineering leadership.
Interested?

Get in touch with

Rogier Rouppe van der Voort

rogier@teampcn.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer
Senior DevSecOps Engineer

Payments & Cards Network • Greater London

On-site
GBP 100,000 - 150,000
GCP DevSecOps Engineer
GCP DevSecOps Engineer

Marshall Wolfe • Greater London

Hybrid
GBP 90,000 - 130,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Space Executive • Greater London

On-site
GBP 70,000 - 120,000
Senior Security Engineer
Senior Security Engineer

Atarus • England

On-site
GBP 70,000 - 90,000
Budget for certifications
Opportunities for continuous learning
Clear progression to Staff / Principal Security Engineer
Cloud Security Engineer
Cloud Security Engineer

The French Sourcer • Greater London

Hybrid
GBP 70,000 - 110,000
Private health cover
Pension contribution
Equity plan
+1
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Hiire.co • Greater London

On-site
GBP 90,000 - 110,000
Senior Security Engineer
Senior Security Engineer

Myn • Greater London

On-site
GBP 80,000 - 100,000
Senior Application Security Consultant
Senior Application Security Consultant

Salt • Greater London

Hybrid
GBP 90,000 - 120,000
DevSecOps Engineer
DevSecOps Engineer

Maxwell Bond • Manchester

Hybrid
GBP 60,000 - 70,000
Performance-related bonus
25 days annual leave plus bank holidays
Pension scheme with employer contributions
+1
Security Engineer
Security Engineer

Caspian One • London

Hybrid
GBP 80,000 - 100,000