Get more replies from employers
Send a job-specific resume in minutes.
Bloom & Wild Group is looking for a Lead DevSecOps Engineer to own security across the product and technology estate. You will report to the Engineering Director and define a 12-18 month security roadmap, embedding secure choices as the fast default option for every engineer.
You’ll split time roughly between strategic governance, shift-left controls in CI/CD pipelines, and hands-on security for AI workflows to harden authentication and safeguard data.
Join Bloom & Wild Group as a Lead DevSecOps Engineer.
Tech Stack: AWS (Fargate/ECS), GCP, Ruby on Rails, Angular, PostgreSQL, Terraform, Datadog
Bloom & Wild Group is Europe’s largest direct-to-consumer flower and gifting business, incorporating Bloom & Wild, bloomon, and Bergamotte. Its 65+ person Tech team builds the software powering e-commerce platforms, production, and delivery logistics across Europe.
As the first Lead DevSecOps Engineer, you’ll own security across the product and technology estate. Operating at the Lead level and reporting into the Engineering Director, you’ll act as a deep subject matter specialist, defining a 12-18 month security roadmap and embedding security into the \"paved road\" so doing the secure thing is the fast, default option for every engineer.
You’ll split your time roughly between:
Strategic Security Roadmap & Governance: Defining priorities (OWASP SAMM audits), managing vendors, responsible disclosures, and advising leadership on risk trade-offs with commercial clarity.
Shift-Left Controls & Developer Experience: Partnering with DX to build security into CI/CD pipelines (code/dependency scanning, secrets management, policy-as-code, feature flagging).
AI-First Security & Hands-On Engineering: Hardening authentication, securing agentic AI workflows against prompt injection and data leakage, and using agentic coding tools (e.g. Claude Code, Cursor) to accelerate remediation.
Deep experience embedding security into fast-moving product engineering environments across AWS (ECS/Fargate) and GCP.
Expertise in infrastructure-as-code, CI/CD security, least-privilege identity, policy-as-code, and continuous monitoring.
Real, personal experience using agentic coding tools to accelerate security workflows, and a strong awareness of how to secure AI systems themselves.
Ability to operate as an individual contributor/expert without a team beneath you, influencing squads and translating technical risk for senior stakeholders with candour and clarity.
Flexibility: Core hours (10-4), hybrid or remote working, plus up to 45 days per year to work abroad.
Time Off: 25 days holiday + birthday + flexible bank holidays + a volunteering day + a day for wedding or moving house + the option to buy more annual leave
Growth & Support: Health cash plan, equity option, flexible training framework, workplace nursery scheme, and generous product discounts