DevSecOps Lead
1 day ago
About Light.
Light exists to replace factory-era ERPs with software that feels alive. Our Smart Financial Platform gives modern, global companies superpowers—automated accounting, real-time reporting, and financial flows that move at the speed of the business.
We build with our customers, ship fast, and obsess over craft. In a short time, Light has gone from idea to the operating core for leading companies like Lovable, Legora, and Keyshot. People don't just use Light—they enjoy it.
We're an early team defining a new software category. Think engineers who love debits and credits, designers who care about reconciliation states, and operators who treat finance as a product. If you're excited to modernize how the world runs money—one workflow at a time—you're in the right place.
Backed by world-class investors and advised by industry titans, we're building category-defining products with the freedom to ship ambitiously and own outcomes.
Come help us make Light the global default for next-gen finance.
The DevSecOps Lead role
As DevSecOps Lead, you'll own security across Light's engineering infrastructure and development lifecycle. You'll establish the security controls and compliance posture that enterprise fintech customers require, whilst embedding security practices that scale with our rapidly growing engineering team.
This is a hands-on technical role with strategic scope. You'll split your time between infrastructure security engineering (Terraform, AWS security services, CI/CD hardening), compliance programme execution (SOC 2, GDPR, ISO 27001), and partnering with engineering teams to build security into their workflows from the start.
Our environment:
AWS infrastructure (EKS,, RDS PostgreSQL, Lambda, ECR, S3, SES, Bedrock for AI/LCI)
Kotlin backend with Gradle, frontend with TypeScript
GitHub Actions CI/CD, Tanka/Jsonnet for Kubernetes, Terraform for infrastructure
Datadog and CloudWatch for observability, SOPS and AWS Secrets Manager for secrets
25 engineers scaling to 50+, distributed across 15+ countries
What you'll own:
You'll design and implement security controls across our AWS environment, harden our EKS cluster security, and secure our CI/CD pipelines. You'll establish security controls for our AI workflows, including Bedrock integrations, prompt validation, and model access governance. You'll lead our SOC 2 Type II compliance programme, establish security policies for GDPR and ISO 27001, and implement automated compliance monitoring. Day-to-day, you'll write Terraform, review architecture designs, triage security alerts, build security into development workflows, coordinate penetration testing, and partner with engineering on threat modelling and secure development practices.
You'll also respond to customer security questionnaires, document controls for auditors, establish incident response procedures, and work with our Head of Engineering on security roadmap and priorities.
How you fit into the team:
You combine deep technical knowledge with strategic judgment, knowing how to balance real-world risks with business speed. You're hands-on when needed, but equally capable of driving policy, compliance programmes, and long-term security maturity. You've led security in high-growth environments before — and you're ready to do it again, with impact.
Your qualifications:
5-7 years' experience in security engineering roles, preferably in fintech, SaaS or payments
Proven experience owning infrastructure and cloud security in a fast-moving environment
Deep technical expertise: AWS (VPC, IAM, EKS, Lambda, RDS), Kubernetes, Terraform/IaC
Hands-on experience with vulnerability management, penetration test oversight, secure CI/CD, container security
Familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR
Excellent risk judgment and ability to balance security requirements with business velocity
Strong communication skills — able to influence engineers and explain security to non-technical stakeholders
Bonus points:
Prior experience in fintech / financial software / payments
Certifications such as AWS Security Specialty, CISSP, CKS, OSCP, or equivalent
Experience with compliance automation platforms (Vanta, Drata, Secureframe)
Background in software engineering or prior development experience
A few tips to stand out
Show how you've balanced speed and security in a high-growth environment
Demonstrate how you've influenced culture — not just control
Share how you've measured and communicated risk, coverage, and progress
Walk us through your past playbooks or roadmaps — and how they evolved
Bonus if you can articulate the "why" behind the trade-offs you've made
The good stuff
In addition to being part of a great team and working in a really fun and innovative environment, we offer:
Competitive salary + potential stock options
Paid parental leave
25 days of annual leave + public holidays (in your country)
Regular socials and company off-sites.
A huge opportunity to shape a market-defining product and engineering culture
The famous last words
At Light, we're building the most trusted financial platform in the world — and trust starts with security. As our InfoSec & Cybersecurity Lead, you'll help us earn that trust every day.
Join the rocket ship while it's taking off
-
Head of DevSecOps
1 week ago
London, Greater London, United Kingdom KX Full time £80,000 - £120,000 per yearDevSecOps LeadDue a period of unprecedented growth KX are currently looking for a DevSecOps Lead to join our R&D team on a permanent basis.This is a truly unique opportunity to join our business as the first dedicated hire in this area and help shape our security strategy in a meaningful way.Key areas of this role include:Responsibility for network and...
-
Head of DevSecOps
1 week ago
London, Greater London, United Kingdom Livestock Information Full time £60,000 - £80,000 per yearThe salary for this role is £70,000.This role is advertised on a 12 month fixed term contract.Would you relish the challenge of embedding a true DevSecOps culture across an ambitious, tech-driven organisation?Are you passionate about leveraging automation and cloud innovation to deliver secure, scalable, and high-performing services?Can you inspire...
-
G7 Lead DevSecOps Engineer, National
3 days ago
London, Greater London, United Kingdom Insolvency Service Full time £56,799 - £63,319 per yearDetailsReference number434925Salary£56,799 - £63,319£56,799 to £63,319 (national) - £58,874 to £66,290 (London)This post attracts an R&R allowance of up to £5,150. Please note that this is a temporary allowance that is currently under review and could be removed.A Civil Service Pension with an employer contribution of 28.97%GBPJob gradeGrade 7Contract...
-
Deployment SME DevSecOps
5 days ago
London, Greater London, United Kingdom Capgemini Engineering Full time £60,000 - £100,000 per yearJob Title: Deployment SME / DevSecOpsHybrid: 2 -3 days a week working from the officeLocation: London, UKGet the future you wantChoosing Capgemini means choosing a company where you will be empowered to shape your career in the way you'd like, where you'll be supported and inspired by a collaborative community of colleagues around the world, and where you'll...
-
Senior DevSecOps engineer
2 weeks ago
London, Greater London, United Kingdom Seccl Full time £72,000 - £108,000 per yearRemote-first role within the UK, with quarterly tribe days and occasional off-sites/workshops in Bath, London or Edinburgh.About UsSeccl is the Octopus-owned embedded investment platform that's on a mission to helping more people to invest – and invest well.We're B-Corp certified with an amazing product-market fit, impressive early traction and the...
-
Lead DevOps Engineer
3 days ago
London, Greater London, United Kingdom Xpertise Recruitment Full time £60,000 - £100,000 per yearLondon | Hybrid | 6-Month Contract | Outside IR35 | Competitive Rates | Immediate StartWe're seeking aLead DevOps Engineer / Jira Adminto drive DevSecOps strategy within a majorhealth insurance organisation. You'll lead CI/CD pipeline design, GitHub Enterprise integrations, and Jira workflow optimisation to enable secure, efficient, and scalable software...
-
Information Security Lead
2 weeks ago
London, Greater London, United Kingdom Legal & General Full time £18,000 - £80,000 per yearLegal & General (L&G) is a leading UK financial services group and major global investor.We've been safeguarding people's financial futures since 1836, and strive to build a better society, while improving the lives of our customers and creating value for shareholders.We are one of the world's largest asset managers and provide powerful asset origination...
-
Information Security Lead
2 weeks ago
London, Greater London, United Kingdom Legal & General Investment Management Full time £80,000 - £100,000 per yearLondonFull-timeIT & Change4870_18055Company DescriptionLegal & General (L&G) is a leading UK financial services group and major global investor.We've been safeguarding people's financial futures since 1836, and strive to build a better society, while improving the lives of our customers and creating value for shareholders.We are one of the world's largest...
-
Open Source Lead
7 days ago
London, Greater London, United Kingdom Intelix Full time £80,000 - £120,000 per yearOpen Source Lead |Technology Risk & OSS Compliance Lead |Open Source Program OfficeLondon£100k + Bonus & BenefitsOpen Source Strategy, Governance & Risk Lead. The role is focused on defining, implementing, and overseeing enterprise-wide controls for open-source software + AI governance, and compliance within highly regulated environments.Key...
-
Security Lead
1 week ago
London, Greater London, United Kingdom NOLI Full time £80,000 - £120,000 per yearLocation: Holborn, LondonWorking Pattern: Hybrid (3 days onsite / 2 days WFH)Employment Type: Full-TimeAbout NoliNoli is a fast-scaling Beauty Tech startup backed by L'Oréal. Launched in 2024, our mission is to help every user find the right beauty products through AI-driven personalisation. Based in Holborn, London, we are building a world-class...