Senior DevSecOps Engineer
Senior DevSecOps Engineer

Senior DevSecOps Engineer

Full-Time 48000 - 84000 ÂŁ / year (est.) No home office possible
L

At a Glance

  • Tasks: Own security across engineering infrastructure and development lifecycle at Light.
  • Company: Join an innovative fintech company redefining financial software.
  • Benefits: Competitive salary, stock options, 25 days leave, and fun socials.
  • Why this job: Make a real impact on security in a fast-growing tech environment.
  • Qualifications: 5-7 years in security engineering, preferably in fintech or SaaS.
  • Other info: Shape a market-defining product and enjoy excellent career growth.

The predicted salary is between 48000 - 84000 ÂŁ per year.

About Light. Light exists to replace factory-era ERPs with software that feels alive. Our Smart Financial Platform gives modern, global companies superpowers—automated accounting, real-time reporting, and financial flows that move at the speed of the business. We build with our customers, ship fast, and obsess over craft. In a short time, Light has gone from idea to the operating core for leading companies like Lovable, Legora, and Keyshot. People don’t just use Light—they enjoy it. We’re an early team defining a new software category. Think engineers who love debits and credits, designers who care about reconciliation states, and operators who treat finance as a product. If you’re excited to modernize how the world runs money—one workflow at a time—you’re in the right place. Backed by world-class investors and advised by industry titans, we’re building category-defining products with the freedom to ship ambitiously and own outcomes. Come help us make Light the global default for next-gen finance.

The Senior DevSecOps Engineer role

You will own security across Light's engineering infrastructure and development lifecycle. You will establish the security controls and compliance posture that enterprise fintech customers require, whilst embedding security practices that scale with our rapidly growing engineering team. This is a hands-on technical role with strategic scope. You will split your time between infrastructure security engineering (Terraform, AWS security services, CI/CD hardening), compliance programme execution (SOC 2, GDPR, ISO 27001), and partnering with engineering teams to build security into their workflows from the start.

Our environment:

  • AWS infrastructure (EKS, RDS PostgreSQL, Lambda, ECR, S3, SES, Bedrock for AI/LCI)
  • Kotlin backend with Gradle, Next.js frontend with TypeScript
  • GitHub Actions CI/CD, Tanka/Jsonnet for Kubernetes, Terraform for infrastructure
  • Datadog and CloudWatch for observability, SOPS and AWS Secrets Manager for secrets
  • 25 engineers scaling to 50+, distributed across 15+ countries

What you will own:

  • You will design and implement security controls across our AWS environment, harden our EKS cluster security, and secure our CI/CD pipelines.
  • You will establish security controls for our AI workflows, including Bedrock integrations, prompt validation, and model access governance.
  • You will lead our SOC 2 Type II compliance programme, establish security policies for GDPR and ISO 27001, and implement automated compliance monitoring.
  • Day-to-day, you will write Terraform, review architecture designs, triage security alerts, build security into development workflows, coordinate penetration testing, and partner with engineering on threat modelling and secure development practices.
  • You will also respond to customer security questionnaires, document controls for auditors, establish incident response procedures, and work with our Head of Engineering on security roadmap and priorities.

How you fit into the team:

You combine deep technical knowledge with strategic judgment, knowing how to balance real-world risks with business speed. You are hands-on when needed, but equally capable of driving policy, compliance programmes, and long-term security maturity. You have led security in high-growth environments before — and you are ready to do it again, with impact.

Your qualifications:

  • 5-7 years' experience in security engineering roles, preferably in fintech, SaaS or payments
  • Proven experience owning infrastructure and cloud security in a fast-moving environment
  • Deep technical expertise: AWS (VPC, IAM, EKS, Lambda, RDS), Kubernetes, Terraform/IaC
  • Hands-on experience with vulnerability management, penetration test oversight, secure CI/CD, container security
  • Familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR
  • Excellent risk judgment and ability to balance security requirements with business velocity
  • Strong communication skills — able to influence engineers and explain security to non-technical stakeholders
  • Practical experience using AI or emerging technology tools to improve productivity, insight, or decision-making, with the ability to apply first-principles thinking to new problems.

Bonus points:

  • Prior experience in fintech / financial software / payments
  • Certifications such as AWS Security Specialty, CISSP, CKS, OSCP, or equivalent
  • Experience with compliance automation platforms (Vanta, Drata, Secureframe)
  • Background in software engineering or prior development experience

A few tips to stand out:

  • Show how you’ve balanced speed and security in a high-growth environment
  • Demonstrate how you’ve influenced culture — not just control
  • Share how you’ve measured and communicated risk, coverage, and progress
  • Walk us through your past playbooks or roadmaps — and how they evolved
  • Bonus if you can articulate the “why” behind the trade-offs you’ve made

The good stuff:

In addition to being part of a great team and working in a really fun and innovative environment, we offer:

  • Competitive salary + potential stock options
  • 25 days of annual leave + public holidays (in your country)
  • Regular socials and company off-sites.
  • A huge opportunity to shape a market-defining product and engineering culture

The famous last words:

At Light, we’re building the most trusted financial platform in the world — and trust starts with security. As our Security Lead, you’ll help us earn that trust every day. Join the rocket ship while it’s taking off.

Senior DevSecOps Engineer employer: Light

At Light, we pride ourselves on being an exceptional employer that fosters a vibrant and innovative work culture. Our team enjoys competitive salaries, generous annual leave, and the opportunity to shape a market-defining product in a fast-paced environment. With a strong focus on employee growth and collaboration, we empower our engineers to take ownership of their work while ensuring they have the support and resources needed to thrive.
L

Contact Detail:

Light Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior DevSecOps Engineer

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to security engineering and cloud infrastructure. This gives potential employers a taste of what you can do.

✨Tip Number 3

Prepare for interviews by brushing up on your technical knowledge and soft skills. Be ready to discuss how you've balanced speed and security in past roles, and don’t forget to highlight your experience with compliance frameworks!

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in being part of our team at Light, where we’re all about building something amazing together.

We think you need these skills to ace Senior DevSecOps Engineer

AWS Security Services
Terraform
CI/CD Hardening
SOC 2 Compliance
GDPR Compliance
ISO 27001 Compliance
Kubernetes
Vulnerability Management
Penetration Testing
Container Security
Risk Assessment
Communication Skills
Incident Response Procedures
Security Policy Development
AI Workflow Security

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Senior DevSecOps Engineer role. Highlight your experience with AWS, Terraform, and compliance frameworks like SOC 2 and GDPR. We want to see how your skills align with what we’re building at Light!

Showcase Your Impact: When detailing your past experiences, focus on how you’ve balanced speed and security in high-growth environments. Share specific examples of how you’ve influenced culture and improved security practices. We love seeing tangible results!

Communicate Clearly: Strong communication skills are key! Make sure you can explain complex security concepts in a way that non-technical folks can understand. This will show us that you can bridge the gap between engineering and security effectively.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates. Plus, we love seeing candidates who take that extra step!

How to prepare for a job interview at Light

✨Know Your Tech Inside Out

Make sure you’re well-versed in the technologies mentioned in the job description, like AWS, Terraform, and Kubernetes. Be ready to discuss your hands-on experience with these tools and how you've implemented security measures in past roles.

✨Showcase Your Compliance Knowledge

Familiarise yourself with compliance frameworks such as SOC 2, GDPR, and ISO 27001. Prepare examples of how you've led compliance programmes or established security policies in previous positions, as this will demonstrate your strategic understanding of security in a fintech environment.

✨Balance Speed and Security

Be prepared to discuss how you've successfully balanced the need for speed in a high-growth environment with robust security practices. Share specific instances where you influenced engineering teams to adopt secure development workflows without slowing down their processes.

✨Communicate Effectively

Strong communication skills are key! Practice explaining complex security concepts in simple terms, especially for non-technical stakeholders. This will show that you can bridge the gap between technical and non-technical teams, which is crucial for the role.

Senior DevSecOps Engineer
Light

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

L
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>