Head of DevSecOps
RemoteLondon Area, United KingdomseniorFull-time
- Posted
- today
- Source
- LinkedIn (remote, Europe)
- Field
- Engineering, Security
Skills
KubernetesLeadershipTerraformSecurityRoadmappingPythonDevOpsCI/CDAWSGo
Description
Head of DevSecOps
We’re a fast-growing deeptech startup looking for a Head of DevSecOps to build and lead our DevSecOps function from the ground up.
This is a foundational hire with huge scope, significant technical ownership and a genuine opportunity to shape how the company builds, secures and scales its engineering infrastructure.
You won’t be inheriting an established DevSecOps function or spending your time maintaining someone else’s tooling. You’ll be the first dedicated DevSecOps hire, responsible for defining the strategy, architecture, tooling and security practices that will underpin the engineering organisation as we scale.
This is a hands-on leadership role. You’ll set the direction, build the foundations yourself and have the scope to grow the function around you over time.
What you'll own
- Define and own the company-wide DevSecOps strategy and roadmap
- Design and build our cloud-native infrastructure and internal developer platform
- Establish secure, scalable CI/CD and GitOps practices
- Build security directly into the software development lifecycle
- Own infrastructure security across Kubernetes, AWS and cloud-native environments
- Introduce policy-as-code and automated security controls
- Develop tooling that makes secure development the default for engineering teams
- Establish monitoring, observability and operational resilience
- Build processes and technical controls around security compliance and accreditation
- Work closely with engineering leadership to embed Secure by Design principles
- Establish the standards, practices and architecture that future DevSecOps engineers will build upon
- Hire and develop the team as the function grows
What you'll work with
- Kubernetes and containerised infrastructure
- AWS and cloud-native environments
- Terraform / Infrastructure as Code
- CI/CD and GitOps
- Python, Go or Bash
- GitLab and internal developer tooling
- Prometheus, OpenTelemetry or ELK
- Policy-as-code and automated security controls
- Secure software development and deployment practices
What we're looking for
We’re particularly interested in engineers who have security-focused infrastructure experience, rather than purely traditional DevOps backgrounds.
You might have experience with:
- Secure by Design
- NIST frameworks
- SOC 2 / ISO 27001 / Cyber Essentials
- UK government or regulated environments
- Cloud security
- Security-focused CI/CD
- Kubernetes security
- Policy-as-code
- Compliance automation
- Threat modelling
- Secure SDLC
- Building security controls directly into development tooling
We’re not expecting you to tick every box.
We’re looking for someone technically exceptional, hands-on and highly autonomous, who can operate at both the architectural and implementation level and is comfortable taking complete ownership of a function that doesn’t yet exist.
Why join us?
This is a chance to build the DevSecOps function from zero.
You’ll have significant influence over our technical direction, work directly with senior engineering leadership and define the foundations on which the wider engineering organisation will scale.
There is no existing playbook to follow and no legacy DevOps function to inherit. You’ll be writing the playbook.
For the right person, there is also significant scope to build and lead a team around you as the company grows.
If you want to build infrastructure where security, resilience and reliability genuinely matter, and want the ownership that comes with being the person responsible for making that happen, this is an opportunity to make a substantial impact.
JobMatch aggregates public listings. Always apply through the original posting.