bloomon
Posted 1w ago

Lead DevSecOps Engineer

bloomon
London or Netherlands
HybridFull Time
Responsibilities
  • defining roadmaps
  • embedding security
  • hardening authentication
Requirements
  • Deep AWS and GCP security experience
  • Infrastructure-as-code
  • CI/CD security
  • Least-privilege identity
  • Policy-as-code
  • Continuous monitoring
  • AI security, and agentic coding tool experience
Technical tools mentioned
Amazon Web Services (AWS)FargateAmazon ECSGoogle Cloud Platform (GCP)Ruby on RailsAngularPostgreSQLTerraformDatadogCI/CDOWASP SAMMClaude CodeCursor

Job description

📍 Location: UK, Netherlands, or Remote (Europe)

🛠️ Tech Stack: AWS (Fargate/ECS), GCP, Ruby on Rails, Angular, PostgreSQL, Terraform, Datadog

 

About Tech at Bloom & Wild Group 💐

We’re Europe’s largest direct-to-consumer flower and gifting business (incorporating Bloom & Wild, bloomon, and Bergamotte). Our 65+ person Tech team builds the software powering our e-commerce platforms, production, and delivery logistics across Europe. You can read lo



The Role

As our first Lead DevSecOps Engineer, you’ll own security across our product and technology estate. Operating at the Lead level and reporting into our Engineering Director, you'll act as a deep subject matter specialist, defining our 12–18 month security roadmap and embedding security into our "paved road" so doing the secure thing is the fast, default option for every engineer.

You'll split your time roughly between:

  • Strategic Security Roadmap & Governance: Defining priorities (OWASP SAMM audits), managing vendors, responsible disclosures, and advising leadership on risk trade-offs with commercial clarity.

  • Shift-Left Controls & Developer Experience: Partnering with DX to build security into CI/CD pipelines (code/dependency scanning, secrets management, policy-as-code, feature flagging).

  • AI-First Security & Hands-On Engineering: Hardening authentication, securing agentic AI workflows against prompt injection and data leakage, and using agentic coding tools (e.g. Claude Code, Cursor) to accelerate remediation.

  •  



What we're looking for...
  • Deep experience embedding security into fast-moving product engineering environments across AWS (ECS/Fargate) and GCP.

  • Expertise in infrastructure-as-code, CI/CD security, least-privilege identity, policy-as-code, and continuous monitoring.

  • Real, personal experience using agentic coding tools to accelerate security workflows, and a strong awareness of how to secure AI systems themselves.

  • Ability to operate as an individual contributor/expert without a team beneath you, influencing squads and translating technical risk for senior stakeholders with candour and clarity.

  • Don't check every box? Please apply anyway! We hire for potential and diverse perspectives over exhaustive checklists.

     



Perks & Benefits
  • Flexibility: Core hours (10–4), hybrid or remote working, plus up to 45 days per year to work abroad.

  • 🌴 Time Off: 25 days holiday + birthday + flexible bank holidays + a volunteering day + a day for wedding or moving house + the option to buy more annual leave

  • 🌱 Growth & Support: Health cash plan, equity option, flexible training framework, workplace nursery scheme, and generous product discounts



  • How we hire
    1. Initial Chat (30-min call with our Talent Acquisition Manager)

    2. Manager Interview (Deep dive on security strategy, posture, and squad partnership with our Engineering Director )

    3. Technical Session (Live technical exercise with Platform & Engineering team members)

    4. Final Chat with our Chief Product & Tech Officer

    (Need interview adjustments? Just let us know in your application, we're happy to support you however you need.)

    About bloomon

    Direct-to-consumer online flower and gift delivery service.

    Year founded
    2014
    Employees
    130
    Organization type
    Private
    Latest investment
    Raised $102.00M Series D (2021) — led by General Catalyst
    Subsidiaries
    Headquarters
    NL

    Similar jobs

    DevSecOps Engineer roles near London, England
    4w
    Save
    Mark Applied
    Hide
    Senior DevSecOps Engineer
    London, England, United Kingdom
    HybridFull Time
    Betway
    BetwayNYSE: SGHC: Global provider of online sports betting and casino games.
    Hands-on application and platform security experience including SAST/DAST/SCA, CI/CD security, container security, IaC knowledge, cloud IAM, audit/compliance support, and strong communication.
    GitHub Actions, GitLab CI, Jenkins, Azure DevOps, Docker, Kubernetes, Terraform, Bicep, CloudFormation, SAST, DAST, SCA, OWASP Top 10
    1mo
    Save
    Mark Applied
    Hide
    Lead DevSecOps Engineer
    London, England, United Kingdom
    HybridFull Time
    Arondite
    Arondite: Building software and AI to power autonomous defense systems.
    3+ YOE3+ years building or scaling internal developer platforms/CI/CD ecosystems; cloud-native and container orchestration experience; IaC (Terraform/OpenTofu/Pulumi); scripting (Python/Go/Bash); security/compliance tooling experience.
    Terraform, OpenTofu, Pulumi, Python, Go, Bash, GitLab, Artifactory, SonarQube, OpenTelemetry, Prometheus, ELK, OPA, Kyverno, AWS Config, Istio, Linkerd, EC2, EKS, GitOps, SAST, DAST
    2mo
    Save
    Mark Applied
    Hide
    DevSecOps Engineer
    El Segundo or Los Angeles or Washington or San Francisco or San Diego or Seattle or London
    $110k-$160k/yr OnsiteFull Time
    CHAOS Industries
    CHAOS Industries: Develops advanced radar and sensing systems for modern defense.
    4+ YOERequires active Secret clearance, 4+ years DevOps/DevSecOps experience, proficiency with CI/CD security, cloud (AWS GovCloud/Azure Government), container security, IaC, scripting (Python/Bash/Go), and automated compliance tooling.
    GitHub Actions, GitLab CI, Jenkins, ACAS, Nessus, OPA, Conftest, Docker, Kubernetes, Terraform, CloudFormation, Ansible, Secrets Manager, SonarQube, Checkmarx, Snyk, OWASP ZAP, Black Duck, Gatekeeper, Kyverno, Sigstore, Cosign, Python, Bash, Go, AWS GovCloud, Azure Government
    2mo
    Save
    Mark Applied
    Hide
    DevSecOps Developer
    Osterley, England, United Kingdom
    HybridFull Time
    Sky
    Sky: Provides television, broadband, and mobile telecommunications services.
    Hands-on application security experience, cloud (AWS) knowledge, secure development with Python/JavaScript/PHP, CI/CD security automation, infrastructure-as-code, containerised platforms, observability, and vulnerability triage skills.
    AWS, Python, JavaScript, PHP, CI/CD
    5mo
    Save
    Mark Applied
    Hide
    DevSecOps Engineer (Pipeline Security) - AI
    London or Sheffield
    HybridContract, Full Time
    Deloitte
    Deloitte: Provides global audit, consulting, tax, and advisory services.
    DevSecOps experience with pipeline security, SAST, secrets scanning; CI/CD pipelines; cloud security; scripting.
    Jenkins, GitLab CI, Azure DevOps, SAST tools, HashiCorp Vault, GitGuardian, Claude Code, Python, Bash, AWS, Azure, GCP
    6mo
    Save
    Mark Applied
    Hide
    Senior DevSecOps Engineer
    London, England, United Kingdom
    OnsiteFull Time
    Yapily
    Yapily: Infrastructure for accessing financial data and payments via APIs.
    Senior DevSecOps Engineer responsible for securing infrastructure, automation, cloud (GCP), Kubernetes, IaC, CI/CD guardrails, vulnerability management, and compliance.
    GCP, Kubernetes, Terraform/OpenTofu, CI/CD tooling (GitLab CI, GitHub Actions), Security tooling (Aqua Security, Falco, Prisma Cloud)
    6mo
    Save
    Mark Applied
    Hide
    DevSecOps Engineer
    London, England, United Kingdom
    OnsiteFull Time
    Teya
    Teya: Digital payment and business management tools for small merchants.
    5+ YOE5+ years in security engineering/DevSecOps; CI/CD security (SAST/DAST/SCA); cloud-native AWS; IaC (Terraform); programming (Python/Go/Bash); policy-as-code; cross-functional collaboration.
    GitHub Actions, GitLab CI, Jenkins, Terraform, Python, Go, Bash
    2y
    Save
    Mark Applied
    Hide
    Code Engineer - Security, GCP, Rego Policies - London, UK
    United Kingdom
    OnsiteFull Time
    Photon: A dynamic team specializing in cloud security and software development.
    3+ YOESeeking a skilled DevSecOps Engineer with expertise in GCP, Rego policies, and Terraform.
    GCP, Rego, Terraform, Wiz, Jenkins, GitLab CI/CD