This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a DevSecOps Architect to join our Information Security team. In this role, you will be a collaborative and strategic partner to our engineering teams, helping design the automation that enables us to ship secure code at velocity. You will advocate for a 'Security by Design' culture, ensuring that robust security practices are seamlessly integrated into the fabric of our product development processes. Your goal is to architect and build a frictionless security environment where the secure path is the easiest path for our developers.
Job Responsibility:
Architect Automated Security Pipelines: Partner with the Platform team to design and implement advanced automated security controls (SAST, DAST, SCA) within our CI/CD pipelines, providing engineers with rapid, high-fidelity feedback
Infrastructure and Policy as Code: You will guide the security architecture for our AWS environment by treating infrastructure as software enabling secure and scalable deployments and ensure automated compliance
Threat Detection Engineering: Engineer advanced threat detection capabilities by integrating platform logs and event data (including RabbitMQ) into our SIEM (Google Security Operations). You will develop and tune YARA-L rules to proactively identify and respond to threats
Collaborative Design and Threat Modelling: Partner with engineering squads during the design phase of new features, facilitating collaborative threat modelling sessions to build security in from the start
Developer Enablement: Create feedback loops that deliver security insights directly into developer workflows (e.g., automated PR comments), enabling teams to self-remediate and learn continuously
Infrastructure as Code: Experience securing Terraform codebases and building secure modules for other teams to use
CI/CD Orchestration: Experience with modern pipelines (e.g., CircleCI, GitHub Actions, or GitLab) and integrating security steps
Automation Engineering: Ability to write script and code (e.g., Python, Typescript) to build integrations and tooling
Modern Detection Engineering: An interest in or experience with modern detection engineering (e.g., Google Chronicle, YARA-L, or similar SIEM tools)
Architecture Patterns: Familiarity with securing API-first and Event-Driven Architectures
Incident Response and Operations: Participate in the team's on-call rotation, including out-of-hours coverage to support platform availability and security
Ambiguity: You thrive in ambiguous and fast-changing environments, and know how to make progress even when requirements are evolving
Nice to have:
Experience with automated policy enforcement
Familiarity with functional programming concepts or Elixir (our core backend language)
Familiarity with securing AI/ML pipelines or services
A pragmatic approach: You focus on high-impact security wins that support business agility rather than 'security for security's sake.'
Certifications like CISSP, CISM, or AWS Security are a bonus
What we offer:
Time off - 27 days holiday, plus 5 additional days off: 1 life event day, 2 volunteer days, 2 company-wide wellbeing days (M-Powered Weekend) and 8 bank holidays per year
Health & Wellness- private medical Insurance with Bupa, a medical cashback scheme, life insurance, gym membership & wellness resources through Wellhub and access to Spill - all in one mental health support
Hybrid work offering - for most roles we collaborate in the office three days per week with the exception of Coaches and Instructors who collaborate in the office once a month
Work-from-anywhere scheme - you'll have the opportunity to work from anywhere, up to 10 days per year
Space to connect: Beyond the desk, we make time for weekly catch-ups, seasonal celebrations, and have a kitchen that’s always stocked!