Light (light.inc) Logo

Light (light.inc)

DevSecOps Lead

Posted 13 Days Ago
Be an Early Applicant
In-Office
London, Greater London, England
Senior level
In-Office
London, Greater London, England
Senior level
As DevSecOps Lead, you will manage security across the engineering infrastructure, implement compliance programs, and work closely with engineering teams on security practices.
The summary above was generated by AI

About Light.
Light exists to replace factory-era ERPs with software that feels alive. Our Smart Financial Platform gives modern, global companies superpowers—automated accounting, real-time reporting, and financial flows that move at the speed of the business.
We build with our customers, ship fast, and obsess over craft. In a short time, Light has gone from idea to the operating core for leading companies like Lovable, Legora, and Keyshot. People don’t just use Light—they enjoy it.
We’re an early team defining a new software category. Think engineers who love debits and credits, designers who care about reconciliation states, and operators who treat finance as a product. If you’re excited to modernize how the world runs money—one workflow at a time—you’re in the right place.
Backed by world-class investors and advised by industry titans, we’re building category-defining products with the freedom to ship ambitiously and own outcomes.
Come help us make Light the global default for next-gen finance.


The DevSecOps Lead role

As DevSecOps Lead, you'll own security across Light's engineering infrastructure and development lifecycle. You'll establish the security controls and compliance posture that enterprise fintech customers require, whilst embedding security practices that scale with our rapidly growing engineering team.

This is a hands-on technical role with strategic scope. You'll split your time between infrastructure security engineering (Terraform, AWS security services, CI/CD hardening), compliance programme execution (SOC 2, GDPR, ISO 27001), and partnering with engineering teams to build security into their workflows from the start.

Our environment:

  • AWS infrastructure (EKS,, RDS PostgreSQL, Lambda, ECR, S3, SES, Bedrock for AI/LCI)

  • Kotlin backend with Gradle, Next.js frontend with TypeScript

  • GitHub Actions CI/CD, Tanka/Jsonnet for Kubernetes, Terraform for infrastructure

  • Datadog and CloudWatch for observability, SOPS and AWS Secrets Manager for secrets

  • 25 engineers scaling to 50+, distributed across 15+ countries

What you'll own:

You'll design and implement security controls across our AWS environment, harden our EKS cluster security, and secure our CI/CD pipelines. You'll establish security controls for our AI workflows, including Bedrock integrations, prompt validation, and model access governance. You'll lead our SOC 2 Type II compliance programme, establish security policies for GDPR and ISO 27001, and implement automated compliance monitoring. Day-to-day, you'll write Terraform, review architecture designs, triage security alerts, build security into development workflows, coordinate penetration testing, and partner with engineering on threat modelling and secure development practices.

You'll also respond to customer security questionnaires, document controls for auditors, establish incident response procedures, and work with our Head of Engineering on security roadmap and priorities.


How you fit into the team:

You combine deep technical knowledge with strategic judgment, knowing how to balance real-world risks with business speed. You're hands-on when needed, but equally capable of driving policy, compliance programmes, and long-term security maturity. You've led security in high-growth environments before — and you're ready to do it again, with impact.

Your qualifications:

  • 5-7 years' experience in security engineering roles, preferably in fintech, SaaS or payments

  • Proven experience owning infrastructure and cloud security in a fast-moving environment

  • Deep technical expertise: AWS (VPC, IAM, EKS, Lambda, RDS), Kubernetes, Terraform/IaC

  • Hands-on experience with vulnerability management, penetration test oversight, secure CI/CD, container security

  • Familiarity with compliance frameworks: SOC 2, ISO 27001, GDPR

  • Excellent risk judgment and ability to balance security requirements with business velocity

  • Strong communication skills — able to influence engineers and explain security to non-technical stakeholders


Bonus points:

  • Prior experience in fintech / financial software / payments

  • Certifications such as AWS Security Specialty, CISSP, CKS, OSCP, or equivalent

  • Experience with compliance automation platforms (Vanta, Drata, Secureframe)

  • Background in software engineering or prior development experience


A few tips to stand out

  • Show how you’ve balanced speed and security in a high-growth environment

  • Demonstrate how you’ve influenced culture — not just control

  • Share how you’ve measured and communicated risk, coverage, and progress

  • Walk us through your past playbooks or roadmaps — and how they evolved

  • Bonus if you can articulate the “why” behind the trade-offs you’ve made

The good stuff

In addition to being part of a great team and working in a really fun and innovative environment, we offer:

💸 Competitive salary + potential stock options
🍼 Paid parental leave
🏝 25 days of annual leave + public holidays (in your country)
🥳 Regular socials and company off-sites.
🚀 A huge opportunity to shape a market-defining product and engineering culture


The famous last words

At Light, we’re building the most trusted financial platform in the world — and trust starts with security. As our InfoSec & Cybersecurity Lead, you’ll help us earn that trust every day.

Join the rocket ship while it’s taking off 🚀

Top Skills

AWS
Ci/Cd
Cloudwatch
Datadog
Gdpr
Github Actions
Iso 27001
Kotlin
Kubernetes
Soc 2
Terraform
Typescript

Light (light.inc) London, England Office

Rathbone Street, London, United Kingdom

Similar Jobs

8 Days Ago
In-Office
City of London, London, England, GBR
Senior level
Senior level
Fintech • Payments • Software • Financial Services
The AppSec/DevSecOps Lead will embed secure development practices, manage application security tools, and promote collaboration on secure coding across teams.
Top Skills: AWSAzureCi/CdDastPowershellPythonSastSca
11 Minutes Ago
Hybrid
London, Greater London, England, GBR
Mid level
Mid level
Big Data • Cloud • Food • Machine Learning • Software • Database • Analytics
The Strategy Manager will develop and implement UKI strategies, support senior stakeholders with clear recommendations, and lead cross-functional projects focused on growth priorities.
15 Minutes Ago
Remote or Hybrid
Staines, Surrey, England, GBR
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
As a Senior Advisory Solution Consultant, you'll support global partnerships, offering pre-sales support, technical advice, and building relationships with partners to enhance ServiceNow's value propositions and delivery.
Top Skills: AICloud ComputingModern Web TechnologiesServicenow

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account