Monument Technology
Senior DevSecOps Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role: Senior DevSecOps Engineer
Location: London (Oxford Circus)
Hybrid: 1-2 days per week in the office
About Monument Technology Limited
Monument Technology provides everything needed to build and run a bank with an open, configurable, end-to-end banking platform as a service which uses best-in-class components to empower small and medium-sized banks around the world to thrive in the digital age. Monument Technology takes the proven, end to end platform developed for Monument Bank, the leading bank for the mass affluent, and makes it available to financial institutions in the UK and globally as a licensed Banking Platform as a Service.
Our platform is a full-stack ‘bank or building-society-in-a-box’, delivering all the functionality needed to run and grow a modern, digital-led financial institution, including native mobile app and web experience, servicing, core and all the back-end technologies, integrated in a single, cloud-native solution (“Bank-in-a-Box”).
Monument Technology provides everything in one solution, taking care of all third-party contracts and integrations as well as ongoing maintenance and future platform enhancements - all for one annual licence fee, allowing our customers to embrace the most modern technology available, without any of the complexity.
THE ROLE
We’re looking for a hands-on Senior DevSecOps Engineer to own the security engineering and DevSecOps quality of our AWS estate. Because Monument Technology sells a banking platform to other banks, our security posture is a commercial precondition, not simply an internal control. This role exists to make security engineering an automated, evidenced property of the platform rather than a manual, person-dependent activity.
You’ll design and enhance our AWS architecture with a view to extending it across multiple cloud providers, configure and tune AWS and third-party security tooling, and lead AWS security projects end to end. You’ll provide security expertise to the delivery teams, review and make recommendations on AWS changes, releases and new functionality, and drive continuous improvement of our security position through automated scanning and monitoring.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Just as important is the influencing side of the role: working collaboratively with onshore and offshore Scrum teams to champion good DevSecOps and security engineering practice, and working with our managed Security Operations Centre (SOC), security product and penetration testing providers. There are no direct reports at the moment, though this may change as the company expands.
HOW YOU’LL MAKE AN IMPACT
- Own the security engineering and DevSecOps quality of the AWS estate, taking day-to-day ownership of AWS security tooling including GuardDuty, Security Hub, WAF and CloudTrail.
- Design and enhance the AWS architecture with a view to extending it across multiple cloud providers, leading AWS security projects end to end.
- Express controls in code and continuously monitor the security position, driving a measurable reduction in the open security findings backlog through automated scanning and monitoring.
- Embed security review as a standard step in the change and release process, and tighten pipeline gates with integrated code quality and security tooling such as SonarCloud.
- Provide security expertise to delivery teams, reviewing and making recommendations on AWS changes, releases and new functionality.
- Champion good DevSecOps practice across onshore and offshore Scrum teams by making the secure path the easy path, using paved roads, templates and automated gates over mandates.
- Work with the managed Security Operations Centre (SOC), security product vendors and penetration testing providers to strengthen the platform’s security assurance.
- Take ownership of Monument Technology environments and communicate with the team and external clients about environment activities and client-facing security assurance.
- Contribute credibly to extending the platform to a second cloud provider, becoming the recognised technical authority on cloud security and DevOps for the platform.
WE LOOK FOR PEOPLE WITH
- Hands-on AWS engineering in a multi-account AWS Organisation is essential, including EC2, EKS, S3, EFS, RDS, DynamoDB, ElastiCache, API Gateway, Lambda, WAF, CloudFormation and Control Tower.
- Cloud security engineering experience securing AWS environments using WAF, GuardDuty, Security Hub, Shield, CloudTrail, CloudWatch, X-Ray, KMS, Secrets Manager and Cognito.
- Infrastructure as Code fluency with Terraform and CloudFormation, writing modules from scratch and having migrated an existing estate into code.
- Strong Kubernetes configuration and troubleshooting across Dockerfiles, manifests and Helm charts, supporting a microservice architecture on EKS.
- DevSecOps tooling and CI/CD experience with Jenkins, GitHub Actions, ArgoCD and Bitbucket Pipelines, with code quality and security gates integrated.
- Scripting and automation in Bash and/or Python, and comfort delivering in an agile environment alongside Product Owners and engineering teams.
- Financial services or comparable regulated-sector experience operating secure, resilient and performant cloud-hosted platform services, with the credibility to champion good practice with onshore and offshore Scrum teams.
- Desirable: equivalent depth in a second public cloud (Azure or GCP); Microsoft 365 and Active Directory security engineering; experience building reusable module libraries or landing zones; relevant Kubernetes certification; observability tooling such as Prometheus, Grafana or Coralogix; and experience supporting a SaaS or BaaS platform serving external bank clients.
- There is no formal degree requirement; AWS Security Specialty, CKA/CKS or equivalent certifications are a plus rather than a filter.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
OUR CULTURE AND VALUES
Our culture and values align with our mission to truly understand and offer exceptional service to our clients.
The Monument Technology team is passionate about building more than a bank and more than a technology platform. We are driven to create solutions that respect our clients’ time, complexity and ambition.
We are guided by integrity, attentiveness, a sense of community and innovation. We build trusted relationships through collaboration, attention to detail and a commitment to continuous improvement. Through inclusive thinking and purposeful innovation, we enable our clients and colleagues to achieve more.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location