Tech Lead (DevSecOps)
Engineering at Blinq
We're hiring a Tech Lead / DevSecOps Engineer, a security-first engineer who is also a strong backend engineer in our Node.js / TypeScript stack.
You'll set the technical direction for how we build securely, harden our cloud environment, own our security incident detection and response, and lead the work that takes our security posture (and compliance) to the next level. This is a high-trust, high-autonomy role with room to shape how security and infrastructure work as we scale.
What you'll do
Lead design and delivery across our Node.js / TypeScript backend and platform, balancing security and platform work with the product-adjacent building that keeps us shipping
Own and harden our GCP, Cloudflare, and Firebase infrastructure - IAM, networking, secrets management, and infrastructure-as-code (Pulumi TypeScript & Terraform)
Embed security into the SDLC: threat modeling, secure code review, and CI/CD security guardrails (SAST/DAST, dependency scanning)
Run vulnerability management end to end - triage, remediation, coordinating external penetration tests, and enhance our vulnerability disclosure programme
Own detection, logging, and incident response, including endpoint detection & response (EDR) and security monitoring in Datadog
Lead anti-phishing, spam, and platform-abuse detection and prevention
Drive identity and access governance - SSO, OAuth, and IAM audits and improvements
Drive our SOC 2 / ISO 27001 and privacy (GDPR) efforts, turning compliance requirements into pragmatic engineering controls
Set technical standards and mentor engineers, raising the bar for how the whole team builds and ships securely
What you'll bring
Tech Lead–level experience as a strong backend engineer with a security focus, ideally in Node.js / TypeScript
Solid application/product security fundamentals - OWASP, secure design, code review, API security
Hands-on cloud experience (GCP ideal; Cloudflare/Firebase a plus) and infrastructure-as-code (Pulumi in TypeScript; Terraform or similar experience translates well)
Detection & response depth - EDR, security monitoring / SIEM, and incident response. Hands-on experience with Datadog is highly desirable.
Familiarity with security tooling (SAST/DAST, Snyk/Dependabot/Renovate, secrets scanning, secrets management) and vulnerability management
Identity / auth depth - OAuth, SSO, and end-user authentication
Exposure to SOC 2, ISO 27001, or GDPR/privacy in a SaaS environment. Compliance automation (e.g. Vanta) a plus
A pragmatic, build-first mindset - comfortable owning ambiguity and setting direction in a scaling startup
Strong communication and the ability to lead and mentor without heavy process
Nice to have
Prior experience as an early or first security hire at a startup
DevSecOps / CI-CD security tooling and automation
Detection & incident response experience
Identity/auth depth (OAuth, SSO)
Endpoint security / MDM exposure (e.g. Iru)
What you get
Equity and ownership. We're building something massive and we want you to share in the upside. Genuinely.
Competitive salary and a real growth path. As Blinq grows, your role and compensation grow with it.
Time to switch off. 20 days of annual leave plus a flexible policy for everything life throws at you beyond that.
Good times, often. Team lunches, padel, games nights, Barry's sessions. We like hanging out and it shows.
Regular catered lunch at some of our offices, plus an always-stocked snack bar.
J-18808-Ljbffr