Overview
In this role you will design, build and operate a Kubernetes-based platform for autonomous vulnerability research at scale, enabling secure, auditable AI-powered workloads. You will own IaC across GCP, implement hardened container/VM images, and enforce strict egress and segmentation to ensure safe research. You’ll collaborate with AI Engineering and Security Architecture to demonstrate control effectiveness, while accelerating researcher velocity within a security-first culture. This is a hands-on, platform-building role that drives secure, scalable research capabilities at Lloyds Banking Group.
Pay / Benefits
- up to 15% pension contribution
- annual performance-related bonus
- share schemes including free shares
- discounted shopping
- 30 days’ holiday plus bank holidays
- wellbeing initiatives and parental leave policies
Responsibilities
- Design, build, and operate the Kubernetes-based platform hosting agentic research workloads
- Own infrastructure-as-code across GCP using Terraform for reproducible environments
- Engineer secure container/VM images with hardened baselines and automated patching
- Implement egress-controlled networking, network policy, and segmentation for sanctioned targets
- Build CI/CD pipelines with integrated supply-chain security, including SBOMs and image signing
- Deliver observability across logs, metrics, traces, and cost telemetry for long-running workloads
- Create evidence-capture pipelines with immutable audit trails and run records
- Manage secrets, identity, and workload authentication with least-privilege access
- Collaborate with AI Engineering and Security Architecture to ensure safe, scalable runtimes
Key requirements
- Deep, hands-on Kubernetes experience (workload design, networking, autoscaling, RBAC, multi-tenancy)
- Strong Terraform and IaC skills with production cloud estates experience
- Substantial GCP experience (GKE, IAM, VPC/networking, Cloud Build/Artifact Registry) or equivalent cloud depth
- Container and VM hardening, including image minimisation and vulnerability management
- Experience implementing egress control, network policy, and segmentation in cloud-native environments
- Strong CI/CD engineering with security controls embedded into delivery pipelines
- Observability expertise across logging, tracing, and metrics with auditability
- Security-first mindset balancing researcher velocity with containment requirements
- Knowledge of artefact provenance and secure software supply chains
- Ability to operate in highly regulated environments or similar contexts
- extra_optional_candidates_badge: true
- Security-minded decision making
- Collaborative, cross-functional teaming
- Judgement to balance speed with control
- Kubernetes
- Terraform
- GCP (GKE, IAM, VPC, Cloud Build, Artifact Registry)
…
