Louis Jackman's CV
Download as a PDF
Louis Jackman
Technology Architect | Engineering & Product Security Manager | Security Expert
Contactable at ljackman@pm.me; London-based, open to hybrid and in-office roles.
I'm an experienced technology strategist, software and infrastructure architect, engineering manager, and information security expert - all refined through a decade of wide-ranging experience, spanning a small B2B startup to a UK-regulated digital bank. I own strategy and roadmaps for technology and security, lead engineering initiatives and manage the teams implementing them, make pragmatic, risk-sensitive strategic technical decisions for the business, and advocate for engineering and security to executive stakeholders.
In recent years, my focus has been scaling up a security engineering function: to adapt to the changing threat landscape posed by AI, to keep pace with a growing product portfolio, and to left-shift security controls closer to product engineering.
I take a product-led approach. That, with my software engineering skills and past Security Operations Centre-responder experience, let me lead in a holistic manner and gives me credibility with engineers and security. I integrate engineering and security considerations across the whole business pipeline: from idea inception, through technical implementation, to delivery of a secure product. I don't consider a product delivered until it's reliably working, in the hands of customers and solving their problems.
Experience
Product Security Manager at Zopa Bank, London
April 2025 - Present
- Leading Product Security Engineering across technology at the organisation. I own strategy, orchestrate control automations, produce executive reports, and run the team. I pivoted the team to a product-led model to scale with our growing product portfolio: less picking up context-free items from a conveyor belt of security tasks, more active product-ownership by security engineers.
- Advocating for Product Security Engineering across the business, getting buy-in across the board: performing company-wide talks, allaying concerns about controls directly with leadership teams, and proactively defining new security strategies and justifying their wider business value.
- Overseeing an overhaul of the team's controls and working model to adapt to industry changes posed by AI. I advised on controls for initial AI harness and model adoption by the business, and personally implemented a suite of AI skills and their knowledge base dependencies: to accelerate threat modelling, security assessments, threat investigations, and patching. I have ongoing exploration of guardrailed, safe "autonomous red-team AI agents" for continual product security coverage.
- Took ownership of the business-wide tracking of product security patching, across a vast set of microservices. Handled initial patching ownership nomination, refinement of the metrics for executive reports, and applying pressure for strategic improvements where patching work could be deduplicated across product teams.
- Leading a team: hiring full-time roles, managing contractors, driving sprint plans, balancing team workload allocation, and making difficult personnel decisions.
Application Security Manager at Zopa Bank, London
September 2022 - April 2025
- Identified strategic gaps in company-wide AppSec security engineering and controls, prioritised their implementation, and drove vendor selection and subsequent relationship management - where third parties were appropriate for a solution.
- Formalised team metrics and objectives to enable higher-level visibility of the team's output; explicitly acknowledged "metrics gaming" issues (i.e. Goodhart's Law), steering around such pitfalls.
- Made strategic security decisions for the business: defined initial high-level security architecture for a source control migration, pushed for accepting appropriately secured cloud tenancy for some third-party security products, and reduced organisational attack surface by creating new Distroless-based locked-down, ultra-minimal product container images.
Application Security Lead at Zopa Bank, London
March 2021 - September 2022
- Took lead in a new Application Security team, when InfoSec became specialised into sub-teams. Adopted more of an advisory, architecture, and peer-reviewing role.
- Orchestrated and headed up numerous internal interviews for internal audits and industry benchmarking. Collated evidence for said audits and allayed auditors' concerns as their point of contact - all to befit a company with a newly minted banking licence.
- Personally rearchitected our "edge security" (e.g. geoblocking, WAFs, and rate-limiting).
- Established engineering security standards and developer-facing guidance where it was missing, and performed tech-wide demos to justify further defence in depth - and to sell why security is everyone's concern rather than an isolated company function.
Security Engineer at Zopa Bank, London
August 2019 - March 2021
- Founded the company's internal Secure Development Lifecycle tool: an automated engineer questionnaire about new services and features, and a subsequent, formalised review process for threat modelling, whitebox code assessments, penetration tests, and eventual approval.
- Performed internal pentests and coordinated with third-party assessors for external ones. Produced threat models, and set up security architecture catch-ups with engineers when necessary.
- Handled security alerts in a SOC: triage, prioritisation, validation, and remediation. Fine-tuned alerts and their response playbooks when I identified inefficiencies.
Security Engineer at Qudini, London
July 2017 - August 2019
- Transitioned to a more security-focused technical role in response to the startup's growth.
- Co-authored an ISMS to achieve ISO/IEC 27001, passing an audit by BSI.
DevOps Engineer at Qudini, London
September 2016 - July 2017
- Provisioned whole new AWS environments for clients wanting dedicated tenancy.
- Created an Akka actor-based internal tool for scaling up transient, disposable test versions of our product for internal testing.
- Rolled out a cloud-based DAST for the company.
- Spear-headed a migration of a legacy Angular 1.x codebase to React, overcoming severe technical hurdles that were seen as blockers for past attempts.
Junior DevOps Engineer at Qudini, London
September 2015 - September 2016
- "DevOps" on paper, but a hybrid of DevOps and software engineering in practice: new product features in Java, deployment scripting in Python, and infrastructure definitions as early adopters of Terraform and of AWS.
- The business previously deployed manually from engineer laptops to hard-coded IPs of fixed server sets. I automated such deployments in a CI pipeline, targeting new auto-scaling sets of transient VMs.