Louis Jackman's CV
Download as a PDF
Louis Jackman
Product Security Manager | Engineering Manager | Information Security Lead
I'm an experienced, UK-based technology strategist, information security expert, manager, and engineer - all refined through a decade of experience, spanning a small B2B startup to a UK-regulated digital bank. I build and lead security engineering teams, own security strategies and roadmaps, make risk-sensitive decisions through a pragmatic lens, and advocate for security and engineering to executive stakeholders.
In recent years, my focus has been scaling up a security function: to keep pace with a growing product portfolio, to left-shift security controls closer to product engineering, and to adapt to the changing threat landscape posed by AI.
My product-led approach - and past software engineering and SOC-responder experience - let me lead a security function in a holistic manner. I integrate security and risk considerations across the whole business pipeline: from idea inception, through technical implementation, to delivery of a secure product. My technical background gives me credibility with engineers, and my past SOC experience helps me make security solutions amenable to both proactive and reactive controls. As well as security assurance, for me, secure delivery also means enabling the release of something that just works - into the hands of our customers.
Experience
Product Security Manager at Zopa Bank, London
April 2025 - Present
- Leading Product Security across the engineering organisation. I own strategy, run the team, and produce executive reports. I pivoted the team to a product-led model to scale with our growing product portfolio: less picking up context-free items from a conveyor belt of security tasks, more active product-ownership by security engineers.
- Advocating for Product Security across the business, getting buy-in across the board: performing company-wide talks, allaying concerns about controls directly with leadership teams, and proactively defining new security strategies and justifying their wider business value.
- Overseeing an overhaul of the team's controls and working model to adapt to industry changes posed by AI. I advised on controls for initial AI harness and model adoption by the business, and personally implemented a suite of AI skills and their knowledge base dependencies, to accelerate threat modelling, security assessments, threat investigations, and patching. I have ongoing exploration of guardrailed, safe "autonomous red-team AI agents" for continual product security coverage.
- Managing a team: hiring full-time roles, managing contractors, driving sprint plans, balancing team workload allocation, and making personnel decisions.
- Took ownership of the business-wide tracking of product security patching, across a vast set of microservices. Handled initial patching ownership nomination, refinement of the metrics for executive reports, and applying pressure for strategic improvements where patching work could be deduplicated across product teams.
Application Security Manager at Zopa Bank, London
September 2022 - April 2025
- Identified strategic gaps in company-wide AppSec security controls, prioritised their implementation, and drove vendor selection and subsequent relationship management - where third parties were appropriate for a solution.
- Formalised team metrics and objectives to enable higher-level visibility of the team's output; explicitly acknowledged "metrics gaming" issues (i.e. Goodhart's Law), steering around such pitfalls.
- Made strategic security decisions for the business: defined initial high-level security architecture for a source control migration, pushed for accepting appropriately secured cloud tenancy for some third-party security products, and reduced organisational attack surface by creating new standards for locked-down, ultra-minimal product container images.
Application Security Lead at Zopa Bank, London
March 2021 - September 2022
- Took lead in a new Application Security team, when InfoSec became specialised into sub-teams. Adopted more of an advisory, architecture, and peer-reviewing role.
- Orchestrated and headed up numerous internal interviews for internal audits and industry benchmarking. Collated evidence for said audits and allayed auditors' concerns as their point of contact - all to befit a company with a newly minted banking licence.
- Personally rearchitected our "edge security" (e.g. geoblocking, WAFs, and rate-limiting).
- Established engineering security standards and developer-facing guidance where it was missing, and performed tech-wide demos to justify further defence in depth - and to sell why security is everyone's concern rather than an isolated company function.
Security Engineer at Zopa Bank, London
August 2019 - March 2021
- Founded the company's internal Secure Development Lifecycle tool: an automated engineer questionnaire about new services and features, and a subsequent, formalised review process for threat modelling, whitebox code assessments, penetration tests, and eventual approval.
- Performed internal pentests and coordinated with third-party assessors for external ones. Produced threat models, and set up security architecture catch-ups with engineers when necessary.
- Handled security alerts in a SOC: triage, prioritisation, validation, and remediation. Fine-tuned alerts and their response playbooks when I identified inefficiencies.
Security Engineer at Qudini, London
2017 - 2019
- Transitioned to a more security-focused technical role in response to the startup's growth.
- Co-authored an ISMS to achieve ISO/IEC 27001, passing an audit by BSI.
DevOps Engineer at Qudini, London
2015 - 2019
- "DevOps" on paper, but a hybrid of DevOps and software engineering in practice: new backend features in Java, scripting in Python, infrastructure definitions as early adopters of Terraform and of AWS, and more.
- The business previously deployed manually from engineer laptops to hard-coded IPs of fixed server sets. I automated such deployments in a CI pipeline, targeting new auto-scaling sets of transient VMs.
- Provisioned whole new AWS environments for clients wanting dedicated tenancy.