DevSecOps Security Engineer

Adecco
Cambridge, United Kingdom
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Compensation
£ 100K

Job location

Cambridge, United Kingdom

Tech stack

Kubernetes Security
Amazon Web Services (AWS)
Azure
Bash
Cloud Computing
Cloud Computing Security
Static Program Analysis
Software Quality
CompTIA Security+
Computer Security
Continuous Integration
DevOps
Dynamic Program Analysis
Identity and Access Management
Intrusion Detection and Prevention
Python
Key Management
Open Source Technology
Role-Based Access Control
Zero Trust Network Access
Software Vulnerability Management
Policy as Code
Data Logging
Scripting (Bash/Python/Go/Ruby)
Google Cloud Platform
Cloud Platform System
Cloud Monitoring
Software Security
Cloudformation
Kubernetes
Infrastructure Automation Frameworks
Terraform
Devsecops
Security Orchestration, Automation & Response
Vulnerability Analysis

Job description

We are seeking a DevSecOps Security Engineer to help elevate security across cloud platforms, delivery tooling, and production environments. You'll play a central role in embedding modern defensive practices, advancing automation, and strengthening engineering resilience across the organisation.

This position requires being on-site in Cambridge three days per week, so applicants should be comfortable with a regular hybrid working pattern.

Platform Security & Automation

  • Introduce protective validation steps throughout software delivery workflows, covering code quality, open-source components, and container images.

  • Engineer automated mechanisms that streamline compliance reporting and reduce operational overhead.

  • Enforce policy-driven safeguards within infrastructure deployment processes.

  • Improve credential management approaches and mature access governance practices. Exposure Management & Technical Controls

  • Assist in reviewing weaknesses across applications and infrastructure and support risk-based prioritisation.

  • Partner with engineering teams to resolve issues efficiently and pragmatically.

  • Refine detection tooling by tuning logic and reducing unnecessary or inaccurate alerts. Operational Readiness & Observability

  • Strengthen visibility across systems through improved log pipelines, alerting pathways, and monitoring strategies.

  • Contribute to updating response guidelines, runbooks, and incident-handling materials.

  • Support initiatives aimed at enhancing defensive posture and operational robustness across platforms. Core Requirements

Requirements

  • Strong experience in DevSecOps, cloud security, or infrastructure security functions.

  • Hands-on knowledge of modern CI/CD pipelines and automation tooling.

  • Proven background securing AWS environments (Azure or GCP is also valuable).

  • Practical experience with security scanning, vulnerability tooling, and tuning to improve accuracy.

  • Proficiency in automation or scripting languages such as Python or Bash.

  • Experience delivering infrastructure through IaC tooling such as Terraform or CloudFormation. Preferred Background & Additional Capabilities

  • Knowledge of securing containerised environments and orchestration platforms.

  • Experience working within assurance-focused frameworks including ISO 27001, SOC 2, or NIST.

  • Familiarity with automated governance and policy-driven cloud controls.

  • Exposure to investigative, detection, or security operations workflows. Qualifications That Would Be Beneficial

  • Industry security certifications such as CISSP, CISM, CCSP, or GSEC.

  • Cloud-focused qualifications like AWS Security Specialty, AWS Solutions Architect, Azure Security Engineer Associate, or Google Professional Cloud Security Engineer.

  • DevOps and automation-related certifications such as Terraform Associate, CKA/CKAD, or Kubernetes Security Specialist (CKS).

  • Compliance and governance accreditations including ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, or NIST-aligned training.

  • Relevant computing or cybersecurity degree (BSc/MSc) or equivalent practical experience.

Keywords

DevSecOps, Cloud Security, AWS, Azure, GCP, CI/CD, Secure Software Delivery, Static Analysis, Dynamic Analysis, Dependency Scanning, Container Security, Kubernetes Security, Infrastructure as Code, Terraform, CloudFormation, Pipeline Security, Cloud Governance, Policy as Code, Secrets Management, Identity and Access Management, Vulnerability Remediation, Threat Detection, Observability, Logging, Automation Engineering, Python, Bash, Zero Trust, Security Hardening, Cloud Monitoring, Least Privilege, Compliance Automation, Security Orchestration

About the company

A rare opportunity to join one of Cambridge's leading AI innovators, a business shaping the future of intelligent automation and rapidly outpacing its competitors. This is a chance to be part of a high-growth technical environment where engineering excellence and security maturity sit at the heart of the organisation's ambitions., Adecco is acting as an Employment Agency. We are proud to be an equal opportunities employer. We are on the client's supplier list for this role.

Apply for this position