Security Platform Engineer (DevSecOps) - SC (MOD/Defence)

The Talent Locker
Aldershot, United Kingdom
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Compensation
£ 75K

Job location

Aldershot, United Kingdom

Tech stack

Kubernetes Security
DevOps
Intrusion Detection and Prevention
Security Information and Event Management
Software Vulnerability Management
Data Logging
Scripting (Bash/Python/Go/Ruby)
Mitre Att&ck
Kubernetes
Nessus
Splunk
Devsecops

Job description

Kubernetes, Splunk, Nessus. You'll own the security tooling across a live platform, not just monitor it.

Working for a defence consultancy providing technical solutions to the MOD and Defence sectors, you will be working across a Kubernetes platform, responsible for deploying, running and improving the tools that provide visibility, detection and control. This is hands on and sits right between platform engineering and security, with a big focus on getting security embedded properly into how things are built and run.

You'll spend your time securing Kubernetes environments, running and tuning Splunk for logging and threat detection, and managing Nessus to track and drive vulnerability remediation. A big part of the role is integrating security into CI/CD pipelines and automating as much as possible, whether that's through scripting or infrastructure as code.

You'll also be working closely with DevOps and engineering teams to make sure security is part of the process, not something that gets added later. Alongside that, you'll keep configurations, artefacts and documentation in good shape and treated as code.

Requirements

Prior experience as a Security Engineer or Platform Engineer type role, with strong Kubernetes knowledge and experience in tools like Splunk and Nessus. You'll understand container security, have some scripting or automation capability, and be comfortable working with security frameworks . Awareness of threat frameworks like ATT&CK is useful.

It would help if you've worked with other SIEM tools, Microsoft Defender or DevSecOps pipelines, and any exposure to threat modelling or security design.

If you want a role where you're actually building and running the security layer across a Kubernetes platform, rather than just watching dashboards, this gives you that ownership from day one.

Apply for this position