> Markdown version of [/jobs/ext/1286405-security-engineer-iii-infrastructure](https://www.wearedevelopers.com/jobs/ext/1286405-security-engineer-iii-infrastructure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer III - Infrastructure - **Company:** Tesco PLC - **Location:** Welwyn Garden City, UK - **Salary:** £41,600.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Computing Platforms, Microsoft Azure, Cloud Computing, Configuration Management, Linux, OpenShift, Cloud Services, Ansible, Virtual Machines, Policy as Code, Cloud Platform System, Containerization, Tanzu, Kubernetes, Infrastructure Automation Frameworks, Bicep, Virtualization Security, Terraform, Security Orchestration, Automation & Response, Vmware - **Published:** July 16, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=d9d492197ef29cc2 ## About the Role * Infrastructure Security Expertise: Strong hands-on experience securing enterprise infrastructure platforms, including Windows, Linux, VMware, cloud platforms, and hybrid environments. * Virtualisation Security: Experience securing virtual machine environments including platform hardening, configuration management, and workload protection. * Container Security: Deep understanding of container and Kubernetes security principles, including image security, workload isolation, runtime protection, secret management, and cluster hardening. * Infrastructure as Code: Proven experience developing and securing infrastructure using Terraform, Bicep or equivalent IaC technologies. Desirable * Experience with Kubernetes platforms such as AKS, EKS, OpenShift, or Tanzu. * Experience implementing policy-as-code using technologies such as OPA Gatekeeper, Kyverno, Sentinel, or Azure Policy. * Familiarity with supply chain security practices, software bill of materials (SBOM), and artifact security. ## Description The Security Engineer III role focused on Infrastructure Security is responsible for overseeing and shaping security controls across core infrastructure platforms. This role focuses on securing virtual machines, container platforms, infrastructure as code, and desired state configuration technologies across on-premises and cloud environments., The engineer works closely with infrastructure and cloud teams to ensure security is embedded into infrastructure services by design. They act as a senior technical specialist, driving security improvements, reducing risk through automation, and helping establish secure engineering practices. You will be responsible for * Secure Infrastructure Platforms: Implement and maintain security controls for virtual machine platforms, container environments, operating systems, and cloud infrastructure * Infrastructure as Code Security: Develop and maintain security standards, policies, and guardrails for infrastructure delivered through Terraform, Bicep, or similar IaC technologies. * Container & Kubernetes Security: Build and enhance security capabilities across container platforms, including image security, workload protection, runtime controls, admission policies, and Kubernetes hardening. * Desired State Configuration & Platform Hardening: Define and maintain secure configuration baselines for Windows, Linux, containers, and cloud services using technologies such as Ansible or equivalent platforms. * Security Automation: Develop automation and engineering solutions that improve prevention, detection, remediation, compliance validation, and operational efficiency. * Secure Platform Design: Partner with infrastructure and platform engineering teams to provide security guidance, and ensure secure-by-design implementation. ## Related Videos - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [The Private AI Platform: Why Agentic Apps Need a Private Application Platform](https://www.wearedevelopers.com/videos/100162-the-private-ai-platform-why-agentic-apps-need-a-private-application-platform) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)