SC Cleared DevSecOps Engineer - Inside IR35 - Remote

Solirius Limited
London, UK
6 days ago
Apply on www.careerboard.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Kubernetes Security JavaScript (Programming Language) Amazon Web Services Automation of Tests Behavior-Driven Development Cloud Computing Cloud Computing Security Cloud Engineering Code Review Continuous Integration DevOps Github
+22 more
Network Topologies Identity and Access Management Information Systems Security Architecture Professional Python (Programming Language) Software Engineering Systems Integration Software Vulnerability Management Policy as Code Test-Driven Development (TDD) Delivery Pipeline Infrastructure as Code (IaC) Concourse Kubernetes Codebase CIS Benchmarks Terraform Code Restructuring Devsecops Docker Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

We are seeking an experienced DevSecOps Engineer to help secure, build, and optimise our AWS cloud infrastructure and deployment pipelines. In this role, you will bridge the gap between cloud architecture, pipeline automation, and security engineering. You will actively identify and remediate AWS vulnerabilities, design secure architecture, and embed security practices directly into our CI/CD pipelines and development workflows., * CI/CD & Pipeline Security: Build, maintain, and secure automation pipelines using Concourse and GitHub Actions, integrating automated security scanning (SAST/DAST/dependency checks) directly into deployment workflows.

  • Infrastructure as Code (IaC): Design, deploy, and manage scalable cloud infrastructure using Terraform, enforcing security best practices through code reviews and policy-as-code tools.
  • AWS Architecture & Networking: Architect and engineer secure AWS environments, designing robust networking topology (VPCs, transit gateways, security groups, IAM roles, and private endpoints).
  • Vulnerability & CVE Remediation: Proactively identify, assess, and remediate AWS Common Vulnerabilities and Exposures (CVEs) across cloud infrastructure, container environments, and services.
  • Development & Refactoring: Write clean, maintainable automation scripts and microservices using Python and JavaScript, employing Test-Driven Development (TDD) and Behavior-Driven Development (BDD) methodologies.
  • Security Advocacy: Collaborate closely with development and operations teams to champion security-first practices across the software development life cycle (SDLC).

Requirements

You are a motivated and adaptable professional with a strong analytical mindset and a passion for using technology to solve real-world problems. You enjoy working in collaborative, agile teams and take pride in delivering high-quality solutions that make a tangible impact. With strong communication skills and a consultative approach, you’re comfortable engaging with clients, understanding their needs, and translating them into effective outcomes., * Cloud Engineering: Hands-on expertise with AWS services, AWS security features, and secure network design/architecture.

  • Infrastructure as Code: Proficiency with Terraform for provisioning and managing cloud infrastructure.
  • CI/CD Expertise: Proven track record configuring and managing Concourse and GitHub Actions.
  • Development Skills: Professional proficiency in Python and JavaScript for tooling, automation, and refactoring.
  • Testing Practices: Strong experience applying TDD and BDD frameworks to infrastructure and software codebases.
  • Vulnerability Management: Deep understanding of cloud security standards, AWS security tools (eg, Security Hub, GuardDuty, Inspector), and hands-on experience patching/remediating AWS CVEs., * Relevant certifications such as AWS Certified Security - Specialty or AWS Certified DevOps Engineer - Professional.
  • Knowledge of container security (Docker, Kubernetes) and compliance frameworks (CIS benchmarks, ISO 27001, SOC 2).

About the company

Solirius Reply, part of the Reply Group, is a technology consultancy and digital transformation partner that helps organisations solve complex challenges through strategy, design, engineering, and delivery.

We work closely with our clients to deliver secure, accessible, user-focused services that evolve with their needs. By combining deep technical expertise with people-centred design, we create solutions that deliver meaningful, lasting impact.

Our consultants partner directly with client teams, embedding into organisations to understand their goals, challenges, and users. This collaborative approach enables us to deliver tailored solutions that drive measurable outcomes across public and private sectors.

Past and present clients include the Ministry of Justice, Department for Education, Ministry of Housing, Communities and Local Government, UEFA, International Olympic Committee, and Mercedes-Benz. Our services span the full digital delivery life cycle, including architecture, engineering, delivery management, user-centred design, business analysis, data, DevOps, and AI.

We operate as a collaborative and inclusive organisation that empowers our people to take ownership, innovate, and develop their expertise. As an equal opportunities employer, we are committed to encouraging equality, diversity, and social mobility, while creating opportunities for our teams to work on meaningful projects that deliver lasting impact.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:20 min

Integrating security into the DevOps lifecycle

Reto Kaeser · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all