> Markdown version of [/jobs/ext/3315989-security-engineer-devsecops](https://www.wearedevelopers.com/jobs/ext/3315989-security-engineer-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer (DevSecOps) - **Company:** Sanderson Recruitment Plc - **Location:** London, UK - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Bash Shell, Code Review, CompTIA Security+, Continuous Integration, DevOps, Identity and Access Management, Internet Security, Python (Programming Language), Software Engineering, Software Vulnerability Management, Istio, Kubernetes, Terraform, Devsecops, Static Application Security Testing, Vulnerability Analysis - **Published:** September 22, 2026 - **Apply:** https://www.totaljobs.com/job/security-engineer/sanderson-recruitment-job108013607 ## About the Role * Hands-on experience in software engineering, DevOps or platform engineering with a strong security focus, or in security engineering. * Experience with CI/CD and security scanning tools (SAST, SCA, secrets, IaC and container scanning). * Python or Bash and Terraform. * AWS fundamentals including IAM, plus working knowledge of containers and Kubernetes. * A good grasp of vulnerability management, including CVSS, EPSS and judging whether an issue is really exploitable. * Clear written communication and comfortable switching between teams. Nice to have * A security certification such as AWS Certified Security - CKS, CompTIA Security+, GIAC or CISSP. * Exposure to policy-as-code or Istio. * Experience in a regulated environment. * An interest in AI security. ## Description This is a hands-on engineering role focused on building security into software as developed and deployed. You'll work across three workstreams alongside three Senior DevSecOps Engineers. You'll pick up work where it's most needed, keep security consistent across all three workstreams and make sure nothing falls between them. It suits a software, DevOps or platform engineer who has already built security into their day-to-day work and wants to take it further. You'll get exposure to platform, AI and integration security. What you'll do * Set up and tune security scanning in CI/CD pipelines, cut down false positives and help developers fix real issues. * Build shared security modules, policy libraries and templates that all three teams can reuse. * Review code, infrastructure-as-code and configuration changes for security issues. * Handle day-to-day vulnerability management, including pen test findings: prioritise what's genuinely exploitable, track fixes and check they've worked. * Help run threat modelling sessions in IriusRisk and turn the results into backlog tickets. * Look after secrets management, certificates and access reviews and keep security documentation, control evidence and CAB records up to date. * Be the go-to person when security is blocking a delivery team, cover for the senior engineers when priorities shift and flag where teams are solving the same problem in different ways. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Shifting Stress to Progress— Understanding DevOps to do DevOps Better](https://www.wearedevelopers.com/videos/268-shifting-stress-to-progress-understanding-devops-to-do-devops-better) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)