Graduate DevSecOps / DevOps Engineer
Role details
Job location
Tech stack
Requirements
Applicants must be a UK national with no other nationality and be able to receive and hold SC government security clearance.
DevSecOps Engineer
Manage and support Morton's development team and training estate.
Required - Essential experience
-
Containers: Containerised software delivery using platforms such as Kubernetes or OpenShift (YAML, etc.).
-
CI/CD: Building and maintaining CI/CD pipelines with automated testing, security scanning, dependency checking, and controlled deployment.
-
Cloud: Ability to manage deployments into constrained enterprise or government cloud hosting environments.
-
Control: Logging, monitoring, patching, rollback, and operational support of live systems.
-
Security: Understanding of secure-by-design principles, including secrets handling, TLS, access control, auditability, and vulnerability management.
-
Team Work: Able to work across development, security, operations, and customer/platform teams to resolve technical blockers.
-
GIT: Familiarity with Git-based workflows, release governance, artefact management, and environment promotion.
-
Defence: Willingness to work in the defence and security sector.
Expected - Not all essential
-
Tooling: Hands-on experience with tools such as SonarQube, Argo, Tekton, OpenShift, Kubernetes, GitHub, or closely related equivalents.
-
Process: Producing deployment documentation, runbooks, technical evidence, and operational procedures.
-
Troubleshoot: Able to troubleshoot issues across development, test, integration, and hosted environments.
-
Reviews: Support design reviews, security reviews, and formal acceptance activity.
Preferred - Nice to have
-
MODCloud: Experience with MOD, Defence Digital, or similarly controlled environments.
-
Hardening: Exposure to SAST, DAST, dependency scanning, container hardening, and remediation workflows.
-
Integration: Experience supporting API-led systems, SSO integration, and cross-team interface management.
-
KeyCloak: Experience with SSO, RBAC, audit logging, and regulated or security-conscious environments.
-
Defence: Experience in defence, or high-assurance delivery environments.
-
Training: Experience in training or simulation environments.
-
UML: Experience reading and creating UML diagrams and architecture.