SecDevOps Engineer
Role details
Job location
Tech stack
Job description
We're supporting a major UK defence and national security programme seeking an experienced SecDevOps Engineer to help embed security throughout the software development life cycle and cloud platforms.
You'll play a key role in designing secure CI/CD pipelines, implementing Infrastructure as Code, automating security controls, and ensuring cloud environments meet stringent security and compliance standards.
This is an excellent opportunity to work on a high-profile programme where security is at the heart of everything you build., * Design, implement and maintain secure CI/CD pipelines
- Integrate automated security testing into software delivery processes
- Develop and maintain secure Infrastructure as Code (Terraform, Bicep, CloudFormation or Ansible)
- Implement cloud security controls across Azure, AWS or Google Cloud
- Automate vulnerability management, monitoring and compliance reporting
- Support container and Kubernetes security
- Work closely with engineering, architecture and cyber security teams to embed Secure by Design principles
- Support threat detection, incident response and security monitoring
- Conduct security reviews and risk assessments across applications and infrastructure
Requirements
- 5+ years' experience in DevOps, SecDevOps, Cloud Engineering or Cyber Security Engineering
- Strong experience with secure CI/CD pipelines using Azure DevOps, GitHub Actions, GitLab CI/CD or Jenkins
- Hands-on Infrastructure as Code experience (Terraform, Bicep, CloudFormation or Ansible)
- Experience integrating security tooling including SAST, DAST, SCA, container security and secrets management
- Strong understanding of Secure Software Development Lifecycle (SSDLC)
- Experience securing cloud environments (Azure, AWS and/or GCP)
- Knowledge of IAM, authentication and privileged access management
- Scripting and automation experience using Python, PowerShell or Bash
Desirable Experience
- Defence, aerospace or other highly regulated environments
- Kubernetes and container security
- SIEM/SOAR platforms
- Zero Trust Architecture
- NIST, ISO 27001, NCSC or NIS2 frameworks
- CISSP, CCSP, Security+, CEH or equivalent certifications
- Cloud security certifications
Security Clearance
Due to the nature of this programme, applicants must be sole British passport holders and either:
- Hold current SC Security Clearance, or
- Be eligible and willing to undergo SC Clearance .