DevSecOps Engineer

Workable
London
3 months ago
Create job alert

We are looking for a DevSecOps Engineer to join our growing DevOps Engineering team.

This role isUK based, primarily remote working with some travel required to our London Office. Sponsorship is not available for this role.

What you will do:

  • Security Integration in CI/CD Pipelines: Implement security controls within CI/CD pipelines using automation and best practices, ensuring vulnerabilities are caught early in the development cycle.
  • Infrastructure as Code (IaC) Security: Secure the infrastructure by applying security measures to IaC tools such as Terraform and Ansible.
  • Container Security: Ensure that containers (Docker, Kubernetes) are secured by configuring appropriate policies, scanning for vulnerabilities, and managing runtime security.
  • Cloud Security: Design, implement, and manage security across Azure, focusing on identity management, data protection, and network security.
  • Vulnerability Management: Identify and prioritize vulnerabilities across infrastructure and applications, and collaborate with teams to remediate them in a timely manner.
  • Threat Modelling and Risk Assessment: Perform threat modelling to identify security risks and provide recommendations for mitigation.
  • Monitoring and Incident Response: Develop and maintain monitoring systems and respond to security incidents quickly and effectively.
  • Automated Security Testing: Integrate and manage SAST, DAST, and other security testing tools to identify security issues in code and applications.
  • Compliance and Governance: Develop and manage Azure policies to ensure compliance with security standards and regulations (ISO 27001, SOC 2, GDPR) across our infrastructure.
  • Collaboration: Work closely with development, operations, and security teams to build a culture of security and ensure it is embedded in all phases of the development process.
  • Security Awareness: Provide mentorship and training to teams on secure coding practices, best security practices, and emerging security threats.
  • Security Integration: Integrate Azure Defender and other security tools to enhance our cloud security posture.

Requirements

Essential:

  • Passion for Security
  • Proven experience in a DevSecOps role or similar.
  • Strong understanding of Azure DevOps, CI/CD practices
  • Familiarity with Azure services, including Azure Defender, Azure Monitor, and Azure Policy.
  • Experience with security and compliance scanning tools such as vulnerability scanners, intrusion detection systems, & security information & event management (SIEM) solutions.
  • Knowledge of container management with Azure Container Registry.
  • Experience in SAST, DAST & other techniques to improve code security

Desirable:

  • Proficiency in scripting, preferably with PowerShell.
  • Understanding of DotNet development and deployment pipelines.
  • Experience working with PCI DSS standards (good to have).

Benefits

  • Competitive salary
  • Generous28 daysholidayallowance, in addition to public holidays.
  • For every year of service you complete, we’ll give you anadditional days holiday(max. 5 days)
  • One Dynamic Day per monthon top of your holiday allowance to spend time doing the things you want to do or simply catching up with life admin.
  • Remote & Hybrid approachvarying with the nature of your role.
  • Life cover; income protectionand participation in the companypension scheme
  • All employees are included in the companydiscretionary bonus scheme.
  • £100 per monthto put towards wellness activities.
  • Annuallearning & development allowance of£1,250and free access to LinkedIn learning and Microsoft ESI learning platforms

Additional Information:

Our company was built by looking at the world through a different lens and our culture today reflects that by encouraging you to be yourself, speak your mind, and share your opinions. We want people who want to push themselves, be part of something great, and be prepared to challenge if they think there is a better way. Collaboration sits at the heart of how we operate, it has fueled our growth enormously and our aim to be ‘world class’.                                                                                                                                  

We want everyone to be the best they can be throughout our recruitment process; if you require any additional adjustments please let us know.Visitinstanda.com/careersfor more information

INSTANDA has an in-house recruitment team, which focuses on sourcing great candidates directly.  INSTANDA does not accept unsolicited resumes from agency or search firm recruiters.  Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired.  When we do use agencies, we have a PSL in place, so please do not contact managers directly.

Related Jobs

View all jobs

DevSecOps Engineer

DevSecOps Engineer

DevSecOps Engineer

Senior DevSecOps Engineer

Senior DevSecOps Engineer

Senior DevSecOps Engineer

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Contract vs Permanent Cybersecurity Jobs: Which Pays Better in 2025?

Cybersecurity has become one of the fastest-growing and most crucial fields in modern business. With high-profile breaches dominating headlines and the ongoing digital transformation exposing organisations to new threats, companies across the UK are competing to attract skilled cybersecurity professionals. Roles range from penetration testers (pen testers) and SOC (Security Operations Centre) analysts to compliance officers, cloud security architects, threat intelligence analysts, and CISOs (Chief Information Security Officers). As demand continues to surge, cybersecurity salaries have climbed accordingly, and businesses have turned to more flexible hiring practices. Alongside permanent employment, many professionals explore short-term day‑rate contracting or fixed-term contracts (FTCs), searching for the ideal balance of pay, job security, and growth opportunities. Which arrangement truly pays better in 2025—and which best aligns with your ambitions? In this article, we dive into the contract vs. permanent debate with a focus on cybersecurity roles. We will examine the current market, the structure of day‑rate vs. FTC vs. permanent positions, the pros and cons of each, and some hypothetical pay comparisons. By the end, you should have a clearer sense of which career path might suit your situation and goals—whether you are a seasoned specialist aiming for top rates, or an up-and-coming analyst seeking a stable environment to develop in.

Cyber Security Jobs for Non‑Technical Professionals: Where Do You Fit In?

Defence Needs More Than Hackers in Hoodies When headlines warn of ransomware crippling hospitals or deepfakes swaying elections, we picture hoodie‑clad hackers and elite penetration testers. Yet the reality of the UK’s cyber security sector is broader—and desperately short of talent. The Department for Science, Innovation & Technology (DSIT) estimates a shortfall of 11,200 cyber security professionals in 2024, while 43 % of advertised roles require governance, risk or communication skills rather than hands‑on technical exploits. Put plainly: if you can guide policy, manage projects, interpret regulations or inspire behaviour change, cyber security wants you. This guide highlights the fastest‑growing non‑technical roles, the transferable skills you already possess, and a concrete 90‑day plan to land a cyber security job—no packet sniffers required.

BAE Systems Cybersecurity Jobs in 2025: Your Complete UK Guide to Protecting Governments, Businesses and Critical Infrastructure

From securing the Royal Navy’s new Dreadnought submarines to foiling multimillion‑pound fraud rings, BAE Systems Digital Intelligence (DI)—formerly Detica—sits at the sharp end of global cyber defence. Head‑quartered in Guildford with hubs in Gloucester, Leeds and London, the 5,500‑strong DI business delivers threat‑intelligence platforms, secure‑by‑design software and 24/7 SOC services to government and commercial clients worldwide. With escalating ransomware, AI‑driven disinformation and complex supply‑chain threats, BAE plans to expand its UK cyber workforce by 20 % in 2025. Whether you’re a graduate passionate about reverse engineering, a DevSecOps engineer who loves IaC, or an incident‑response pro comfortable in high‑side environments, this guide explains how to land a BAE Systems cybersecurity job in 2025.