Senior DevSecOps Engineer
Listed on 2026-08-15
-
IT/Tech
Cybersecurity, Information Security & Data Protection
You’ll take ownership of work that gives us our competitive edge, including:
Development and Application Security-by-Design
Integrate and operate application security controls within CI/CD pipelines, including:
Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Secrets detection and dependency risk scanning
Support secure SDLC practices such as:
Branch protection and quality gates, Secure build and release controls, Artifact integrity and validation checks
Assist with threat modelling and secure design reviews in collaboration with architecture teams.
Support developers in vulnerability triage and remediation.
Tune security tools to reduce false positives and developer friction.
Support audit, compliance, and evidence generation activities.
Participate in security incident investigation related to application flaws.
Ensure secure, compliant approaches are the default and easiest options for development teams to adopt.
Configure and maintain security tooling integrations within CI/CD systems (e.g. Git Hub Actions, Git Lab CI, Jenkins, Azure Dev Ops) under agreed architectural standards
Ensure security controls operate consistently across teams and repositories.
Define and document Dev Sec security standards, patterns, and decisions.
Provide evidence and control mappings to support audits, risk assessments, and regulatory reviews.
Identify and track Dev Sec-related risks and technical debt, driving remediation through process improvements rather than manual controls.
Influence security outcomes through collaboration and technical leadership rather than enforcement.
Contribute to security enablement, awareness, and uplift initiatives focused on cloud-native and container security practices.
- Clear, confident communication (written and verbal), and the ability to breakdown complex ideas
- A collaborative mindset, working smoothly with cross-functional teams to hit shared goals
- Strong organisational skills and the ability to manage multiple projects without dropping the ball
- Exceptional attention to detail and a commitment to high-quality work
- Adaptability - you stay sharp, productive and positive in fast-moving environments
- Strong grounding in application security concepts. Secure coding knowledge (OWASP Top 10, API security, dependency risk).
- Strong knowledge of SAST, DAST, SCA, and software supply-chain security concepts.
- Strong advocate for enablement-first security.
- Ability to influence engineering teams through collaboration and technical credibility.
- Hands-on expertise with containers and orchestration platforms (e.g. Docker, Kubernetes).
- Demonstrated experience implementing container security across build, registry, and runtime.
- Proven experience securing CI/CD pipelines and developer tool chains.
- Knowledge of:
Infrastructure as Code (Terraform, Bicep, Cloud Formation, etc.) - Secrets and key management
- Cloud identity and access management
- Solid understanding of information security frameworks (e.g. ISO 27001).
- Experience operating in regulated or audited environments.
- Able to design controls that are auditable without slowing delivery.
Demonstrates expertise in Application Security, including Secure SDLC practices and CI/CD pipeline security. Proficient in threat modeling, vulnerability management, and security tooling integration, with a strong focus on collaboration and enablement within cross-functional teams.
Highest-signal resume keywords- Application Security Concepts
- CI/CD Pipeline Security
- SAST, DAST, SCA
- Container Security
- Infrastructure as Code
- Secure Coding Knowledge
- Threat Modeling
- Vulnerability Triage
- Security Tooling Integration
- Secrets Management
- Cloud Identity and Access Management
- Information Security Frameworks
- Container Orchestration
- Dev Sec Standards Documentation
- Audit and Compliance Support
- Clear Communication
- Collaborative Mindset
- Organizational Skills
- Attention to Detail
- Adaptability
- Application Security
- Secure SDLC
- Dev Sec Ops
- Regulated Environments
- ISO 27001
- Git Hub Actions
- Git Lab CI
- Jenkins
- Azure Dev Ops
- Docker
- Kubernetes
- Terraform
- Bicep
- Cloud Formation
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: