Security Engineer (DevSecOps)
London, Greater London
£143,000 - £169,000/annum
Posted 4 days ago
About the role
Security Engineer (DevSecOps)
A variety of soft skills and experience may be required for the following role Please ensure you check the overview below carefully.
Rate - £550 - £650 Inside IR35
Duration - 6 months initial
Location - London once a week on site
Reports to: Head of Security Architecture and Engineering
The role:
This is a hands-on engineering role focused on building security into software as developed and deployed. You'll work across three workstreams alongside three Senior DevSecOps Engineers. You'll pick up work where it's most needed, keep security consistent across all three workstreams and make sure nothing falls between them.
It suits a software, DevOps or platform engineer who has already built security into their day-to-day work and wants to take it further. You'll get exposure to platform, AI and integration security.
What you'll do
Set up and tune security scanning in CI/CD pipelines, cut down false positives and help developers fix real issues.
Build shared security modules, policy libraries and templates that all three teams can reuse.
Review code, infrastructure-as-code and configuration changes for security issues.
Handle day-to-day vulnerability management, including pen test findings: prioritise what's genuinely exploitable, track fixes and check they've worked.
Help run threat modelling sessions in IriusRisk and turn the results into backlog tickets.
Look after secrets management, certificates and access reviews and keep security documentation, control evidence and CAB records up to date.
Be the go-to person when security is blocking a delivery team, cover for the senior engineers when priorities shift and flag where teams are solving the same problem in different ways.
What you'll need
Hands-on experience in software engineering, DevOps or platform engineering with a strong security focus, or in security engineering.
Experience with CI/CD and security scanning tools (SAST, SCA, secrets, IaC and container scanning).
Python or Bash and Terraform.
AWS fundamentals including IAM, plus working knowledge of containers and Kubernetes.
A good grasp of vulnerability management, including CVSS, EPSS and judging whether an issue is really exploitable.
Clear written communication and comfortable switching between teams.
Nice to have
A security certification such as AWS Certified Security - CKS, CompTIA Security+, GIAC or CISSP.
Exposure to policy-as-code or Istio.
Experience in a regulated environment.
An interest in AI security.
Reasonable Adjustments:
Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. xwzovoh Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.
If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
A variety of soft skills and experience may be required for the following role Please ensure you check the overview below carefully.
Rate - £550 - £650 Inside IR35
Duration - 6 months initial
Location - London once a week on site
Reports to: Head of Security Architecture and Engineering
The role:
This is a hands-on engineering role focused on building security into software as developed and deployed. You'll work across three workstreams alongside three Senior DevSecOps Engineers. You'll pick up work where it's most needed, keep security consistent across all three workstreams and make sure nothing falls between them.
It suits a software, DevOps or platform engineer who has already built security into their day-to-day work and wants to take it further. You'll get exposure to platform, AI and integration security.
What you'll do
Set up and tune security scanning in CI/CD pipelines, cut down false positives and help developers fix real issues.
Build shared security modules, policy libraries and templates that all three teams can reuse.
Review code, infrastructure-as-code and configuration changes for security issues.
Handle day-to-day vulnerability management, including pen test findings: prioritise what's genuinely exploitable, track fixes and check they've worked.
Help run threat modelling sessions in IriusRisk and turn the results into backlog tickets.
Look after secrets management, certificates and access reviews and keep security documentation, control evidence and CAB records up to date.
Be the go-to person when security is blocking a delivery team, cover for the senior engineers when priorities shift and flag where teams are solving the same problem in different ways.
What you'll need
Hands-on experience in software engineering, DevOps or platform engineering with a strong security focus, or in security engineering.
Experience with CI/CD and security scanning tools (SAST, SCA, secrets, IaC and container scanning).
Python or Bash and Terraform.
AWS fundamentals including IAM, plus working knowledge of containers and Kubernetes.
A good grasp of vulnerability management, including CVSS, EPSS and judging whether an issue is really exploitable.
Clear written communication and comfortable switching between teams.
Nice to have
A security certification such as AWS Certified Security - CKS, CompTIA Security+, GIAC or CISSP.
Exposure to policy-as-code or Istio.
Experience in a regulated environment.
An interest in AI security.
Reasonable Adjustments:
Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. xwzovoh Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.
If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
About this listing
Screened by Joboru
This role passed our automated spam and quality filters and was active in our feed when last checked. Joboru is an aggregator — here is how we screen listings. If anything looks off, tell us.
Similar jobs you may like
Dayforce HCM Migration Technical Lead - Fintech Carveout
1 day agoBarclays
CMM Programmer
1 day agoRobert Walters
Digital Skills Coach (Teachers)
1 day agoYork College
Document Developer
1 day agoRefresco Drinks UK Limited
Automation Engineer
1 day agoAmazon
Lead Backend Engineer - Technologist
1 day agoClient Server
Mobile Developer C++ Swift - Cyber Security
1 day agoClient Server
Senior Safety Engineer
1 day agoMeridian Business Support
Group Application Development Manager cloned on 10-09-26 170929
1 day agoDFS Head Office