DevSecOps Engineer
Oscar
In this hands-on role you strengthen Azure deployments and application security across the software delivery lifecycle. You own CI/CD pipelines, Infrastructure-as-Code, and security testing, partnering with development teams to embed secure practices. You will safeguard Azure services and implement repeatable, secure deployment patterns at scale. You will mentor junior engineers and drive secure coding and release practices, contributing to a culture of proactive security and reliability. This position offers ownership over how secure software is built, tested, and released in a cloud-first environment.
Responsibilities- Design and maintain CI/CD pipelines in Azure DevOps
- Deploy and manage Azure applications/infrastructure using Terraform
- Support Azure services (App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints, Front Door/WAF)
- Introduce blue/green releases, automated rollback, and drift detection
- Integrate SAST/DAST, dependency and container scanning into pipelines
- Conduct web app security testing with Burp Suite or OWASP ZAP
- Manage vulnerabilities per OWASP Top 10 and CVSS
- Implement secrets detection, rotation and secure Key Vault practices
- Strengthen software supply-chain security with SBOMs, signing, and dependency scanning
- Support API security testing, threat modelling and third-party pen tests
- Configure Azure-native security tooling (Defender for Cloud, Azure Policy, Sentinel, Azure Monitor)
- Enforce identity/access controls across Entra ID, RBAC, Conditional Access and PIM
- Support compliance with Cyber Essentials Plus, ISO 27001 and GDPR
- Mentor junior engineers and promote secure coding/deployment practices
- Three to five years’ experience in DevOps, platform engineering or application security
- Strong hands-on experience with Microsoft Azure and Azure DevOps
- Proven experience securing web applications in production
- Practical experience using Burp Suite for application security testing
- Experience with SonarQube or equivalent SAST tooling
- Strong knowledge of OWASP Top 10, vulnerability management and remediation
- Experience building repeatable Azure deployments using Terraform
- Scripting ability with PowerShell, Python or Bash
- Experience implementing secrets detection and dependency/CVE remediation tooling
- Ability to work independently and support junior engineers
- Experience with Docker, Kubernetes/AKS, API security testing, threat modelling, SIEM tooling or software supply-chain security is a plus
- Relevant certifications (AZ-500, AZ-400, Security+, CySA+, CEH or OSCP) are beneficial
- Ability to work independently
- Risk-based decision making
- Mentoring and guiding junior engineers
- Azure
- Azure DevOps
- Terraform
Reference: WJ-747_30154748