IT & Software

DevSecOps Engineer

Oscar

Surrey · Surrey · United Kingdom

Overview

In this hands-on role you strengthen Azure deployments and application security across the software delivery lifecycle. You own CI/CD pipelines, Infrastructure-as-Code, and security testing, partnering with development teams to embed secure practices. You will safeguard Azure services and implement repeatable, secure deployment patterns at scale. You will mentor junior engineers and drive secure coding and release practices, contributing to a culture of proactive security and reliability. This position offers ownership over how secure software is built, tested, and released in a cloud-first environment.

Responsibilities
  • Design and maintain CI/CD pipelines in Azure DevOps
  • Deploy and manage Azure applications/infrastructure using Terraform
  • Support Azure services (App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints, Front Door/WAF)
  • Introduce blue/green releases, automated rollback, and drift detection
  • Integrate SAST/DAST, dependency and container scanning into pipelines
  • Conduct web app security testing with Burp Suite or OWASP ZAP
  • Manage vulnerabilities per OWASP Top 10 and CVSS
  • Implement secrets detection, rotation and secure Key Vault practices
  • Strengthen software supply-chain security with SBOMs, signing, and dependency scanning
  • Support API security testing, threat modelling and third-party pen tests
  • Configure Azure-native security tooling (Defender for Cloud, Azure Policy, Sentinel, Azure Monitor)
  • Enforce identity/access controls across Entra ID, RBAC, Conditional Access and PIM
  • Support compliance with Cyber Essentials Plus, ISO 27001 and GDPR
  • Mentor junior engineers and promote secure coding/deployment practices
Key requirements
  • Three to five years’ experience in DevOps, platform engineering or application security
  • Strong hands-on experience with Microsoft Azure and Azure DevOps
  • Proven experience securing web applications in production
  • Practical experience using Burp Suite for application security testing
  • Experience with SonarQube or equivalent SAST tooling
  • Strong knowledge of OWASP Top 10, vulnerability management and remediation
  • Experience building repeatable Azure deployments using Terraform
  • Scripting ability with PowerShell, Python or Bash
  • Experience implementing secrets detection and dependency/CVE remediation tooling
  • Ability to work independently and support junior engineers
  • Experience with Docker, Kubernetes/AKS, API security testing, threat modelling, SIEM tooling or software supply-chain security is a plus
  • Relevant certifications (AZ-500, AZ-400, Security+, CySA+, CEH or OSCP) are beneficial
  • Ability to work independently
  • Risk-based decision making
  • Mentoring and guiding junior engineers
  • Azure
  • Azure DevOps
  • Terraform

Reference: WJ-747_30154748

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.