IT & Software

DevSecOps Engineer

Oscar Associates (UK) Limited

London · England · United Kingdom

DevSecOps Engineer - Azure / Application Security

We're working with an established organisation looking to appoint an experienced DevSecOps Engineer to strengthen its Azure deployment and application security capabilities. This is a hands-on position combining Azure DevOps, cloud infrastructure and application security. You'll take ownership of CI/CD pipelines, Infrastructure-as-Code and security testing, while helping development teams embed secure practices throughout the software delivery lifecycle.

The Role

You'll be responsible for: Designing and maintaining CI/CD pipelines within Azure DevOps

Deploying Azure applications and infrastructure using Terraform

Supporting Azure services including App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints and Front Door/WAF

Introducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detection

Integrating SAST, DAST, dependency and container scanning into development pipelines

Conducting web application security testing using Burp Suite, OWASP ZAP or similar tools

Identifying and managing vulnerabilities against OWASP Top 10 and CVSS principles

Implementing secrets detection, credential rotation and secure Key Vault practices

Strengthening software supply-chain security through SBOM generation, dependency scanning and artefact signing

Supporting API security testing, threat modelling and third-party penetration tests

Configuring Azure-native security tooling, including Defender for Cloud, Azure Policy, Sentinel and Azure Monitor

Enforcing identity and access controls across Entra ID, RBAC, Conditional Access and PIM

Supporting compliance with frameworks such as Cyber Essentials Plus, ISO 27001 and GDPR

Mentoring junior engineers and helping developers adopt secure coding and deployment practices

What We're Looking For

You'll need: Around three to five years' experience across DevOps, platform engineering or application security

Strong hands-on experience with Microsoft Azure and Azure DevOps

Proven experience securing web applications in a production environment

Practical experience using Burp Suite for application security testing

Experience with SonarQube or comparable SAST tooling

Strong knowledge of OWASP Top 10, vulnerability management and remediation

Experience building repeatable Azure deployments using Terraform

Scripting ability with PowerShell, Python or Bash

Experience implementing secrets detection and dependency/CVE remediation tooling

The confidence to work independently, make risk-based decisions and support junior engineers

Experience with Docker, Kubernetes/AKS, API security testing, threat modelling, SIEM tooling or software supply-chain security would be particularly useful. Relevant certifications such as AZ-500, AZ-400, Security+, CySA+, CEH or OSCP would also be beneficial, although practical experience is more important. This is an excellent opportunity for someone who enjoys working across cloud engineering and application security and wants genuine ownership over how secure software is built, tested and released. Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy. To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.

TPBN1_UKTJ

Reference: WJ-799_23731456

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.