IT & Software

DevSecOps Engineer

Graphnet Health

Milton Keynes · England · United Kingdom

Reporting to: Technical Services Manager

Location: Milton Keynes/Homebased - with the expectation to attend Graphnet Group office sites at least once per month, or as and when required for team collaboration days.

Overview:

We are a British healthcare software company delivering market-leading integrated care record and population health solutions. Our Azure-hosted SaaS platform supports critical healthcare services, so security, reliability and resilience are central to everything we do.

We are looking for a hands-on Azure DevSecOps Engineer for a role that is balanced between DevOps engineering and Security engineering, helping us strengthen secure software delivery, cloud security posture and operational resilience.

The ideal candidate will be comfortable switching between DevOps activities such as CI/CD, automation and Infrastructure as Code, and security activities such as vulnerability management, monitoring, cloud hardening and incident response.

Key responsibilities include:

  • Build and improve secure CI/CD pipelines using Azure DevOps and/or GitHub Actions.
  • Embed DevSecOps practices such as code scanning, dependency checks, secret scanning, container scanning and IaC validation.
  • Work with Security, Engineering and Operations teams to identify, prioritise and remediate vulnerabilities and misconfigurations.
  • Deploy and harden Azure infrastructure using Infrastructure as Code, secure configuration and least-privilege principles.
  • Support secure Azure platform design across AKS, App Services, API Management, Azure SQL, networking, Key Vault, monitoring and logging.
  • Improve security visibility through automation, dashboards, alerts and operational tooling.
  • Contribute to threat modelling, security standards, policy-as-code and secure engineering guidance.
  • Support DR/BCP testing to ensure services remain secure, available and recoverable.

Personal Attributes:

  • Works well independently and as part of a collaborative engineering team.
  • Has a strong security mindset and a practical, risk-based approach.
  • Communicates clearly with technical and non-technical stakeholders.
  • Can prioritise work, manage competing demands and follow improvements through to completion.
  • Pays attention to detail and values consistent standards and repeatable processes.
  • Stays current with cloud, security and DevSecOps tools and practices.

Education & Skills Required:

  • Strong hands-on experience with Microsoft Azure, especially secure design, deployment and operation of Azure PaaS services.
  • Proven DevOps experience building and maintaining CI/CD pipelines using Azure DevOps and/or GitHub Actions.
  • Experience with Infrastructure as Code and automation, ideally using Terraform, Azure Verified Modules and PowerShell.
  • Experience with Azure security and operations tooling such as Microsoft Sentinel, Microsoft Defender for Cloud, Azure Monitor and Application Insights.
  • Practical experience with AKS, container security, App Services, API Management, Azure SQL, Key Vault, managed identities and Azure networking.
  • Knowledge of DevSecOps practices including SAST, dependency scanning, secret scanning, IaC scanning, container scanning and automated security gates.
  • Experience supporting vulnerability management, including triage, prioritisation, remediation tracking and collaboration with security teams.
  • Experience with Cloudflare or similar edge security, WAF, DNS and traffic protection technologies.

Advantageous:

  • Healthcare, NHS, Government or other regulated industry experience.
  • Experience with Jira and Confluence for workflow, documentation and audit trails.
  • Knowledge of TCAF, Azure Verified Modules, landing zones or enterprise-scale Azure governance.
  • Knowledge of secure development practices, threat modelling, OWASP or application security testing.
  • Experience supporting ISO 27001 controls, evidence gathering or audit readiness.

Qualifications:

  • Relevant Microsoft Azure certification such as AZ-400 or AZ-500, or equivalent practical experience.
  • Security, cloud or DevSecOps certifications such as SC-200, CISSP, CCSP or similar would be beneficial.

As an equal opportunities’ employer, we welcome applications from individuals of all backgrounds. However, for you to be eligible for this role, you must have a valid right to work in the UK for the entire duration of your employment, as we are unable to provide routes to sponsorship currently.

#J-18808-Ljbffr

Reference: WJ-766_22290307

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.