Senior DevSecOps & Product Security Engineer
Indexed description
We are looking for an experienced Senior DevSecOps & Product Security Engineer to help build, automate and operate security capabilities across our cloud platform, SDLC and CI/CD pipelines.
This is a hands-on role working closely with engineering, cloud operations and architecture teams to improve security posture, embed automated controls and support compliance with customer, contractual and regulatory requirements.
Key Responsibilities
- Design and implement security controls across CI/CD pipelines
- Automate SAST, SCA, secret detection, container scanning, IaC scanning and DAST where appropriate
- Build policy-as-code, security guardrails and automated compliance reporting
- Secure cloud infrastructure, Kubernetes environments and deployment processes
- Improve IAM, privileged access management, MFA, networking and encryption standards
- Own vulnerability management, including scanning, risk assessment, remediation tracking, patch coordination and reporting
- Partner with development teams on secure coding standards, threat modelling, design reviews and software supply chain security
- Support penetration testing, customer security assessments and audit preparation
- Investigate security events, support incident response and improve detection, logging and monitoring
- Develop automation for evidence collection, reporting, dashboards and security workflows
What We’re Looking For
- 5+ years’ experience in Security Engineering, DevSecOps or Cloud Security
- Experience securing cloud-native SaaS products and production cloud platforms
- Strong knowledge of at least one major cloud platform: AWS, Azure or Google Cloud
- Hands-on experience with CI/CD tools such as GitHub Actions, Azure DevOps, GitLab CI or Jenkins
- Experience with security tools such as Checkmarx, SonarQube, GitHub Advanced Security, Trivy, Snyk, Semgrep or OWASP ZAP
- Strong container and Kubernetes security knowledge, including Docker and Helm
- Experience with IaC tools such as Terraform, Bicep, CloudFormation or Pulumi
- Familiarity with IaC scanning tools such as Checkov, tfsec or Terrascan
- Strong scripting skills in Python, PowerShell or Bash
- Solid understanding of OWASP Top 10, Secure SDLC, threat modelling, Zero Trust, IAM, encryption, PKI, secrets management, SIEM, incident response and vulnerability management
- Experience with frameworks such as ISO 27001, ISO 27002, NIST CSF, CIS Controls, SSDF or SOC 2
Nice to Have
- Go programming experience
- Experience with UK Government Security Policy Framework or NCSC Cloud Security Principles
- Experience in government or regulated industry environments
About You
You are hands-on, pragmatic and automation-focused. You can work closely with engineering teams, communicate clearly, influence technical decisions and continuously improve how security is embedded into software delivery.
What Success Looks Like
In your first 12 months, you will have helped embed automated security testing into CI/CD pipelines, improved cloud security posture, reduced manual security work, strengthened vulnerability management and increased confidence in secure software delivery.
What We Offer
- Private healthcare for you and your dependents.
- Urban Sports Club & Udemy Business memberships covered by Doxis.
- Access to Udemy Business.
- Flexible working hours and a hybrid or remote working environment.
- 25 days of vacation.
- Daily meal allowance.
- Local and international events.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search