Back to search
Oscar Technology Reedcouk · Posted today

DevSecOps Engineer

Surrey GBP 60000-80000 / year Permanent

Permanent Reedcouk
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

DevSecOps Engineer - Azure / Application Security

We're working with an established organisation looking to appoint an experienced DevSecOps Engineer to strengthen its Azure deployment and application security capabilities.

This is a hands-on position combining Azure DevOps, cloud infrastructure and application security. You'll take ownership of CI/CD pipelines, Infrastructure-as-Code and security testing, while helping development teams embed secure practices throughout the software delivery lifecycle.

The Role

You'll be responsible for:

  • Designing and maintaining CI/CD pipelines within Azure DevOps

  • Deploying Azure applications and infrastructure using Terraform

  • Supporting Azure services including App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints and Front Door/WAF

  • Introducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detection

  • Integrating SAST, DAST, dependency and container scanning into development pipelines

  • Conducting web application security testing using Burp Suite, OWASP ZAP or similar tools

  • Identifying and managing vulnerabilities against OWASP Top 10 and CVSS principles

  • Implementing secrets detection, credential rotation and secure Key Vault practices

  • Strengthening software supply-chain security through SBOM generation, dependency scanning and artefact signing

  • Supporting API security testing, threat modelling and third-party penetration tests

  • Configuring Azure-native security tooling, including Defender for Cloud, Azure Policy, Sentinel and Azure Monitor

  • Enforcing identity and access controls across Entra ID, RBAC, Conditional Access and PIM

  • Supporting compliance with frameworks such as Cyber Essentials Plus, ISO 27001 and GDPR

  • Mentoring junior engineers and helping developers adopt secure coding and deployment practices

What We're Looking For

You'll need:

  • Around three to five years' experience across DevOps, platform engineering or application security

  • Strong hands-on experience with Microsoft Azure and Azure DevOps

  • Proven experience securing web applications in a production environment

  • Practical experience using Burp Suite for application security testing

  • Experience with SonarQube or comparable SAST tooling

  • Strong knowledge of OWASP Top 10, vulnerability management and remediation

  • Experience building repeatable Azure deployments using Terraform

  • Scripting ability with PowerShell, Python or Bash

  • Experience implementing secrets detection and dependency/CVE remediation tooling

  • The confidence to work independently, make risk-based decisions and support junior engineers


Experience with Docker, Kubernetes/AKS, API security testing, threat modelling, SIEM tooling or software supply-chain security would be particularly useful.

Relevant certifications such as AZ-500, AZ-400, Security+, CySA+, CEH or OSCP would also be beneficial, although practical experience is more important.

This is an excellent opportunity for someone who enjoys working across cloud engineering and application security and wants genuine ownership over how secure software is built, tested and released.

Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.

To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search