Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

DevSecOps Engineer

£30.7 - £35.7 per hourEstimated

DevSecOps Engineer - Azure / Application Security We're working with an established organisation looking to appoint an experienced DevSecOps Engineer to strengthen its Azure deployment and application security capabilities.This is a hands-on position combining Azure DevOps, cloud infrastructure and application security. You'll take ownership of CI/CD pipelines, Infrastructure-as-Code and security testing, while helping development teams embed secure practices throughout the software delivery lifecycle. The Role You'll be responsible for:Designing and maintaining CI/CD pipelines within Azure DevOpsDeploying Azure applications and infrastructure using TerraformSupporting Azure services including App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints and Front Door/WAFIntroducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detectionIntegrating SAST, DAST, dependency and container scanning into development pipelinesConducting web application security testing using Burp Suite, OWASP ZAP or similar toolsIdentifying and managing vulnerabilities against OWASP Top 10 and CVSS principlesImplementing secrets detection, credential rotation and secure Key Vault practicesStrengthening software supply-chain security through SBOM generation, dependency scanning and artefact signingSupporting API security testing, threat modelling and third-party penetration testsConfiguring Azure-native security tooling, including Defender for Cloud, Azure Policy, Sentinel and Azure MonitorEnforcing identity and access controls across Entra ID, RBAC, Conditional Access and PIMSupporting compliance with frameworks such as Cyber Essentials Plus, ISO 27001 and GDPRMentoring junior engineers and helping developers adopt secure coding and deployment practices What We're Looking For You'll need:Around three to five years' experience across DevOps, platform engineering or application securityStrong hands-on experience with Microsoft Azure and Azure DevOpsProven experience securing web applications in a production environmentPractical experience using Burp Suite for application security testingExperience with SonarQube or comparable SAST toolingStrong knowledge of OWASP Top 10, vulnerability management and remediationExperience building repeatable Azure deployments using TerraformScripting ability with PowerShell, Python or BashExperience implementing secrets detection and dependency/CVE remediation toolingThe confidence to work independently, make risk-based decisions and support junior engineersExperience with Docker, Kubernetes/AKS, API security testing, threat modelling, SIEM tooling or software supply-chain security would be particularly useful.Relevant certifications such as AZ-500, AZ-400, Security+, CySA+, CEH or OSCP would also be beneficial, although practical experience is more important.This is an excellent opportunity for someone who enjoys working across cloud engineering and application security and wants genuine ownership over how secure software is built, tested and released.Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the DevSecOps Engineer in Guildford, Surrey vacancy
  • £45k - £50k per annum

    Company: STRATOSPHEREC LTD Job Type: Permanent, Full Time Salary: £45000 - £50000/annum
    Suggested
    Permanent
    Full-time

    STRATOSPHEREC LTD

    Guildford, Surrey
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to DevSecOps Engineer. Be the first to apply!