Job Summary
Job Description - DevOps Engineer Function: CSO Role: DevOps Engineer Hiring Managers: Louise Furniss / Julie Wilson Grade: E/F Location: UK / Offshore Open Positions: 2 Duration: 10 Months ________________________________________ Job Summary • Join the Cyber Security organization to build and maintain secure, scalable, and automated software delivery pipelines. • Enable secure software development practices by embedding security controls throughout the DevOps lifecycle. • Support engineering teams in implementing DevSecOps principles, automation, and continuous compliance. • Design and enhance CI/CD pipelines that improve deployment speed, reliability, and security. • Collaborate with development, infrastructure, and security teams to strengthen software supply chain security. • Drive adoption of security-by-design practices across cloud-native and enterprise technology platforms. • Contribute to the organization\'s secure software delivery and cyber resilience objectives
Key Responsibilities
Design, implement, and maintain secure CI/CD pipelines across multiple development environments. • Integrate SAST, DAST, dependency scanning, and software composition analysis tools into delivery pipelines. • Implement Policy as Code controls to automate governance, compliance, and security validation. • Establish automated security gates and approval mechanisms within software delivery workflows. • Develop and maintain secure configuration management standards across applications and infrastructure. • Collaborate with development teams to identify and remediate security vulnerabilities early in the SDLC. • Monitor pipeline performance, security compliance, and deployment effectiveness while driving continuous improvement.
Skill Requirements
Strong experience with DevOps and DevSecOps methodologies in enterprise environments. • Hands-on expertise in building and managing secure CI/CD pipelines using modern automation tools. • Experience implementing SAST, DAST, dependency scanning, and software supply chain security controls. • Knowledge of Policy as Code frameworks and infrastructure automation technologies. • Understanding of secure software development lifecycle (SSDLC) principles and security engineering practices. • Experience with cloud platforms, container technologies, automation frameworks, and configuration management tools. • Strong troubleshooting, analytical, stakeholder management, and problem-solving capabilities. ________________________________________ Technical Certification Need to Have and Good to Have Need to Have • Demonstrated experience in DevOps, DevSecOps, or Secure Software Engineering roles. • Strong practical knowledge of CI/CD tools, automation frameworks, and secure deployment practices. • Experience implementing application security controls within software development pipelines. • Knowledge of vulnerability management, secure configuration management, and compliance monitoring. • Familiarity with cloud-native development and automated infrastructure management. Good to Have • Certified Kubernetes Administrator (CKA) or Certified Kubernetes Application Developer (CKAD). • Microsoft Azure DevOps Engineer Expert (AZ-400). • AWS Certified DevOps Engineer – Professional. • HashiCorp Terraform Associate Certification. • Certified Secure Software Lifecycle Professional (CSSLP). • Certified Information Systems Security Professional (CISSP) or Certified Cloud Security Professional (CCSP). • GitLab, GitHub Advanced Security, Jenkins, or equivalent DevSecOps platform certifications.
Other Requirements
This role focuses on building secure CI/CD pipelines, implementing security controls, and enabling secure software delivery at scale. • Experience integrating security tools into automated development workflows is highly desirable. • Candidates with strong DevSecOps expertise and a security-first engineering mindset will be preferred. • Exposure to cloud security, container security, Infrastructure as Code (IaC), and software supply chain security is advantageous. • The position offers an opportunity to strengthen enterprise software delivery capabilities through automation, security, and modern engineering practices.