DevSecOps Engineer
Whitehall Resources are currently looking for a DevSecOps Engineer on a hybrid basis in Berkshire for an initial 6-month contract.
***INSIDE IR35***
Job Spec
The DevSecOps Engineer is accountable for integrating security practices, controls, and automation throughout the software development lifecycle and cloud infrastructure platforms. This role ensures security is embedded by design across development, deployment, and operational activities while maintaining delivery speed, reliability, and compliance.
The DevSecOps Engineer develops and maintains secure CI/CD pipelines, infrastructure-as-code solutions, automated security testing capabilities, and monitoring frameworks. The role works closely with software engineers, platform engineers, cyber security specialists, architects, and operational teams to ensure applications and platforms are resilient against cyber threats and compliant with organisational and regulatory requirements.
Key Responsibilities
- Design, implement, and maintain secure CI/CD pipelines incorporating automated security controls.
- Integrate security testing tools and practices into software delivery processes.
- Develop and maintain Infrastructure as Code (IaC) in accordance with security and compliance requirements.
- Support secure cloud adoption and cloud-native security practices.
- Implement automated vulnerability management and remediation processes.
- Monitor infrastructure, applications, and environments for security threats and vulnerabilities.
- Collaborate with development, security, and operations teams to embed security by design principles.
- Support incident response, threat detection, and investigation activities.
- Ensure compliance with security standards, governance requirements, and industry frameworks.
- Implement security monitoring, logging, and alerting solutions.
- Conduct risk assessments and security reviews of applications and infrastructure.
- Promote a culture of continuous improvement, automation, and secure engineering practices.
Essential
- 5+ years of experience in DevOps, SecDevOps, Cloud Engineering, or Cyber Security Engineering.
- Strong knowledge of secure software development lifecycle (SSDLC) methodologies.
- Experience implementing and managing CI/CD pipelines using tools such as Azure DevOps, GitHub Actions, GitLab CI/CD, or Jenkins.
- Practical experience with Infrastructure as Code technologies such as Terraform, Bicep, CloudFormation, or Ansible.
- Experience integrating security tools such as SAST, DAST, SCA, container security, and secrets management solutions.
- Strong understanding of cloud security principles across Microsoft Azure, AWS, or Google Cloud.
- Experience securing containerized and Kubernetes-based environments.
- Knowledge of Identity and Access Management (IAM), privileged access management, and authentication technologies.
- Experience managing vulnerability assessments, remediation, and compliance activities.
- Strong scripting and automation experience using Python, PowerShell, Bash, or similar languages.
- Experience with security monitoring, logging, and alerting platforms.
- Strong analytical and problem-solving skills.
- Excellent communication and stakeholder management capabilities.
Desirable
- Relevant security certifications such as CISSP, CEH, CCSP, or Security+.
- Experience within defence, aerospace, or highly regulated environments.
- Knowledge of Zero Trust Architecture principles.
- Experience supporting classified or secure-by-design environments.
- Knowledge of NIST, ISO 27001, NCSC, or NIS2 frameworks.
- Experience implementing SIEM and SOAR platforms.
- Experience with threat modelling methodologies and security architecture reviews.
- Experience supporting multi-cloud environments.
- Knowledge of supply chain security frameworks and practices.
All of our opportunities require that applicants are eligible to work in the specified country/location, unless otherwise stated in the job description.
Whitehall Resources are an equal opportunities employer who value a diverse and inclusive working environment. All qualified applicants will receive consideration for employment without regard to race, religion, gender identity or expression, sexual orientation, national origin, pregnancy, disability, age, veteran status, or other characteristics.