Negotiable
Outside
Remote
United Kingdom
Summary: The Security Engineer role focuses on securing Azure-based IT and Operational Technology (OT) environments, emphasizing automation, governance, and secure-by-design principles. The position involves designing and implementing security frameworks, managing Azure policies, and enhancing DevSecOps pipelines. The role requires collaboration with cross-functional teams to embed security throughout the delivery lifecycle. This is a remote position based in the UK with occasional site travel for key meetings.
Key Responsibilities:
- Design and implement a robust RBAC framework for OT environments, ensuring least privilege access across automation pipelines and infrastructure
- Deploy and manage Azure Policy to enforce governance and automate the secure onboarding of IT/OT servers
- Build and enhance DevSecOps pipelines for Python-based Azure Functions, integrating automated security scanning and compliance checks
- Define and implement security baselines and standards for proxy-based architectures supporting OT environments
- Support patch management and remediation strategies using Azure Update Manager
- Collaborate with cross-functional teams to ensure security is embedded across the full delivery lifecycle
- Drive automation and continuous improvement across cloud security processes
Key Skills:
- Strong experience with Microsoft Azure security, including Azure Policy and identity/access management
- Proven track record in DevSecOps, including integrating security tools into CI/CD pipelines
- Experience developing or supporting Azure Functions (Python preferred)
- Solid understanding of RBAC models and least privilege principles
- Experience with vulnerability scanning and security tooling (e.g. SAST/DAST solutions)
- Knowledge of patch management and update automation within Azure environments
- Exposure to Operational Technology (OT) / Industrial Control Systems (ICS) environments is highly desirable
- Strong stakeholder engagement and communication skills
Salary (Rate): undetermined
City: undetermined
Country: United Kingdom
Working Arrangements: remote
IR35 Status: outside IR35
Seniority Level: undetermined
Industry: IT
Security Engineer (Azure / DevSecOps / OT)
Location: Remote (UK-based) with occasional site travel for key meetings
Contract: 6 months, rising to a year
Rate: Competitive, Outside IR35
Overview
We are working with a leading global technology consultancy to recruit a highly skilled Security Engineer for a critical programme focused on securing Azure-based IT and Operational Technology (OT) environments. This role sits at the intersection of cloud security, DevSecOps, and industrial/OT systems, with a strong emphasis on automation, governance, and secure-by-design principles.
Key Responsibilities
- Design and implement a robust RBAC framework for OT environments, ensuring least privilege access across automation pipelines and infrastructure
- Deploy and manage Azure Policy to enforce governance and automate the secure onboarding of IT/OT servers
- Build and enhance DevSecOps pipelines for Python-based Azure Functions, integrating automated security scanning and compliance checks
- Define and implement security baselines and standards for proxy-based architectures supporting OT environments
- Support patch management and remediation strategies using Azure Update Manager
- Collaborate with cross-functional teams to ensure security is embedded across the full delivery lifecycle
- Drive automation and continuous improvement across cloud security processes
Key Skills & Experience
- Strong experience with Microsoft Azure security, including Azure Policy and identity/access management
- Proven track record in DevSecOps, including integrating security tools into CI/CD pipelines
- Experience developing or supporting Azure Functions (Python preferred)
- Solid understanding of RBAC models and least privilege principles
- Experience with vulnerability scanning and security tooling (e.g. SAST/DAST solutions)
- Knowledge of patch management and update automation within Azure environments
- Exposure to Operational Technology (OT) / Industrial Control Systems (ICS) environments is highly desirable
- Strong stakeholder engagement and communication skills
Desirable Experience
- Experience working within regulated or industrial sectors (e.g. energy, utilities, manufacturing)
- Familiarity with proxy-based architectures in secure environments
- Certifications in Azure or cloud security (e.g. AZ-500)
Why Apply?
- Opportunity to work on a high-impact security programme within a complex Azure environment
- Immediate start on a well-funded, business-critical project
- Flexible remote-first working with occasional on-site collaboration