£650 Per day
Inside
Hybrid
England
Summary: The role is for a SC DevOps/DevSecOps Engineer on a 6-month contract, requiring active security clearance and a hybrid working arrangement with two days onsite. The position demands expertise in modern DevOps tooling and security automation practices, particularly in cloud-native environments. The contractor will be expected to implement security controls and mentor teams on secure coding practices.
Key Responsibilities:
- Utilize modern DevOps tooling with secure configurations.
- Implement security automation in CI/CD and infrastructure-as-code pipelines.
- Enforce security controls in cloud-native environments.
- Use security tools to ensure pipeline and platform security.
- Lead and mentor teams on secure coding and architecture patterns.
- Monitor and log security telemetry platforms.
Key Skills:
- Deep understanding of modern DevOps tooling (e.g., GitHub Actions, Terraform, Kubernetes, Docker).
- Strong hands-on expertise in DevSecOps practices.
- Experience with cloud-native security controls (e.g., AWS, Azure).
- Proven track record with security enforcement tools (e.g., Snyk, Trivy).
- Familiarity with compliance requirements (e.g., NIST, ISO 27001).
- Ability to lead and mentor teams.
- Experience with monitoring and logging platforms (e.g., Prometheus, ELK).
Salary (Rate): £650 daily
City: undetermined
Country: UK
Working Arrangements: hybrid
IR35 Status: inside IR35
Seniority Level: undetermined
Industry: IT
6 month contract
Must have Active SC
2 days onsite, whichever site is closest to you
£650 PD Inside IR35
Essential Skills and Experience
- Deep understanding of modern DevOps tooling (e.g., GitHub Actions/ CircleCI, Terraform, Kubernetes, Docker) with secure configurations.
- Strong hands-on expertise in DevSecOps practices, particularly security automation in CI/CD and infrastructure-as-code pipelines.
- Experience implementing security controls in cloud-native environments (e.g., AWS or Azure) including IAM, network policies, and container security.
- Proven track record of using tools such as Snyk, Trivy, Checkov, OPA/Gatekeeper/ OWASP ZAP, or similar to enforce pipeline and platform security.
- Familiarity with compliance requirements (e.g., NIST, ISO 27001, CIS Benchmarks) and their implementation via code.
- Ability to lead and mentor teams on secure coding, threat modelling, and secure architecture patterns.
- Experience with monitoring, logging, and security telemetry platforms (e.g., Prometheus, Loki, ELK, XDR/SIEM integrations).
Lawrence Harvey is acting as an Employment Business in regards to this position. Visit our website and follow us on Twitter for all live vacancies (lawharveyjobs)