Senior DevSecOps Engineer
Whitehall Resources are currently looking for a Senior DevSecOps Engineer on a hybrid basis in Berkshire for an initial 6-month contract.
***INSIDE IR35***
Job Spec
The Senior SecDevOps Engineer is accountable for leading the integration of security, automation, and operational best practices throughout the software development lifecycle, infrastructure platforms, and cloud environments. This role ensures that security is embedded by design across enterprise systems, enabling the organisation to deliver secure, resilient, and compliant digital products and services at scale.
The Senior SecDevOps Engineer provides technical leadership for secure platform engineering, cloud security, CI/CD pipelines, infrastructure automation, vulnerability management, and security monitoring. The role works closely with software engineers, infrastructure teams, cyber security specialists, architects, and delivery teams to establish DevSecOps standards, implement secure automation, and continuously improve the organisation’s security posture.
Key responsibilities
- Lead the design, implementation, and operation of secure DevSecOps platforms and toolchains.
- Embed security controls, testing, and compliance validation into CI/CD pipelines.
- Design and implement Infrastructure as Code (IaC) solutions aligned with security standards.
- Develop and maintain cloud security architectures across hybrid and multi-cloud environments.
- Implement automated vulnerability identification, remediation, and reporting solutions.
- Lead the adoption of secure software development lifecycle (SSDLC) principles and practices.
- Support threat modelling, security architecture reviews, and risk assessments.
- Establish security monitoring, logging, auditing, and incident response capabilities.
- Collaborate with engineering teams to improve security awareness and secure coding practices.
- Support compliance with organisational, regulatory, and industry security frameworks.
- Provide technical leadership, mentoring, and guidance to engineering and security teams.
- Drive continuous improvement and automation across platform and security operations.
Essential
- 7+ years of experience in SecDevOps, DevOps, Cloud Security, or Security Engineering roles.
- Extensive experience building and managing secure CI/CD pipelines using Azure DevOps, GitHub Actions, GitLab CI/CD, or Jenkins.
- Strong knowledge of secure software development lifecycle (SSDLC) methodologies.
- Experience implementing security scanning technologies including SAST, DAST, SCA, container scanning, and secrets detection.
- Strong understanding of Microsoft Azure security services and controls.
- Experience supporting hybrid cloud and on-premises environments.
- Hands-on experience with Kubernetes and OpenShift security.
- Practical experience with Infrastructure as Code tools including Terraform, Bicep, ARM Templates, and Ansible.
- Strong experience with Identity and Access Management (IAM), RBAC, and Privileged Access Management (PAM).
- Experience operating SIEM, SOAR, logging, monitoring, and observability platforms.
- Strong scripting and automation skills using PowerShell, Python, Bash, or similar languages.
- Experience supporting vulnerability management and incident response processes.
- Strong analytical, troubleshooting, and root cause analysis skills.
- Excellent communication and stakeholder management capabilities.
- Proven ability to mentor engineers and influence technical direction.
- Experience working within Agile, DevOps, and Platform Engineering environments.
Desirable
- CISSP, CCSP, CKS, Security+, CEH, or equivalent certifications.
- Experience within aerospace, defence, government, or highly regulated environments.
- Experience supporting secure and classified platforms.
- Familiarity with NCSC, NIST 800-53, ISO 27001, Cyber Essentials Plus, or similar frameworks.
- Knowledge of Zero Trust Architecture principles.
- Experience implementing security controls for AI and machine learning platforms.
- Experience with service mesh technologies such as Istio or Linkerd.
- Experience with multi-cloud security architectures.
- Experience implementing Policy-as-Code solutions such as Open Policy Agent (OPA).
- Knowledge of FinOps and cloud cost optimisation practices.
All of our opportunities require that applicants are eligible to work in the specified country/location, unless otherwise stated in the job description.
Whitehall Resources are an equal opportunities employer who value a diverse and inclusive working environment. All qualified applicants will receive consideration for employment without regard to race, religion, gender identity or expression, sexual orientation, national origin, pregnancy, disability, age, veteran status, or other characteristics.