Job Title: Senior SecDevOps Engineer
Location: Reading (Hybrid)
Contract Length: 6 Months
Rate: £410- £510 a Day
Key Responsibilities
- Design, implement, and maintain secure DevSecOps platforms, CI/CD pipelines, and automated security controls.
- Embed security testing and compliance validation throughout the software development lifecycle.
- Develop and maintain Infrastructure as Code (IaC) solutions using industry-standard tooling.
- Support and enhance secure Azure, AWS, and hybrid cloud environments.
- Implement automated vulnerability management, security scanning, and remediation processes.
- Collaborate with engineering, security, infrastructure, and architecture teams to drive secure-by-design principles.
- Support threat modelling, security reviews, risk assessments, and cyber incident response activities.
Requirements
- Experience working within Defence, Aerospace, MOD, Defence Digital, or other highly regulated environments.
- 5+ years' experience in DevOps, SecDevOps, Platform Engineering, Cloud Security, or Cyber Security Engineering.
- Strong understanding of Secure Software Development Lifecycle (SSDLC) principles and practices.
- Experience implementing and managing CI/CD pipelines using Azure DevOps, GitHub Actions, GitLab CI/CD, Jenkins, or similar tooling.
- Hands-on experience with Infrastructure as Code technologies such as Terraform, Bicep, CloudFormation, or Ansible.
- Experience integrating security tools including SAST, DAST, SCA, container security, secrets management, and vulnerability scanning solutions.
- Strong understanding of cloud security principles across Azure, AWS, or hybrid-cloud environments.
Desirable
- Experience leading DevSecOps teams, defining standards, and mentoring engineers.
- Knowledge of Zero Trust Architecture and secure-by-design delivery frameworks.
- Experience supporting classified or secure government environments.
- Knowledge of NIST, ISO 27001, NCSC, NIS2, or similar security frameworks.
- Experience with threat modelling, security architecture reviews, and cloud security governance.
- Experience implementing SIEM, SOAR, or advanced security observability platforms.
- CISSP, CCSP, Security+, CEH, GSEC, GIAC, or equivalent security certifications.
- Microsoft Azure Security Engineer, AWS Security Specialty, CKA, or CKS certifications.