
DEVSECOPS SECURITY ENGINEER – 100K Chatham, England
Job description
DevSecOps Security Engineer – 100k
A highly reputable and market leading financial corporation is currently hiring a DevSecOps Security Engineer who will contribute towards the design and implementation of a greenfield cloud security platform. The ideal candidate will have the experience and knowledge to lead the detailed security design and implementation activities for foundational cloud services such as compute, storage, and networking as well as the integration points with existing Group Security services and processes such as monitoring, alerting and incident response.
This role is paying up to 100k+ 25% Bonus with hybrid working (2 day PW in office) to be based in Chatham or Wolverhampton.
- Scope, design and build secure Azure cloud services to support the Modernisation programme and deliver a scalable and flexible cloud security architecture
- Implement secure system architectures through the application of regulations, policies, standards and procedures to meet user needs while managing business and security risks.
- Develop, test, and deliver Security Policy as code for a variety of Public Cloud compute services and Container platforms leveraging native services.
- Understand industry standard controls such as CIS/NIST/GDPR/ISO/CSA CCM to deliver compliant solutions through appropriate adoption and configuration of key controls.
- Working to deliver leading edge solutions in identity management, network and infrastructure protection, cloud security, security monitoring, network segregation etc.
- Working closely with application development teams to deliver secure coding platforms and implement product feature pipelines and integration with various SAST, SCA and DAST tools.
- Utilise DevSecOps practices to implement security and compliance policies-as-code
- Solid experience in a Cloud Infrastructure Engineering/platform Engineer/Security Engineer role, deploying and maintaining multi-cloud foundation services (aka Landing zone) and/or container orchestrator platforms
- SIEM & SOAR
- Core foundational security services of cloud providers
- Provisioning Security policy as Code (IAC) tools such as Terraform, CloudFormation and adapt secure code practices and guidelines
- Good level of experience of at least one of programming languages such as Python, Go
- Setting up and managing container security in platforms such as Kubernetes
- Key management tools such as Azure Key Vault or cloud based KMS and PKI
- Integrating CI/CD pipelines for the underlying cloud infrastructure platform and/or the landing zone services with Security tools
- Solid experience in integrating security testing tools such as Veracode, InsightAppSec, Trivy, Checkov, etc.
- Identity and Access Management (Azure AD, RBAC, Identity Protection, PIM, SSO)
- Network knowledge (next-gen firewalls, Layer 3 – 7 security, edge security, TLS/mTLS
- 100k
- Up to 25% Bonus
- Work from home options
- Flexible working
- 30 Days Holiday
- Medical Cover
- Life Cover
- Pension (up to 8% employer contribution)
DevSecOps Security Engineer – 100k
