DevSecOps Engineer AI
Own the secure engineering and automation layer for the AI platform. This role makes releases controlled, repeatable and auditable through GitHub, CI/CD, Terraform, GitOps, OPA/Rego, code scanning, security gates and release/change evidence.
Core responsibilities- Design, maintain and troubleshoot secure CI/CD pipelines and GitHub workflows.
- Maintain branch protection, pull request checks, required approvals and deployment controls.
- Build and maintain Terraform / Infrastructure-as-Code modules and GitOps deployment patterns.
- Integrate OPA/Rego policy-as-code into CI/CD for pre-deployment guardrails.
- Implement and operate code scanning: SAST, dependency, secret, IaC and container scanning where applicable.
- Ensure critical/high findings block merge or deployment unless formally excepted.
- Support release management: environment consistency, promotion, rollback planning and post-release validation.
- Track security findings, policy exceptions and remediation evidence with clear reporting.
- Support repository standardisation, pipeline templates, deployment automation and audit evidence.
- Work closely with Cloud Engineer on Azure platform patterns and operational handover.
- Strong DevOps / DevSecOps engineering experience in cloud environments.
- Strong GitHub, CI/CD, branch protection, pull request governance and deployment automation skills.
- Strong Terraform, Infrastructure-as-Code and GitOps capability.
- Experience with OPA/Rego or comparable policy-as-code tooling.
- Good understanding of secure software delivery and cloud security controls.
- Working knowledge of SAST, dependency scanning, secret scanning, IaC scanning and container scanning.
- Ability to troubleshoot pipelines, deployments, infrastructure, security gates and access issues.
- Good documentation discipline and ability to turn controls into repeatable standards.
- Has built or standardised CI/CD pipelines and deployment controls in a regulated enterprise.
- Can explain Terraform state, environments, approval gates, rollback and drift control.
- Can explain how code/security scanning should work in pull requests and release pipelines.
- Has implemented policy-as-code or equivalent automated governance, not just written manual standards.