DevSecOps Engineer (Associate Consultant / Consultant)
The DevSecOps Engineer is the primary technical delivery resource for the AI Platform and supports the full software development lifecycle, including AI pipelines, backend services, infrastructure provisioning, CI/CD automation, security controls and system integrations.
The DevSecOps Engineer shall demonstrate proficiency in:
a) developing agentic AI and document-processing solutions using approved Government AI services;
b) building and operating cloud-native solutions on AWS GCC;
c) developing secure APIs and enterprise integrations;
d) implementing DevSecOps pipelines, infrastructure-as-code, monitoring and security controls;
e) developing systems that handle legally sensitive and personal data; and
f) working effectively in Agile, multidisciplinary delivery teams.
g) Experience with OutSystems Platform integration will be advantageous.
Responsibilities
• Work with Business owner, business analyst and solution architect to translate user stories into technical requirements;
• Develop and maintain API integrations with STREAM, CAMP and any other required systems;
• Design and build the agentic AI pipeline, including LLM API integration, prompt engineering, skill and context design, structured output schemas, confidence scoring, and error handling;
• Work with Software Quality Engineer to develop automation and processes to deploy, manage, scale and monitor applications in data centres and cloud environments;
• Troubleshoot and resolve system and application issues, participating in on-call escalations for critical incidents;
• Take ownership of end-to-end infrastructure and security solutions across the products and relevant systems;
• Deploy and manage monitoring tools to track infrastructure performance, utilisation and health;
• Implement configuration management systems for business continuity and automate disaster recovery measures;
• Ensure provision of virtual machines, databases, application containers and licenses for development teams;
• Configure and maintain CI/CD pipelines, incorporating streamlined change management and release processes;
• Develop scripts and automation tools to support software build, integration and deployment across development and production environments;
• Automate the configuration management of development, QA, and production workloads;
• Design, build, optimise and monitor automation systems to identify bottlenecks and maximise service availability;
• Implement security practices that comply with industry standards to protect MinLaw's data and infrastructure;
• Plan, implement and monitor system security architecture, including threat and risk assessments;
• Perform security checks, such as vulnerability assessments and system hardening, and troubleshoot security incidents; and
• Apply secure configurations and best practices when implementing security controls in infrastructure and applications
Required Experience & Skills
Mandatory
• Degree or diploma in Computer Science, Computer or Electronics Engineering, IT or related disciplines.
• Passion for automation, standardisation, and best practices in infrastructure and security.
• Strong understanding of the Software Development Life Cycle (SDLC), Test-Driven Development (TDD), Continuous Integration (CI), and Continuous Delivery (CD).
• Track record in agentic AI system design with multi-agent pipeline, Bedrock AgentCore, orchestration and MCP Server, RAG knowledge base, HITL architecture.
• Experience in regulatory or compliance contexts where agent outputs must be accurate, auditable and structured for legal decision-makers is a significant advantage.
• Experience working with high availability, high performance and high-security multi-data centre systems and hybrid cloud environments.
• Proficiency in at PowerShell, Python.
• Experience with Git and modern branching workflows.
• Strong understanding of container technologies (Docker, Kubernetes).
• Experience with infrastructure monitoring and observability tools.
• Strong ability to troubleshoot complex issues across system resources and application stacks.
• Experience with CI/CD pipelines (GitHub Actions, GitLab CI).
• Experience with disaster recovery planning, system backup, and restore processes.
• Knowledge of RPM-based software packaging and deployment;
• Experience implementing security controls within CI/CD pipelines and cloud-native architectures.
• Hands-on experience with security assessments, vulnerability scanning and system hardening.
• Strong understanding of network infrastructure, including firewalls, subnets, routing and access controls.
• Experience performing security assessments in government or highly regulated environments.
Added advantage
• Security certifications such as CREST, CISSP, CISM or relevant cloud security credentials.
• Experience working in an organisation that successfully implemented DevSecOps transformation.
• Hands-on experience with API security, secrets management and zero-trust architectures.
• Experience developing and deploying systems on GCC.
• Experience building on OutSystems Platform and/or experience building applications designed to operate as part of a larger shared platform.
• Legal regulatory domain familiarity: Contextual knowledge on legal, enforcement or insolvency workflows to better understand how users interact with the system and how it should help them.
Skill Level:
• Associate Consultant to Consultant
Skills
- Agentic AI
- Agile
- AI
- API
- Api Security
- Automation
- AWS
- CI/CD
- Cism
- Cissp
- Cloud
- Cloud Native
- Cloud Security
- DevSecOps
- Docker
- Firewall
- Git
- GitHub
- GitHub Actions
- GitLab
- Infrastructure as Code
- Kubernetes
- LLM
- MCP
- Observability
- PowerShell
- Prompt Engineering
- Python
- SDLC
- Secrets Management
- TDD
- User Stories
- Vulnerability Scanning
- Zero Trust
