DevSecOps Engineer
We're working with an established organisation looking to appoint an experienced DevSecOps Engineer to strengthen its Azure deployment and application security capabilities.
This is a hands-on position combining Azure DevOps, cloud infrastructure and application security. You'll take ownership of CI/CD pipelines, Infrastructure-as-Code and security testing, while helping development teams embed secure practices throughout the software delivery lifecycle.
The RoleYou'll be responsible for:
-
Designing and maintaining CI/CD pipelines within Azure DevOps
-
Deploying Azure applications and infrastructure using Terraform
-
Supporting Azure services including App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints and Front Door/WAF
-
Introducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detection
-
Integrating SAST, DAST, dependency and container scanning into development pipelines
-
Conducting web application security testing using Burp Suite, OWASP ZAP or similar tools
-
Identifying and managing vulnerabilities against OWASP Top 10 and CVSS principles
-
Implementing secrets detection, credential rotation and secure Key Vault practices
-
Strengthening software supply-chain security through SBOM generation, dependency scanning and artefact signing
-
Supporting API security testing, threat modelling and third-party penetration tests
-
Configuring Azure-native security tooling, including Defender for Cloud, Azure Policy, Sentinel and Azure Monitor
-
Enforcing identity and access controls across Entra ID, RBAC, Conditional Access and PIM
-
Supporting compliance with frameworks such as Cyber Essentials Plus, ISO 27001 and GDPR
-
Mentoring junior engineers and helping developers adopt secure coding and deployment practices
You'll need:
-
Around three to five years' experience across DevOps, platform engineering or application security
-
Strong hands-on experience with Microsoft Azure and Azure DevOps
-
Proven experience securing web applications in a production environment
-
Practical experience using Burp Suite for application security testing
-
Experience with SonarQube or comparable SAST tooling
-
Strong knowledge of OWASP Top 10, vulnerability management and remediation
-
Experience building repeatable Azure deployments using Terraform
-
Scripting ability with PowerShell, Python or Bash
-
Experience implementing secrets detection and dependency/CVE remediation tooling
-
The confidence to work independently, make risk-based decisions and support junior engineers
Experience with Docker, Kubernetes/AKS, API security testing, threat modelling, SIEM tooling or software supply-chain security would be particularly useful.
Relevant certifications such as AZ-500, AZ-400, Security+, CySA+, CEH or OSCP would also be beneficial, although practical experience is more important.
This is an excellent opportunity for someone who enjoys working across cloud engineering and application security and wants genuine ownership over how secure software is built, tested and released.
Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.
To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.