About the Role
We are seeking a highly skilled Senior DevSecOps Engineer to design, automate, and maintain secure, scalable, and resilient infrastructure and deployment pipelines. You will play a key role in integrating security into development workflows and infrastructure operations across cloud and on-premise environments.
This role requires strong expertise in cloud platforms, infrastructure automation, CI/CD, security engineering, and modern DevSecOps practices. You will work closely with engineering, operations, and security teams to drive automation, reliability, and compliance at scale.
Key Responsibilities
Infrastructure & Automation
- Design and implement automation solutions for deployment, scaling, monitoring, and infrastructure management across cloud and data centre environments.
- Provision and manage virtual machines, databases, containers, and supporting infrastructure for development teams.
- Build and maintain CI/CD pipelines with streamlined release and change management processes.
- Develop scripts and automation tools to support software build, integration, testing, and deployment.
- Automate configuration management across development, QA, and production environments.
- Optimise system reliability, performance, and service availability through monitoring and automation.
- Implement disaster recovery, backup, and business continuity solutions.
- Deploy and manage infrastructure monitoring and observability tools.
Security & Compliance
- Implement security best practices and controls aligned with industry standards and organisational policies.
- Design and maintain secure system architectures, including threat modelling and risk assessments.
- Conduct vulnerability assessments, system hardening, and security troubleshooting.
- Integrate security controls into CI/CD pipelines and cloud-native platforms.
- Support compliance initiatives across regulated and security-sensitive environments.
- Manage secrets, access controls, and zero-trust security practices where applicable.
Operations & Support
- Troubleshoot and resolve infrastructure, platform, and application issues across environments.
- Participate in incident response and on-call support for critical production systems.
- Take ownership of end-to-end infrastructure and security solutions across the organisation.
Requirements
Qualifications & Experience
- Degree or Diploma in Computer Science, Information Technology, Engineering, or a related discipline.
- Strong understanding of SDLC, CI/CD, DevOps, and Test-Driven Development (TDD).
- Experience managing high-availability, high-performance, and secure hybrid cloud environments.
- Proficiency in Shell scripting, YAML, and Infrastructure-as-Code (IaC).
- Experience with Git and modern branching strategies.
- Hands-on experience with cloud platforms such as AWS, Azure, or Google Cloud Platform.
- Experience with automation and provisioning tools such as Terraform, Ansible, Puppet, or Vagrant.
- Strong understanding of containerisation and orchestration technologies including Docker and Kubernetes.
- Familiarity with CNCF ecosystem tools such as Prometheus, Helm, ArgoCD, Istio, Gatekeeper, and Crossplane.
- Experience with monitoring, observability, backup, and disaster recovery solutions.
- Strong troubleshooting and problem-solving skills across infrastructure and application layers.
Security & DevSecOps Expertise
- Experience implementing security controls within CI/CD pipelines and cloud-native architectures.
- Hands-on experience with vulnerability scanning, security assessments, and system hardening.
- Familiarity with enterprise security tools such as HashiCorp Vault, Tenable, HP Fortify, Sonatype Nexus IQ, and AWS security services.
- Strong knowledge of networking concepts including firewalls, subnets, routing, and access controls.
- Experience operating in government, regulated, or high-security environments is an advantage.
Preferred Qualifications
- Security certifications such as CISSP, CISM, CREST, or cloud security certifications.
- Experience driving or supporting DevSecOps transformation initiatives.
- Familiarity with ISO 27001, NIST, CIS Benchmarks, and related security frameworks.
- Experience with API security, secrets management, and service mesh security implementations such as Istio or Linkerd.