DevSecOps Engineer

About the job

About the DevSecOps Engineer role

The DevSecOps Engineer is responsible for developing and maintaining automation, CI/CD pipelines, cloud infrastructure, and security controls that support secure and reliable software delivery. Working closely with development and technical teams, this role manages cloud-native environments, Infrastructure as Code, monitoring and observability, vulnerability management, system hardening, and security architecture while supporting incident response, disaster recovery, and operational reliability across the software development lifecycle.

Key Responsibility:

  • Develop automation capabilities to deploy, manage, monitor, and maintain applications and infrastructure
  • Design and maintain CI/CD pipelines for application deployment and release management
  • Implement infrastructure-as-code and environment automation practices
  • Manage cloud resources and platform services
  • Develop and maintain CI/CD tooling and automation to support software build, testing, integration, and release processes
  • Monitor and optimise platform availability, performance, utilisation, reliability, and operational health
  • Implement security controls and ensure compliance with government security requirements
  • Plan, implement, and monitor system security architecture, including threat and risk assessments
  • Conduct vulnerability assessments, system hardening, security reviews, and remediation activities
  • Implement disaster recovery, backup, and business continuity measures
  • Investigate, troubleshoot, and resolve system, application, and infrastructure issues
  • Collaborate closely with developers to integrate security throughout the software development lifecycle
  • Coordinate and work together with other members of the team

Requirements:

  • Strong understanding of Software Development Lifecycle (SDLC), CI/CD, Test-Driven Development (TDD), and DevSecOps practices
  • Experience designing, deploying, and supporting cloud-native applications and infrastructure on AWS. Experience with GCC environment is advantageous
  • Proficiency in at least two programming/scripting languages:
    • Bash
    • PowerShell
    • Python
    • JavaScript
    • Java
  • Experience with infrastructure-as-code and automation tools such as Terraform, Ansible, or equivalent technologies
  • Experience with containerisation and orchestration technologies including Docker and Kubernetes
  • Experience with source code management, GitLab workflows, and CI/CD platforms
  • Experience implementing monitoring, logging, and observability solutions to support platform reliability and operational excellence
  • Knowledge of application security and cloud security, secure coding practices, and DevSecOps principles
  • Hands-on experience with vulnerability management, security assessments, system hardening, and remediation activities
  • Familiarity with cloud-native and Cloud Native Computing Foundation (CNCF) tools (Prometheus, Helm, ArgoCD, Istio, Gatekeeper, Crossplane)
  • Familiarity with enterprise security and secrets management solutions (HashiCorp Vault, Tenable, Fortify, Sonatype Nexus IQ, AWS security services)
  • Experience with AWS services related to identity and access management, networking, monitoring, container platforms, and security
  • Strong troubleshooting, incident response, and operational support skills
  • Experience working in regulated or government environments is preferred

Search Popup

Help me find…

This will close in 0 seconds