Surrey
£60000 - £80000 per annum
Full time
Ref: 45678 - DevSecOps_1787050644
We're working with an established organisation looking to appoint an experienced DevSecOps Engineer to strengthen its Azure deployment and application security capabilities.
This is a hands-on position combining Azure DevOps, cloud infrastructure and application security. You'll take ownership of CI/CD pipelines, Infrastructure-as-Code and security testing, while helping development teams embed secure practices throughout the software delivery lifecycle.
You'll be responsible for:
Designing and maintaining CI/CD pipelines within Azure DevOps
Deploying Azure applications and infrastructure using Terraform
Supporting Azure services including App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints and Front Door/WAF
Introducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detection
Integrating SAST, DAST, dependency and container scanning into development pipelines
Conducting web application security testing using Burp Suite, OWASP ZAP or similar tools
Identifying and managing vulnerabilities against OWASP Top 10 and CVSS principles
Implementing secrets detection, credential rotation and secure Key Vault practices
Strengthening software supply-chain security through SBOM generation, dependency scanning and artefact signing
Supporting API security testing, threat modelling and third-party penetration tests
Configuring Azure-native security tooling, including Defender for Cloud, Azure Policy, Sentinel and Azure Monitor
Enforcing identity and access controls across Entra ID, RBAC, Conditional Access and PIM
Supporting compliance with frameworks such as Cyber Essentials Plus, ISO 27001 and GDPR
Mentoring junior engineers and helping developers adopt secure coding and deployment practices
You'll need:
Around three to five years' experience across DevOps, platform engineering or application security
Strong hands-on experience with Microsoft Azure and Azure DevOps
Proven experience securing web applications in a production environment
Practical experience using Burp Suite for application security testing
Experience with SonarQube or comparable SAST tooling
Strong knowledge of OWASP Top 10, vulnerability management and remediation
Experience building repeatable Azure deployments using Terraform
Scripting ability with PowerShell, Python or Bash
Experience implementing secrets detection and dependency/CVE remediation tooling
The confidence to work independently, make risk-based decisions and support junior engineers
Experience with Docker, Kubernetes/AKS, API security testing, threat modelling, SIEM tooling or software supply-chain security would be particularly useful.
Relevant certifications such as AZ-500, AZ-400, Security+, CySA+, CEH or OSCP would also be beneficial, although practical experience is more important.
This is an excellent opportunity for someone who enjoys working across cloud engineering and application security and wants genuine ownership over how secure software is built, tested and released.
Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.
To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
Recruitment Consultant
Share job