Instanda Logo

Instanda

DevSecOps Engineer

Posted 2 Days Ago
Be an Early Applicant
London, Greater London, England
Mid level
London, Greater London, England
Mid level
The DevSecOps Engineer will integrate security into the CI/CD pipelines, manage security for infrastructure as code tools, ensure container security, and implement cloud security practices on Azure. Responsibilities include vulnerability management, threat modeling, automated security testing, and collaboration with development and security teams to promote secure coding practices.
The summary above was generated by AI

Description

We are looking for a DevSecOps Engineer to join our growing DevOps Engineering team.

This role isUK based, primarily remote working with some travel required to our London Office. Sponsorship is not available for this role.

What you will do:

  • Security Integration in CI/CD Pipelines: Implement security controls within CI/CD pipelines using automation and best practices, ensuring vulnerabilities are caught early in the development cycle.
  • Infrastructure as Code (IaC) Security: Secure the infrastructure by applying security measures to IaC tools such as Terraform and Ansible.
  • Container Security: Ensure that containers (Docker, Kubernetes) are secured by configuring appropriate policies, scanning for vulnerabilities, and managing runtime security.
  • Cloud Security: Design, implement, and manage security across Azure, focusing on identity management, data protection, and network security.
  • Vulnerability Management: Identify and prioritize vulnerabilities across infrastructure and applications, and collaborate with teams to remediate them in a timely manner.
  • Threat Modelling and Risk Assessment: Perform threat modelling to identify security risks and provide recommendations for mitigation.
  • Monitoring and Incident Response: Develop and maintain monitoring systems and respond to security incidents quickly and effectively.
  • Automated Security Testing: Integrate and manage SAST, DAST, and other security testing tools to identify security issues in code and applications.
  • Compliance and Governance: Develop and manage Azure policies to ensure compliance with security standards and regulations (ISO 27001, SOC 2, GDPR) across our infrastructure.
  • Collaboration: Work closely with development, operations, and security teams to build a culture of security and ensure it is embedded in all phases of the development process.
  • Security Awareness: Provide mentorship and training to teams on secure coding practices, best security practices, and emerging security threats.
  • Security Integration: Integrate Azure Defender and other security tools to enhance our cloud security posture.
Requirements

Essential:

  • Passion for Security
  • Proven experience in a DevSecOps role or similar.
  • Strong understanding of Azure DevOps, CI/CD practices
  • Familiarity with Azure services, including Azure Defender, Azure Monitor, and Azure Policy.
  • Experience with security and compliance scanning tools such as vulnerability scanners, intrusion detection systems, & security information & event management (SIEM) solutions.
  • Knowledge of container management with Azure Container Registry.
  • Experience in SAST, DAST & other techniques to improve code security

Desirable:

  • Proficiency in scripting, preferably with PowerShell.
  • Understanding of DotNet development and deployment pipelines.
  • Experience working with PCI DSS standards (good to have).
Benefits
  • Competitive salary
  • Generous 28 days holiday allowance, in addition to public holidays.
  • For every year of service you complete, we’ll give you an additional days holiday (max. 5 days)
  • One Dynamic Day per month on top of your holiday allowance to spend time doing the things you want to do or simply catching up with life admin.
  • Remote & Hybrid approach varying with the nature of your role.
  • Life cover; income protection and participation in the company pension scheme
  • All employees are included in the company discretionary bonus scheme.
  • £100 per month to put towards wellness activities.
  • Annual learning & development allowance of £1,250 and free access to LinkedIn learning and Microsoft ESI learning platforms

Additional Information:

Our company was built by looking at the world through a different lens and our culture today reflects that by encouraging you to be yourself, speak your mind, and share your opinions. We want people who want to push themselves, be part of something great, and be prepared to challenge if they think there is a better way. Collaboration sits at the heart of how we operate, it has fueled our growth enormously and our aim to be ‘world class’.                                                                                                                                  

We want everyone to be the best they can be throughout our recruitment process; if you require any additional adjustments please let us know. Visit for more information

INSTANDA has an in-house recruitment team, which focuses on sourcing great candidates directly.  INSTANDA does not accept unsolicited resumes from agency or search firm recruiters.  Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired.  When we do use agencies, we have a PSL in place, so please do not contact managers directly.

Top Skills

Ansible
Azure
Docker
Kubernetes
Powershell
Terraform
HQ

Instanda London, England Office

70 Gracechurch Street, Floor 2, London, United Kingdom, EC3V 0XL

Similar Jobs

Be an Early Applicant
6 Days Ago
London, Greater London, England, GBR
568 Employees
Senior level
568 Employees
Senior level
Fashion • Retail • Software
As the Lead DevSecOps Engineer, you will design, secure, and deliver Cloud Landing Zones using AWS, Azure, and GCP, while implementing DevSecOps practices. You will lead a team, mentor junior engineers, collaborate across teams, and ensure effective CI/CD pipelines and Infrastructure as Code (IaC) processes are in place.
Be an Early Applicant
6 Days Ago
London, Greater London, England, GBR
568 Employees
Mid level
568 Employees
Mid level
Fashion • Retail • Software
The DevSecOps Engineer will collaborate with infrastructure and software engineers to ensure the security standards of Cloud Landing Zones and services. Responsibilities include integrating security testing, performing threat assessments, enhancing automated security measures, and maintaining security documentation and compliance.
Be an Early Applicant
15 Days Ago
Reading, Berkshire, England, GBR
26,500 Employees
Senior level
26,500 Employees
Senior level
Fintech • Information Technology • Payments
The Senior DevSecOps Engineer at Visa will develop automation tools for high availability payment processing systems, design scalable components, manage component security, and ensure system stability. Collaboration across teams is essential for troubleshooting and supporting secure coding practices. This role spans both development and security efforts in a hybrid workspace.

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account