Overview
We are seeking a DevSecOps Engineer to support a prominent digital consumer brand in a critical compliance engagement. This role focuses on ensuring compliance with the CAF 4 framework, involving hands-on cloud security remediation and stakeholder reporting primarily within AWS and some involvement with GCP. The selected candidate will work closely with internal teams and third-party suppliers to strengthen security measures and document compliance outcomes efficiently.
Responsibilities
- Assess current security controls and identify necessary remediation to meet CAF 4 compliance objectives.
- Implement changes across AWS infrastructure, including IAM, MFA, network segmentation, and centralised logging.
- Produce clear, audit-ready documentation to support compliance outcomes.
- Collaborate with internal teams and third-party suppliers to validate shared security responsibilities.
- Provide weekly progress updates to senior stakeholders on risks, blockers, and delivery status.
- Focus on supply chain risk, access control, and incident recovery measures.
Requirements
- Strong hands-on experience with securing AWS environments; working knowledge of GCP is advantageous.
- Experience with cyber security and compliance frameworks such as CAF, NIS, ISO 27001, or similar.
- Solid understanding of IAM, MFA, logging, monitoring, backup, and network segmentation.
- Ability to produce technical and compliance documentation for senior stakeholders.
- Comfortable operating in a fast-paced delivery environment with immediate impact.
- Strong stakeholder communication skills are essential.