Overview
The Lead DevSecOps Engineer will play a critical role in driving the technical delivery of CI/CD pipelines and integrated security tooling for a leading Defence and National Security IT provider. Working closely with a Scrum team, the contractor will contribute to the technical implementation, design activities, and assurance of DevSecOps practices while mentoring junior engineers. This on-site position requires strong experience in software development and DevSecOps tooling, particularly within security-focused engineering processes.
Responsibilities
- Own the technical implementation, delivery, and assurance of DevSecOps tooling and processes.
- Contribute to technical implementation and design activities, supporting decisions and assessing design options.
- Develop and document reusable automation scripts and Infrastructure as Code artifacts.
- Write build automation in Ansible and Infrastructure as Code in Terraform while configuring CI/CD pipelines.
- Advise end users on the use of DevSecOps technologies and secure engineering processes.
- Collaborate within a Scrum team to define and prioritize tasks, as well as identify risks and dependencies.
- Ensure DevSecOps implementation aligns with business outcomes and security requirements.
- Mentor junior engineers and contribute to planning and progress reporting.
Requirements
- Must hold UK Sole National with active DV Clearance.
- Significant experience with CI/CD pipelines, preferably using Azure DevOps.
- Proficient in Infrastructure as Code tools such as Terraform and Ansible.
- Experienced with SCA, IAST, and DAST tools like Black Duck, Coverity, Codesight, JFrog, or Snyk.
- Familiarity with automated test tools, ideally Selenium or Robot Framework.
- Knowledge of secure secrets management, preferably with Azure DevOps and HashiCorp Vault.
- Experience with version control using Git.
- Strong background in software development, capable across both Windows and Linux operating systems.