Overview
We are seeking a Senior DevSecOps Engineer to join a leading tech consultancy for a contract engagement with a high-profile financial services client. This role is primarily focused on hands-on engineering within the Platform team, aiming to integrate security throughout the software development lifecycle and enhance security practices across engineering teams. The ideal candidate will leverage their expertise in DevSecOps, platform security, and cloud security engineering to help shape security engineering initiatives and build effective security patterns.
Responsibilities
- Define and drive a security engineering roadmap embedded within CI/CD pipelines and Infrastructure as Code (IaC).
- Develop and implement repeatable security patterns and lead technical vulnerability triage processes.
- Consult with feature teams on Data Privacy Impact Assessments (DPIAs) and integrate compliance into engineering practices.
- Collaborate with engineering teams and leadership to gain trust and ensure effective security measures.
- Influence stakeholders at various levels from working group to leadership through strong technical knowledge.
Requirements
- Proven experience in DevSecOps, platform, or cloud security engineering.
- Hands-on experience with AWS security in hybrid-cloud and SaaS environments.
- Strong understanding of CI/CD and IaC security integration.
- Ability to write code in Python or a similar language, beyond just scripting.
- Experience with technical vulnerability triage and remediation strategies.
- Familiarity with security frameworks, such as NIST CSF and CSA Critical Controls.
- Experience with zero-trust architecture across both cloud and traditional deployment models.
- Certifications such as AWS Certified Security – Specialty, CEH, CCSP, or CISSP are advantageous.