Senior DevSecOps Engineer

Senior DevSecOps Engineer

Temporary 60000 - 70000 £ / year (est.) Home office (partial)
Alexander Mann Solutions - Public Sector Resourcing

At a Glance

  • Tasks: Manage and improve CI/CD pipelines, ensuring security in software development.
  • Company: Join the Ministry of Justice, making a real difference in public safety.
  • Benefits: Hybrid working, competitive pay, and the chance to impact justice reform.
  • Other info: Opportunities for growth in a supportive and inclusive environment.
  • Why this job: Be part of a mission-driven team enhancing security in the justice system.
  • Qualifications: Experience in DevSecOps and a passion for secure software practices.

The predicted salary is between 60000 - 70000 £ per year.

On behalf of The Ministry of Justice we are looking for a Senior DevSecOps Engineer (Inside IR35) for a 6 month contract. Hybrid working based in any UK MOJ office.

The Ministry of Justice (MoJ) priorities include improving public safety and reducing reoffending by reforming prisons, probation and youth justice, and building a justice system which makes access to justice swifter and more certain for all citizens whatever their background. Project professionals in the MoJ help to improve the government's ability to protect the public and reduce reoffending, and to provide a more effective, transparent and responsive criminal justice system for victims and the public.

This role sits within The AppSec Team within the Office of the CTO. Part of their responsibility is to help teams build secure pipelines and automation security testing.

As a Senior DevSecOps Engineer your main responsibilities will be to:

  • Manage, maintain, and continuously improve centralised CI/CD pipelines for SCA, SAST, and DAST security scanning across engineering teams.
  • Collaborate with ALB and internal stakeholders to define, implement, and enforce organisation-wide security engineering standards and best practices.
  • Support the identification, triage, and mitigation of vulnerabilities across the organisation's platforms, applications, and infrastructure.
  • Provide technical guidance to engineering teams to ensure secure development and deployment practices are embedded within delivery pipelines.
  • Monitor and respond to security findings generated by automated tools, ensuring timely remediation and risk reduction.
  • Stay up to date with emerging security vulnerabilities, mitigations, Indicators of Compromise (IoCs), and Proofs of Concept (PoCs), translating relevant intelligence into actionable improvements within the DevOps and security ecosystem.

Essential:

  • An active SC Clearance is an essential requirement for this role, as a minimum you must be willing & eligible to undergo checks.
  • Proven experience implementing secure-by-design principles across engineering teams, aligned to enterprise security standards, policies, and frameworks.
  • Strong hands-on expertise with DevSecOps practices, including embedding security controls within CI/CD pipelines (e.g. SAST, DAST, dependency scanning, IaC scanning, secrets detection).
  • Demonstrated ability to enable secure delivery of cloud-native services, with solid understanding of major cloud platforms and enterprise security architectures.
  • Experience leading threat modelling and cyber risk assessments, with the ability to identify, evaluate, and manage risks in line with organisational risk appetite.
  • Working knowledge of security assurance activities, such as Infrastructure/IT Health Checks (ITHCs), and a track record of driving remediation and improving security posture.
  • Experience collaborating with engineering and security operations (SOC) teams to implement effective logging, monitoring, and alerting for security events.
  • Strong understanding of vulnerability management processes, including triage, prioritisation, remediation coordination, and validation of fixes across systems.
  • Ability to develop and maintain reusable security standards, patterns, and guidance, enabling scalable and consistent adoption across multiple teams.
  • Excellent stakeholder engagement and influencing skills, with the ability to work across multidisciplinary teams and functions.
  • Passion for promoting a strong security culture, including mentoring engineers and sharing best practices within wider cyber and digital communities.

Please be aware that this role can only be worked within the UK and not Overseas.

Disability Confident: As a member of the Disability Confident Scheme, MOJ guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. This scheme encourages candidates with a disability and/or neurodivergence to apply.

Armed Forces Covenant: The Ministry of Justice guarantees to interview veterans or spouses/partners of military personnel who meet all the essential criteria for the vacancy. In cases where we have a high volume of ex-military candidates/military spouses or partners, who meet all the essential criteria, we will interview the best candidates from within that group.

In applying for this role, you acknowledge the following: this role falls in scope of the Off Payroll Working in the Public Sector legislation. Any rates of payment quoted will reflect the gross rate per day for the assignment and will be subject to appropriate taxes and statutory costs. As such the payment to the intermediary and your income resulting from this contract will be different.

Senior DevSecOps Engineer employer: Alexander Mann Solutions - Public Sector Resourcing

The Ministry of Justice is an exceptional employer, offering a unique opportunity to contribute to the improvement of public safety and justice in the UK. With a strong commitment to employee growth, a collaborative work culture, and a focus on security best practices, the MoJ provides a supportive environment for professionals to thrive while making a meaningful impact. The hybrid working model allows for flexibility, ensuring that employees can balance their professional and personal lives effectively.

Alexander Mann Solutions - Public Sector Resourcing

Contact Details:

Alexander Mann Solutions - Public Sector Resourcing Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior DevSecOps Engineer

Tip Number 1

Network like a pro! Reach out to your connections in the industry, especially those who might have insights into the Ministry of Justice. A friendly chat can sometimes lead to opportunities that aren’t even advertised.

Tip Number 2

Prepare for the interview by brushing up on your technical skills and security practices. Make sure you can confidently discuss your experience with CI/CD pipelines and security scanning tools, as these will be key topics.

Tip Number 3

Show your passion for security! During interviews, share examples of how you've promoted a strong security culture in previous roles. This will demonstrate your commitment to the field and align with the MoJ's priorities.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we’re here to support you every step of the way!

We think you need these skills to ace Senior DevSecOps Engineer

SC Clearance
DevSecOps Practices
CI/CD Pipeline Management
SAST
DAST
Dependency Scanning
Infrastructure as Code (IaC) Scanning

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Senior DevSecOps Engineer role. Highlight your experience with CI/CD pipelines, security practices, and any relevant projects that showcase your skills in line with the job description.

Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for this role. Mention your passion for security culture and how your previous experiences align with the Ministry of Justice's goals. Keep it engaging and personal!

Showcase Your Security Knowledge:In your application, don’t forget to mention your hands-on expertise with DevSecOps practices and any relevant certifications. We want to see how you can contribute to improving security standards and practices within the organisation.

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates from us!

How to prepare for a job interview at Alexander Mann Solutions - Public Sector Resourcing

Know Your Stuff

Make sure you brush up on your DevSecOps knowledge, especially around CI/CD pipelines and security practices. Be ready to discuss how you've implemented secure-by-design principles in past roles, as this will show you're the right fit for the Ministry of Justice's needs.

Showcase Your Experience

Prepare specific examples of your hands-on experience with SAST, DAST, and vulnerability management processes. Highlight any successful projects where you collaborated with engineering teams to improve security posture, as this will demonstrate your ability to work effectively within multidisciplinary teams.

Stay Current

Keep yourself updated on the latest security vulnerabilities and trends. Being able to discuss recent incidents or emerging threats will not only impress your interviewers but also show your passion for promoting a strong security culture.

Engage and Influence

Think about how you can engage with stakeholders and influence best practices in security. Prepare to share your thoughts on mentoring engineers and fostering a security-first mindset within teams, as this aligns perfectly with the Ministry's goals.