At a Glance
- Tasks: Lead application and cloud security in a modern Azure-first environment.
- Company: Join a forward-thinking tech company focused on product security.
- Benefits: Competitive salary, hybrid working, and comprehensive benefits package.
- Why this job: Make a real impact by embedding security into innovative products.
- Qualifications: Experience in DevSecOps, Azure, and strong security principles required.
- Other info: Dynamic role with opportunities for professional growth and collaboration.
We're looking for a hands-on DevSecOps Engineer to take ownership of application and cloud security across a modern, Azure-first product environment. This is a product-focused security role, sitting at the intersection of development, DevOps and security, helping teams understand why vulnerabilities exist and how to fix them properly.
The foundations are already strong, with regular external penetration testing, positive audit outcomes, and mature security tooling in place. Your role is to raise the bar further, embedding security deeper into how products are built, configured and deployed. You'll be the subject matter owner for DevSecOps, working closely with developers, DevOps and product teams to improve security posture through insight, automation and education.
The role:
- Act as the DevSecOps lead, owning application and cloud security practices across the business.
- Analyse outputs from SAST and DAST tools (e.g. Snyk, BrightSec), understanding vulnerabilities at a low level and advising development teams on remediation.
- Work closely with DevOps to ensure secure configuration and deployment within Azure (including Azure Front Door, WAF, Defender for Cloud, Sentinel).
- Support and interpret results from ITHC (UK Government-standard) penetration tests, ensuring findings are understood and remediated across product and platform teams.
- Embed security controls and testing into CI/CD pipelines, improving automation and consistency.
- Help educate and uplift DevOps and engineering teams on secure practices where needed.
- Collaborate with external security partners, audits and penetration testing providers.
- Investigate and support resolution of security issues raised via customers or automated alerts.
- Provide security input into customer discussions alongside sales and consultancy teams.
About you:
- Comfortable operating as a solo SME, owning the subject, partnering with the business and third parties.
- Experienced with working in a software house and product-led environment.
- Strong background and understanding of Azure.
- Ability to share knowledge and educate the wider team on best practices.
- Ideally with a background who has tight security principles.
- Full UK right to work required without restrictions, successful candidate will be taken through clearance checking.
Nottingham based office, hybrid working with minimum 2x office days per week. Salary £60,000 - £65,000 + benefits. Permanent opportunity.
DevSecOps Engineer in Nottingham employer: Big Red Recruitment Midlands Limited
Contact Detail:
Big Red Recruitment Midlands Limited Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land DevSecOps Engineer in Nottingham
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at local meetups. We all know that sometimes it’s not just what you know, but who you know that can help you land that DevSecOps role.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects and contributions to security practices. We want to see how you’ve tackled vulnerabilities and improved security in real-world scenarios.
✨Tip Number 3
Prepare for those interviews! Brush up on common DevSecOps questions and be ready to discuss your experience with Azure and security tools. We recommend practising with a friend or using mock interview platforms to boost your confidence.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace DevSecOps Engineer in Nottingham
Some tips for your application 🫡
Read the Job Description Thoroughly: Before you start your application, take a good look at the job description. We want to see that you understand what we're looking for in a DevSecOps Engineer, so make sure you highlight relevant experience and skills that match our needs.
Showcase Your Technical Skills: When writing your application, don’t hold back on showcasing your technical expertise. Mention specific tools and technologies you've worked with, especially those related to Azure and security practices. We love seeing how you can contribute to our product-focused environment!
Be Yourself: We’re all about authenticity here at StudySmarter. Let your personality shine through in your application. Share your passion for security and how you’ve tackled challenges in the past. We want to know the real you!
Apply Through Our Website: Make sure to submit your application through our website. It’s the best way for us to keep track of your application and ensure it gets the attention it deserves. Plus, it shows you’re serious about joining our team!
How to prepare for a job interview at Big Red Recruitment Midlands Limited
✨Know Your Tools
Familiarise yourself with the SAST and DAST tools mentioned in the job description, like Snyk and BrightSec. Be ready to discuss how you've used these tools in the past and how they can help identify and remediate vulnerabilities.
✨Understand Azure Security
Since this role is Azure-focused, brush up on Azure security practices, including Azure Front Door, WAF, and Defender for Cloud. Show that you can not only use these tools but also explain their importance in securing applications and cloud environments.
✨Emphasise Collaboration
This position requires working closely with development and DevOps teams. Prepare examples of how you've successfully collaborated with cross-functional teams in the past to improve security practices and outcomes.
✨Be Ready to Educate
The role involves uplifting teams on secure practices. Think of ways you've educated others about security in previous roles and be prepared to share those experiences. Highlight your ability to communicate complex security concepts in an understandable way.