At a Glance
- Tasks: Lead application and cloud security in a modern Azure-first environment.
- Company: Join a forward-thinking tech company focused on product security.
- Benefits: Enjoy hybrid working, competitive salary, and opportunities for professional growth.
- Why this job: Make a real impact by embedding security into innovative products.
- Qualifications: Experience in software development and strong knowledge of Azure required.
- Other info: Collaborative culture with a focus on continuous learning and improvement.
The predicted salary is between 36000 - 60000 Β£ per year.
We're looking for a hands-on DevSecOps Engineer to take ownership of application and cloud security across a modern, Azure-first product environment. This is a product-focused security role, sitting at the intersection of development, DevOps and security, helping teams understand why vulnerabilities exist and how to fix them properly.
The foundations are already strong, with regular external penetration testing, positive audit outcomes, and mature security tooling in place. Your role is to raise the bar further, embedding security deeper into how products are built, configured and deployed.
You'll be the subject matter owner for DevSecOps, working closely with developers, DevOps and product teams to improve security posture through insight, automation and education.
Responsibilities- Act as the DevSecOps lead, owning application and cloud security practices across the business.
- Analyse outputs from SAST and DAST tools (e.g. Snyk, BrightSec), understanding vulnerabilities at a low level and advising development teams on remediation.
- Work closely with DevOps to ensure secure configuration and deployment within Azure (including Azure Front Door, WAF, Defender for Cloud, Sentinel).
- Support and interpret results from ITHC (UK Government-standard) penetration tests, ensuring findings are understood and remediated across product and platform teams.
- Embed security controls and testing into CI/CD pipelines, improving automation and consistency.
- Help educate and uplift DevOps and engineering teams on secure practices where needed.
- Collaborate with external security partners, audits and penetration testing providers.
- Investigate and support resolution of security issues raised via customers or automated alerts.
- Provide security input into customer discussions alongside sales and consultancy teams.
- Comfortable operating as a solo SME, owning the subject, partnering with the business and third parties.
- Experienced with working in a software house and product-led environment.
- Strong background and understanding of Azure.
- Ability to share knowledge and educate the wider team on best practices.
- Ideally with a background who has tight security principles.
Glasgow based office, hybrid working with minimum 2x office days per week. Full UK right to work required as successful candidate will be taken through clearance checking.
DevSecOps Engineer in Glasgow employer: Big Red Recruitment
Contact Detail:
Big Red Recruitment Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land DevSecOps Engineer in Glasgow
β¨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even local tech events. You never know who might be looking for a DevSecOps Engineer just like you!
β¨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to Azure and security practices. This gives potential employers a taste of what you can do and how you tackle real-world problems.
β¨Tip Number 3
Prepare for interviews by brushing up on common DevSecOps scenarios. Be ready to discuss how you've handled vulnerabilities or improved security in past roles. We want to see your thought process and how you can elevate our security game!
β¨Tip Number 4
Donβt forget to apply through our website! Itβs the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace DevSecOps Engineer in Glasgow
Some tips for your application π«‘
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the DevSecOps role. Highlight your experience with Azure, security practices, and any relevant tools you've used. We want to see how you can contribute to our team!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about DevSecOps and how your background makes you a perfect fit for us. Donβt forget to mention specific projects or achievements that showcase your expertise.
Showcase Your Problem-Solving Skills: In your application, give examples of how you've tackled security vulnerabilities in the past. We love seeing candidates who can think critically and provide solutions, so share those stories that demonstrate your hands-on experience!
Apply Through Our Website: We encourage you to apply directly through our website. Itβs the best way for us to receive your application and ensures youβre considered for the role. Plus, it shows youβre keen on joining our awesome team at StudySmarter!
How to prepare for a job interview at Big Red Recruitment
β¨Know Your Tools
Familiarise yourself with the SAST and DAST tools mentioned in the job description, like Snyk and BrightSec. Be ready to discuss how you've used these tools in past roles and how they can help identify and remediate vulnerabilities.
β¨Understand Azure Security
Since this role is Azure-focused, brush up on Azure security features such as Azure Front Door, WAF, and Defender for Cloud. Prepare to explain how you would implement secure configurations and deployments within Azure.
β¨Showcase Your Collaboration Skills
This position requires working closely with various teams. Think of examples where you've successfully collaborated with developers and DevOps teams to improve security practices. Highlight your ability to educate others on security principles.
β¨Prepare for Scenario Questions
Expect scenario-based questions that test your problem-solving skills in real-world situations. Practice articulating how you would handle security issues raised by customers or alerts, and how you would ensure findings from penetration tests are remediated effectively.