At a Glance
- Tasks: Define security standards and guide teams in a greenfield mobile and web application build.
- Company: Join a forward-thinking company focused on cloud security and innovative solutions.
- Benefits: Flexible remote work, competitive salary, and opportunities for professional growth.
- Why this job: Make a real impact on security governance in a dynamic, regulated environment.
- Qualifications: Strong DevSecOps experience, cloud security knowledge, and excellent communication skills.
- Other info: Collaborate with engineering teams and influence best practices in a supportive culture.
The predicted salary is between 48000 - 72000 £ per year.
We are seeking a Senior DevSecOps Consultant to support a greenfield mobile and web application build in a regulated environment. There is flexibility for the large majority of the role to be remote with occasional days in the office for key sessions. This role focuses on security governance, architecture guidance and assurance across Azure, AWS, Kubernetes and SaaS platforms. You will define security standards, guide engineering teams on best practice, and ensure solutions meet Cyber Essentials Plus, ISO 27001 and Zero Trust requirements. This is not a BAU ops role—you’ll act as the bridge between engineering and governance to ensure secure delivery from day one.
What You’ll Be Doing
- Define and maintain multi-cloud security standards and reference blueprints
- Own security architecture patterns and contribute to HLDs, LLDs, threat models and risk assessments
- Experience in CI/CD Pipelines
- Set assurance and evidence requirements for internal teams and third-party suppliers
- Establish policy-as-code standards, including exception handling and risk ownership
- Define identity and access controls (Entra ID Conditional Access, MFA, PIM, AWS IAM federation)
- Govern SaaS security onboarding (SSO, OAuth, DLP, vendor assessments)
- Ensure solutions align with regulatory and audit requirements
- Educate and influence teams through clear guidance, reviews and security clinics
What We’re Looking For
- Strong DevSecOps / Cloud Security experience across Azure
- Background in regulated environments (CE+, ISO 27001, similar frameworks)
- Solid understanding of IaaS, PaaS and SaaS security risks
- Experience working on greenfield web and mobile application builds
- Excellent communication skills and ability to influence engineering teams
- Security or cloud certifications (AZ-500, SC-100, SC-200, AZ-700, AWS Security Specialty, CISSP)
- Experience with architecture governance or blueprint catalogues
- Working knowledge of Kubernetes / container security (AKS/EKS)
- Hands-on involvement may be required for validation and assurance: Azure: Policy, Defender for Cloud, Entra ID, PIM; AWS: Control Tower, SCPs, Security Hub, GuardDuty, IAM; Security & Monitoring: Microsoft Sentinel (KQL), Defender XDR
If this sounds of interest please send your CV for review.
DevSecOps Consultant - Azure - Outside IR35 in London employer: Experis UK
Contact Detail:
Experis UK Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land DevSecOps Consultant - Azure - Outside IR35 in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the DevSecOps space, especially those who work with Azure or in regulated environments. A friendly chat can lead to insider info about job openings that aren't even advertised yet.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects related to security governance and cloud architecture. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on your knowledge of Cyber Essentials Plus, ISO 27001, and Zero Trust principles. Be ready to discuss how you've applied these in past roles, as this will demonstrate your expertise and fit for the position.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take the initiative to connect directly with us.
We think you need these skills to ace DevSecOps Consultant - Azure - Outside IR35 in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that match the job description. Highlight your DevSecOps and cloud security experience, especially in Azure, to show us you’re the right fit for this role.
Showcase Relevant Projects: If you've worked on greenfield mobile or web applications, let us know! Share specific examples of how you’ve defined security standards or contributed to architecture guidance in regulated environments.
Be Clear and Concise: When writing your application, keep it straightforward. Use clear language to describe your experiences and how they relate to the responsibilities listed in the job description. We appreciate brevity!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss any important updates from our team.
How to prepare for a job interview at Experis UK
✨Know Your Tech Inside Out
Make sure you’re well-versed in Azure, AWS, Kubernetes, and the specific security frameworks mentioned in the job description. Brush up on your knowledge of Cyber Essentials Plus, ISO 27001, and Zero Trust principles. Being able to discuss these topics confidently will show that you’re not just familiar with them, but that you can apply them in a real-world context.
✨Prepare for Scenario-Based Questions
Expect questions that ask you to solve hypothetical problems related to security governance and architecture. Think about past experiences where you’ve defined security standards or guided teams through best practices. Use the STAR method (Situation, Task, Action, Result) to structure your answers clearly and effectively.
✨Showcase Your Communication Skills
Since this role involves influencing engineering teams, it’s crucial to demonstrate your communication skills during the interview. Practice explaining complex security concepts in simple terms. You might even want to prepare a few examples of how you've successfully educated teams in the past.
✨Ask Insightful Questions
At the end of the interview, don’t forget to ask questions that show your interest in the role and the company. Inquire about their current security challenges or how they approach security governance in their projects. This not only shows your enthusiasm but also helps you gauge if the company is the right fit for you.