At a Glance
- Tasks: Design and maintain secure cloud infrastructure while embedding security in the software delivery lifecycle.
- Company: Join Immediate, home to beloved UK brands like Radio Times and Good Food.
- Benefits: Enjoy 25 days holiday, flexible working, and tailored training opportunities.
- Why this job: Make a real impact on security and automation in a dynamic tech environment.
- Qualifications: Experience in cloud infrastructure, CI/CD automation, and security frameworks required.
- Other info: Be part of a diverse team with a focus on growth and well-being.
The predicted salary is between 57600 - 84000 £ per year.
Immediate is home to some of the biggest and most loved consumer brands in the UK, including Radio Times, Good Food and BBC Gardeners World magazine. Our trusted, quality content reaches millions of people a month across digital, print, video, podcasts, apps and live events. We’re the destination for people looking to get more from the things they love. We’re here to inspire, fuel, encourage and educate.
About the role
We are seeking a DevSecOps Engineer to join our growing Platforms & Security team. This is a hands‑on role for someone passionate about automation, cloud operations, and security by design. You’ll be responsible for ensuring our platforms, products, and infrastructure are secure, resilient, and scalable while working closely with developers, QA, and product teams. You’ll combine DevOps best practices with modern security engineering approaches to embed security throughout the software delivery lifecycle, strengthen our cloud infrastructure, and proactively protect our customers’ data.
As a DevSecOps Engineer you will:
- Design, build, and maintain secure and scalable infrastructure in AWS using Terraform, Kubernetes, and Docker.
- Embed security into the CI/CD pipeline (Jenkins, GitHub Actions, CodePipeline) including SAST/DAST and dependency scanning.
- Collaborate with developers and product teams to promote DevSecOps practices, threat modelling, and secure coding standards.
- Conduct security assessments of applications, services, and infrastructure, identifying vulnerabilities and recommending remediation.
- Operate, tune, and extend monitoring, logging, and alerting systems for both performance and security.
- Manage DNS, CDN, caching, firewalls, load balancers, and WAFs to ensure secure and performant web delivery.
- Respond to and resolve security incidents and platform issues, driving continuous improvement and automation of responses.
- Keep documentation current, including runbooks, incident playbooks, and security procedures.
- Stay ahead of industry trends, emerging threats, and new DevSecOps tools.
Skills and experience
- Strong background in cloud infrastructure (AWS preferred: EC2, Lambda, RDS, Route53, ELBs, EKS).
- Proven experience with CI/CD automation and infrastructure-as-code (Terraform, Ansible, Jenkins, Git/GitHub).
- Proficiency in containerisation (Docker, Kubernetes) and managing production workloads.
- Solid understanding of security frameworks (CIS, OWASP) and common vulnerabilities (OWASP Top 10, misconfigurations, supply chain risks).
- Experience with application and infrastructure monitoring (e.g. Prometheus, Grafana, ELK, CloudWatch).
- Knowledge of Linux‑based systems (LAMP stack, Nginx, Varnish, MySQL/Postgres, Mongo) with performance tuning and hardening experience.
- Strong grasp of networking and security protocols (TCP/IP, SSL/TLS, DNS, NAT, firewalls, load balancers, WAFs).
- Familiarity with code security tools (SAST, DAST, dependency scanners) and integrating them into pipelines.
- Excellent problem‑solving, communication, and cross‑team collaboration skills.
- Disaster recovery process and GDPR.
Desired
- Knowledge on PCI DSS.
A relaxed working environment with regular socials including a summer festival. Supportive well‑being initiatives and benefits, talks & workshops, and Mental Health First Aiders & Champions. 25 days holiday plus a day for your birthday. Our offices will be closed between Christmas and New Year’s which are in addition to your annual entitlement. Tailored training and development through both our in‑house learning platform and LinkedIn Learning. A progressive and transparent culture focused on your development. Flexible / hybrid working plus early finish Fridays. Cycle to work scheme. Enhanced Family Policies including paternity, adoption and surrogacy leave. We also provide a pregnancy loss, fertility, and carers policy. Competitive pension plans and Life Assurance. A newly renovated modern office with lots of collaborative spaces.
People are at the heart of our business and creating a diverse and inclusive working environment is extremely important to us. Immediate is an equal opportunities employer. We’ll never treat anyone less favourably because of their sex, gender reassignment, pregnancy and maternity, marital/civil partnerships, sexual orientation, race, nationality, ethnic origin, age, religion or belief or disability. We’re also committed to supporting applications from those who are returning to work following a career break, maternity leave or caring responsibilities. Immediate is a place where you can grow, be supported, and make a difference.
DevSecOps Engineer in City of London employer: Immediate Live Co
Contact Detail:
Immediate Live Co Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land DevSecOps Engineer in City of London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to DevSecOps. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common DevSecOps questions and scenarios. Practice explaining your thought process and how you tackle security challenges in cloud environments. Confidence is key!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are genuinely interested in joining our team at Immediate.
We think you need these skills to ace DevSecOps Engineer in City of London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the DevSecOps role. Highlight your experience with AWS, Terraform, and CI/CD tools. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Share your passion for automation and security by design. Let us know why you’re excited about joining our Platforms & Security team at Immediate.
Showcase Your Projects: If you've worked on relevant projects, don’t hold back! Include links to your GitHub or any other platforms where we can see your work in action. We love seeing practical examples of your skills.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and we can’t wait to see your application come through!
How to prepare for a job interview at Immediate Live Co
✨Know Your Tech Stack
Make sure you’re well-versed in the technologies mentioned in the job description, like AWS, Terraform, and Docker. Brush up on your knowledge of CI/CD pipelines and security frameworks, as these will likely come up during the interview.
✨Showcase Your Problem-Solving Skills
Prepare to discuss specific challenges you've faced in previous roles, especially related to security incidents or infrastructure issues. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your problem-solving abilities.
✨Demonstrate Collaboration
Since this role involves working closely with developers and product teams, be ready to share examples of how you’ve successfully collaborated in the past. Highlight any experience you have in promoting DevSecOps practices and how you’ve helped teams adopt secure coding standards.
✨Stay Current with Industry Trends
Research the latest trends in DevSecOps and be prepared to discuss them. This shows your passion for the field and your commitment to continuous learning, which is crucial for a role that requires staying ahead of emerging threats and tools.