At a Glance
- Tasks: Design and maintain secure cloud infrastructure while embedding security in the software delivery lifecycle.
- Company: Join Immediate, home to beloved UK brands like Radio Times and Good Food.
- Benefits: Enjoy 25 days holiday, flexible working, and tailored training opportunities.
- Why this job: Make a real impact on security and automation in a dynamic tech environment.
- Qualifications: Experience in AWS, CI/CD, and strong problem-solving skills required.
- Other info: Be part of a diverse team with a focus on growth and well-being.
The predicted salary is between 43200 - 67200 ÂŁ per year.
Immediate is home to some of the biggest and most loved consumer brands in the UK, including Radio Times, Good Food and BBC Gardeners World magazine. Our trusted, quality content reaches millions of people a month across digital, print, video, podcasts, apps and live events. We are here to inspire, fuel, encourage and educate.
About the role
We are seeking a DevSecOps Engineer to join our growing Platforms & Security team. This is a handsâon role for someone passionate about automation, cloud operations, and security by design. You will be responsible for ensuring our platforms, products, and infrastructure are secure, resilient, and scalable while working closely with developers, QA, and product teams.
You will combine DevOps best practices with modern security engineering approaches to embed security throughout the software delivery lifecycle, strengthen our cloud infrastructure, and proactively protect our customers' data.
As a DevSecOps Engineer you will:
- Design, build, and maintain secure and scalable infrastructure in AWS using Terraform, Kubernetes, and Docker.
- Embed security into the CI/CD pipeline (Jenkins, GitHub Actions, CodePipeline) including SAST/DAST and dependency scanning.
- Collaborate with developers and product teams to promote DevSecOps practices, threat modelling, and secure coding standards.
- Conduct security assessments of applications, services, and infrastructure, identifying vulnerabilities and recommending remediation.
- Operate, tune, and extend monitoring, logging, and alerting systems for both performance and security.
- Manage DNS, CDN, caching, firewalls, load balancers, and WAFs to ensure secure and performant web delivery.
- Respond to and resolve security incidents and platform issues, driving continuous improvement and automation of responses.
- Keep documentation current, including runbooks, incident playbooks, and security procedures.
- Stay ahead of industry trends, emerging threats, and new DevSecOps tools.
Skills and experience
- Strong background in cloud infrastructure (AWS preferred: EC2, Lambda, RDS, Route53, ELBs, EKS).
- Proven experience with CI/CD automation and infrastructure-as-code (Terraform, Ansible, Jenkins, Git/GitHub).
- Proficiency in containerisation (Docker, Kubernetes) and managing production workloads.
- Solid understanding of security frameworks (CIS, OWASP) and common vulnerabilities (OWASP Top 10, misconfigurations, supply chain risks).
- Experience with application and infrastructure monitoring (e.g. Prometheus, Grafana, ELK, CloudWatch).
- Knowledge of Linuxâbased systems (LAMP stack, Nginx, Varnish, MySQL/Postgres, Mongo) with performance tuning and hardening experience.
- Strong grasp of networking and security protocols (TCP/IP, SSL/TLS, DNS, NAT, firewalls, load balancers, WAFs).
- Familiarity with code security tools (SAST, DAST, dependency scanners) and integrating them into pipelines.
- Excellent problemâsolving, communication, and crossâteam collaboration skills.
- Disaster recovery process and GDPR.
Desired
- Knowledge on PCI DSS.
Benefits
- A relaxed working environment with regular socials including a summer festival.
- Supportive wellâbeing initiatives and benefits, talks & workshops, and Mental Health First Aiders & Champions.
- 25 days holiday plus a day for your birthday. Our offices will be closed between Christmas and New Year's which are in addition to your annual entitlement.
- Tailored training and development through both our inâhouse learning platform and LinkedIn Learning.
- A progressive and transparent culture focused on your development.
- Flexible / hybrid working plus early finish Fridays.
- Cycle to work scheme.
- Enhanced Family Policies including paternity, adoption and surrogacy leave. We also provide a pregnancy loss, fertility, and carers policy.
- Competitive pension plans and Life Assurance.
- A newly renovated modern office with lots of collaborative spaces.
People are at the heart of our business and creating a diverse and inclusive working environment is extremely important to us. Immediate is an equal opportunities employer. We will never treat anyone less favourably because of their sex, gender reassignment, pregnancy and maternity, marital/civil partnerships, sexual orientation, race, nationality, ethnic origin, age, religion or belief or disability. We are also committed to supporting applications from those who are returning to work following a career break, maternity leave or caring responsibilities. Immediate is a place where you can grow, be supported, and make a difference.
DevSecOps Engineer in London employer: Immediate Live Co
Contact Detail:
Immediate Live Co Recruiting Team
StudySmarter Expert Advice đ€«
We think this is how you could land DevSecOps Engineer in London
âšTip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
âšTip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to DevSecOps. This gives potential employers a taste of what you can do and sets you apart from the crowd.
âšTip Number 3
Prepare for interviews by practising common DevSecOps questions and scenarios. Think about how you would handle security incidents or implement CI/CD pipelines. The more prepared you are, the more confident you'll feel!
âšTip Number 4
Don't forget to apply through our website! Itâs the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step to engage with us directly.
We think you need these skills to ace DevSecOps Engineer in London
Some tips for your application đ«Ą
Tailor Your CV: Make sure your CV reflects the skills and experience mentioned in the job description. Highlight your cloud infrastructure knowledge, CI/CD automation, and security frameworks to catch our eye!
Craft a Compelling Cover Letter: Use your cover letter to tell us why you're passionate about DevSecOps. Share specific examples of how you've embedded security into your previous projects and how you can contribute to our team.
Showcase Your Projects: If you've worked on relevant projects, donât hesitate to include them! Whether it's a personal project or something from your previous job, we love seeing practical applications of your skills.
Apply Through Our Website: We encourage you to apply directly through our website. Itâs the best way for us to receive your application and ensures youâre considered for this exciting opportunity!
How to prepare for a job interview at Immediate Live Co
âšKnow Your Tech Stack
Make sure youâre well-versed in the technologies mentioned in the job description, like AWS, Terraform, and Docker. Brush up on your knowledge of CI/CD pipelines and security frameworks, as these will likely come up during the interview.
âšShowcase Your Problem-Solving Skills
Prepare to discuss specific challenges you've faced in previous roles, especially related to security incidents or infrastructure issues. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your problem-solving abilities.
âšEmphasise Collaboration
Since this role involves working closely with developers and product teams, be ready to talk about your experience in cross-team collaboration. Share examples of how youâve promoted DevSecOps practices and improved communication between teams.
âšStay Current with Industry Trends
Demonstrate your passion for the field by discussing recent trends or emerging threats in DevSecOps. Mention any new tools or techniques youâve been exploring, as this shows your commitment to continuous learning and improvement.