At a Glance
- Tasks: Join our team to enhance security in software development and cloud environments.
- Company: Instem, a global leader in bespoke software solutions for drug discovery.
- Benefits: Enjoy competitive salary, flexible working, private medical, and 25 days leave.
- Why this job: Make a real impact on security in innovative tech while growing your skills.
- Qualifications: Experience in DevSecOps, cloud security, and strong coding skills required.
- Other info: Be part of a supportive culture with excellent career growth opportunities.
The predicted salary is between 36000 - 60000 £ per year.
Overview
Location: Stone, Staffordshire Hybrid working, 2 days a week in our Stone Office
Status: Permanent, Full Time
Package: Competitive Salary, Flexible Working, Development & Opportunity (Personal & Technical), Private Medical (Optical & Dental options), Matching Contributory Pension, 25 Days Leave + Public Holidays + Buy and Sell Scheme, Life Insurance, Referral Scheme, Employee Assistance Program, Benefits Hub.
Who is Instem?
We are a global provider of bespoke industry-leading software solutions and services, which facilitate the pre-clinical and clinical phases of the drug discovery process. We have over fifteen products in our portfolio, used by over 700 pharmaceutical clients (including all the top 25!).
Culture and Environment
For a global business of over 400 staff, we have a family feel. You will be part of a friendly, communal, solution-based, flexible environment, where you will feel empowered, valued and accountable. We will invest in you as a person and encourage you to take part in company-wide workshops for wellbeing, mental health, critical conversations, and strengths.
Role context
This role sits within the Platform Engineering team and works closely with SRE, development teams, and our managed SOC. You will operate in an environment that includes established platforms, legacy patterns, and in-flight migrations, alongside newer cloud-native services. A key part of the role is understanding what exists today, identifying material risks and gaps and leading pragmatic improvements over time. You will be expected to operate with a high degree of autonomy. This is a developing senior role for someone who can gather information, form a clear view of the current state, and advise on priorities and direction without needing a fully defined roadmap. You will influence platform security strategy through evidence, engineering judgement, and collaboration.
What are you responsible for?
- Assess the current security posture of our existing platforms, pipelines and cloud environments
- Gather and synthesise information across teams to build a clear view of current risks, gaps, and constraints
- Lead the definition of pragmatic, prioritised improvements to security maturity over time
- Embed security into platform architecture, infrastructure and CI/CD pipelines across the SDLC
- Introduce and evolve a practical threat modelling approach appropriate to a mixed legacy and cloud native estate
- Design, build and improve secure Azure landing zones and shared platform services
- Ensure migrations from managed data centres into Azure result in measurable security improvements
- Jointly own security monitoring and detection capabilities with the managed SOC, shaping alerts, workflows, and responsibilities
- Own and evolve security guardrails using policy as code and automated controls
- Integrate security testing into delivery pipelines, including code, dependency, container and infrastructure scanning
- Partner with Platform Engineers to define secure by default patterns and reusable components
- Work with SREs to align runtime security, observability, and incident response
- Participate in security incidents and post-incident reviews, driving long term corrective actions
- Enable engineering teams through capture the flag exercises, threat scenarios and hands-on security learning
- Provide clear, evidence-based security advice to platform, architecture and delivery leadership
Skills, Knowledge, Experience
- Strong hands-on experience in DevSecOps, platform security or cloud security engineering
- Background as a software developer, platform engineer, or architect, with a solid understanding of how real systems are built and delivered is a real advantage
- Demonstrable experience working across the full SDLC, including design, development, testing, deployment and operation
- Ability to reason about security in the context of application code, infrastructure and runtime behaviour rather than in isolation
- Deep experience securing Azure environments, with working knowledge of AWS
- Proven experience designing, assessing and evolving secure cloud landing zones
- Practical experience applying threat modelling techniques to both new and existing systems
- Strong experience integrating security controls and testing into CI/CD pipelines
- Solid Infrastructure as Code experience (Terraform, Bicep, ARM, etc.)
- Experience securing containers, Kubernetes, and cloud native workloads
- Familiarity with modern testing practices, including unit, integration, and security testing and how they fit together
- Strong automation and scripting skills (PowerShell, Python, Bash, etc.)
- Experience working alongside managed security providers or SOC teams
DevSecOps Engineer employer: Instem plc
Contact Detail:
Instem plc Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land DevSecOps Engineer
✨Tip Number 1
Network like a pro! Reach out to current employees at Instem on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing the DevSecOps Engineer role. Personal connections can make a huge difference!
✨Tip Number 2
Prepare for the interview by brushing up on your technical skills and understanding of security practices. Be ready to discuss how you would assess and improve security in existing platforms. Show us that you can think critically and provide evidence-based solutions!
✨Tip Number 3
Don’t just focus on your technical skills; highlight your soft skills too! Being part of a friendly, communal environment means collaboration is key. Share examples of how you've worked with teams to solve problems or improve processes.
✨Tip Number 4
Finally, apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows us you’re genuinely interested in being part of the Instem family. Good luck!
We think you need these skills to ace DevSecOps Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the DevSecOps Engineer role. Highlight your relevant experience in platform security, cloud environments, and any hands-on work with CI/CD pipelines. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about DevSecOps and how you can contribute to our team. Be sure to mention specific projects or experiences that relate to the job description.
Showcase Your Technical Skills: Don’t forget to showcase your technical skills in your application. Mention your experience with Azure, Terraform, and any automation tools you've used. We love seeing candidates who can demonstrate their expertise in real-world scenarios!
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at Instem plc
✨Know Your Stuff
Make sure you brush up on your DevSecOps knowledge, especially around Azure environments and CI/CD pipelines. Be ready to discuss your hands-on experience with security controls and how you've integrated them into the software development lifecycle.
✨Showcase Your Problem-Solving Skills
Prepare to share specific examples of how you've identified risks and implemented improvements in past roles. Think about times when you had to work with legacy systems and how you approached those challenges.
✨Understand the Company Culture
Instem values a friendly and solution-based environment, so be sure to convey your collaborative spirit. Highlight experiences where you've worked well in teams and contributed to a positive workplace culture.
✨Ask Insightful Questions
Prepare thoughtful questions that show your interest in the role and the company. Inquire about their current security posture, ongoing projects, or how they envision the evolution of their platform security strategy.