DevSecOps Engineer: Azure Cloud
DevSecOps Engineer: Azure Cloud

DevSecOps Engineer: Azure Cloud

Full-Time 48000 - 84000 £ / year (est.) No home office possible
N

At a Glance

  • Tasks: Join our InfoSec team as a DevSecOps Engineer, ensuring secure application development.
  • Company: Be part of the NAO, a forward-thinking organisation focused on data and technology.
  • Benefits: Enjoy a dynamic work environment with opportunities for growth and innovation.
  • Why this job: Make a real impact on national security while working in a fun, collaborative team.
  • Qualifications: Strong cyber security knowledge and experience in DevOps practices are essential.
  • Other info: Opportunity to obtain professional certifications and work towards SC Security Clearance.

The predicted salary is between 48000 - 84000 £ per year.

Job Description

Why are we recruiting?

In a world where cyber challenges and opportunities are constantly evolving, we are committed to staying ahead of the curve. With new investment aimed at enhancing the NAO’s security maturity our Information Security team is expanding. This is your chance to join a dynamic organisation with clear strategic objectives and help advance our data use and embrace new technologies securely.

We’re not just growing—we’re evolving. As part of a forward-thinking organisation with a strong mandate to harness data and embrace cutting-edge technologies, our InfoSec team is central to enabling and securing the NAO’s digital future.

We’re on the lookout for passionate, curious, and collaborative security professionals across a wide range of specialisms. Whether your expertise lies in governance, engineering, threat detection, or cloud security, you’ll find real scope to make an impact—both within InfoSec and across the wider organisation.

  • Be part of a diverse and expanding team that thrives on challenge and innovation.
  • Work in a complex, data-rich environment where your insights will shape national-level outcomes.
  • Help embed security into every layer of our digital transformation—from strategy to code.

This is more than a job. It’s a chance to help define the future of security at the NAO and be part of a high performing, and fun team.

Context and main purpose of the job:

Why are we recruiting for this role?

The InfoSec DevSecOps Engineer is an additional role within the NAO’s Information Security function. Working within the Cyber Security function they will have the responsibility for ensuring the security of our applications by implementing robust security controls, supporting the delivery of a DevSecOps approach and collaborating closely with our development teams. As one of our security engineers, you will be at the forefront of driving continuous improvement across a range of software applications, secure coding practices, and supporting the organization’s digital transformation initiatives.

Who are the team?

The role sits within an inclusive, diverse, respectful, and agile team of information security professionals responsible for enabling the business to better understand, identify and manage the threats and risks that could impact the NAO’s ability to deliver on its vision and strategy.

What are the main responsibilities of this role?

The DevSecOps Engineer will play a crucial role in protecting the NAOs information and application assets. This position involves representing the Information Security function’s risk appetite into the implementation of new application capabilities and the development of existing tools and services.

The Cyber Security team will lead on establishing, implementing, and maturing the NAO’s operational AppSec functions and controls, harden the Azure platforms, and work with the Secure Software Development Lifecycle processes.

It is a function critical to the success of the NAO’s strategy, ensuring that application security controls are effectively implemented and adhered to, in line with our policies and procedures, identifying and mitigating risks, and ensuring compliance with policies and regulations, enabling the security, digital and data objectives.

This role requires strong cyber security knowledge, excellent stakeholder management skills, an ability to maintain currency with emerging technologies and trends in the application development and AppSec fields; a good understanding of both the definition and application of strong information security best practice and working closely with the Director of Information Security and Head of InfoSec to help elevate the NAO's security maturity and embed an information security culture across the organisation.

Responsibilities:

In this role level, you will:

  • Be responsible for proactively integrating security first and continuously throughout a secure application development lifecycle, while reacting to find and fix vulnerabilities in applications.
  • Conduct regular security assessments and support penetration testing and their outputs, to identify vulnerabilities in applications.
  • Transform technical requirements into an effective application development lifecycle, incorporated into a wider DevSecOps toolchain to enable secure product delivery across all technology pillars (identity, endpoint, data, apps, infrastructure, network).
  • Ensure that secure deployment strategies for applications are repeatable, scalable, and highly available.
  • Support technical and security teams and suppliers to maintain, sustain, and secure the organization’s digital cloud estate, including providing coaching and mentoring.
  • Ensure continuous improvement and change capabilities, thoroughly understanding service requirements, and optimizing resources, services, and tools within a cloud service context.
  • Conduct investigative work into problems and opportunities in existing processes, managing information collection, and creating recommendations for process optimization.
  • Develop and implement integrated and secure cloud service solutions, leveraging advanced knowledge in cloud computing, data analytics, and enterprise architecture.
  • Utilize delivery management, agile methodologies, and Azure DevOps capabilities to ensure project success.
  • Maintain a keen awareness of security and digital standards, methods, principles, tools, and applications, making informed choices supported by a strong understanding of the security, digital, AI industries, government digital trends and emerging technologies.
  • Azure Cloud security and Governance: Automate security baselines and configuration management using IaC Biceps/Terraform and enforce with Azure policy.
  • Continually improve the Secure Software Development Lifecycle (SSDLC) ensuring that the organisation adopts good practices and standards commensurate with identified risks.
  • Support risk assessments and identify and implement effective mitigation strategies.
  • Ensure that all cloud services integrate effectively with Information Security’s governance, risk, and compliance controls.

Key skills/competencies required:

The skill sets listed also include the corresponding skill level (awareness, working, practitioner, expert):

  • Information/Application Security: You can design applications, solutions and services with security controls included, specifically engineered to mitigate security threats. (Skill level: Practitioner)
  • Service Support: You can identify, locate, and fix complex application faults. You can advise others on different methodologies and types of application security support. (Skill level: Expert)
  • Development process optimisation: You can analyse current processes, identify, and implement opportunities to optimiser processes. You help to evaluate and establish requirements for the implementation of changes by setting policy and standards. (Skill level: Practitioner)
  • Enabling and informing risk-based decisions: You can work with risk owners to advise and give feedback. You advise on risk impact and whether it is within risk tolerance. You can describe different risk methodologies and how these are applied, as well as the proportionality of risk. (Skill level: Working)
  • Modern development standards: You can apply modern development standards and support others in applying them. (Skill level: Practitioner)
  • Programming and build (software engineering): You can collaborate with others when necessary to review specifications. You use the agreed specifications to design, code, test and document programs or scripts of medium-to-high complexity, using the right standards and tools. (Skill level: Practitioner)
  • Prototyping: You can approach prototyping as a team activity, actively soliciting prototypes and testing with others. You establish design patterns and iterate them, using a variety of prototyping methods and choose the most appropriate. (Skill level: Practitioner)
  • Research and innovation: You can advise on developments to security properties in technology. You identify new technologies and design their use in a business context. (Skill level: Working)
  • Systems Design: You can design systems characterised by medium levels of risk, impact and business or technical complexity. You select appropriate design standards, methods, and tools, and ensure they are applied effectively. You can review the system designs of others to ensure the selection of appropriate technology, efficient use of resources and integration of multiple systems and technology. (Skill level: Practitioner)
  • Systems integration: You can define the integration build; co-ordinate build activities across systems and understand how to undertake and support integration testing activities. (Skill level: Practitioner)
  • Security technology: You can explain the effect of vulnerabilities on current and future designs, sharing information on a range of systems. (Skill level: Practitioner)
  • Understanding security implications of transformation: You can interpret and apply an understanding of policy and process, business architecture, and legal and political implications to assist the development of technical solutions or controls. (Skill level: Working)

Experience

  • Demonstrated background in integrating security practices into the DevOps lifecycle, including automated security testing, secure code reviews, and vulnerability management.
  • Experience with continuous integration and continuous deployment (CI/CD) pipelines, infrastructure as code (IaC), and the use of security automation tools to embed security throughout the development process.
  • Track record of implementing Zero Trust security models, such as identity verification, least privilege access, and continuous monitoring; experience with micro-segmentation, multi-factor authentication (MFA), and adaptive access controls to provide secure, granular resource access.
  • Knowledge of industry standards and regulations (e.g. GDPR/Data Protection Act 2018, ISO 27001, NIST), including conducting security audits, risk assessments, and achieving compliance with relevant legal and regulatory frameworks.
  • Experience leading investigative work on process optimisation, including identifying problems in current processes, gathering information, and making recommendations for improvements.

Essential

  • Analytical and problem-solving abilities, with attention to detail.
  • Ability to delegate effectively, facilitate knowledge sharing, and work collaboratively within multi-disciplinary teams, including audit and technology colleagues.
  • Initiative and motivation to promote secure practices, continuous improvement, and organisational change.
  • Extensive experience as a DevOps professional.
  • Working towards, or able to obtain within the first year, a relevant professional certification such as CISSP, CISM, or CRISC.
  • Eligibility for SC Security Clearance, or ability to achieve SC clearance promptly.
  • Current technical knowledge including:
  • ISO 27001
  • Risk Management
  • Data Protection Act 2018/GDPR
  • Awareness of current application security and AI/Gen AI issues, particularly those relevant to government.

DevSecOps Engineer: Azure Cloud employer: National Audit Office

Join the National Audit Office (NAO) as a DevSecOps Engineer in a vibrant and inclusive environment that prioritises innovation and security. With a strong commitment to employee growth, you will have access to continuous learning opportunities and the chance to shape national-level outcomes through your expertise in cloud security. Enjoy a collaborative work culture that values diversity and encourages you to make a meaningful impact on the future of information security.
N

Contact Detail:

National Audit Office Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land DevSecOps Engineer: Azure Cloud

✨Tip Number 1

Familiarise yourself with Azure Cloud security features and best practices. Understanding how to implement security controls within Azure will give you a significant edge, as this role heavily focuses on securing applications in the cloud.

✨Tip Number 2

Engage with the DevSecOps community online. Participating in forums or attending meetups can help you stay updated on the latest trends and tools, which is crucial for a role that requires continuous improvement in security practices.

✨Tip Number 3

Showcase your experience with CI/CD pipelines and infrastructure as code (IaC) in your discussions. Being able to articulate how you've integrated security into these processes will demonstrate your practical knowledge and relevance to the role.

✨Tip Number 4

Prepare to discuss your approach to risk management and compliance with industry standards like ISO 27001 and GDPR. This role requires a solid understanding of these frameworks, so being able to speak confidently about them will set you apart.

We think you need these skills to ace DevSecOps Engineer: Azure Cloud

Azure Cloud Security
DevSecOps Practices
Secure Software Development Lifecycle (SSDLC)
Automated Security Testing
Continuous Integration and Continuous Deployment (CI/CD)
Infrastructure as Code (IaC)
Vulnerability Management
Zero Trust Security Models
Identity Verification
Least Privilege Access
Multi-Factor Authentication (MFA)
Security Audits
Risk Assessments
GDPR/Data Protection Act 2018 Compliance
ISO 27001 Knowledge
NIST Standards
Analytical Skills
Problem-Solving Skills
Stakeholder Management
Collaboration in Multi-Disciplinary Teams
Process Optimisation
Technical Documentation
Agile Methodologies
Cloud Service Solutions Development
Emerging Technologies Awareness

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in DevSecOps, Azure Cloud, and application security. Use keywords from the job description to demonstrate that you meet the specific requirements of the role.

Craft a Compelling Cover Letter: In your cover letter, express your passion for cybersecurity and how your skills align with the responsibilities outlined in the job description. Mention specific projects or experiences that showcase your ability to integrate security into the development lifecycle.

Showcase Relevant Skills: Clearly list your technical skills related to Azure Cloud, CI/CD pipelines, and security automation tools. Provide examples of how you've applied these skills in previous roles to enhance application security.

Highlight Continuous Improvement Initiatives: Discuss any past experiences where you identified opportunities for process optimisation or implemented changes that improved security practices. This will demonstrate your proactive approach and commitment to continuous improvement.

How to prepare for a job interview at National Audit Office

✨Showcase Your Cyber Security Knowledge

Make sure to brush up on your understanding of cyber security principles, especially those relevant to Azure Cloud. Be prepared to discuss how you would implement security controls and manage risks in a DevSecOps environment.

✨Demonstrate Your Experience with CI/CD Pipelines

Highlight your experience with continuous integration and continuous deployment pipelines. Discuss specific tools you've used and how you've integrated security practices into these processes to ensure secure product delivery.

✨Prepare for Technical Questions

Expect technical questions related to secure coding practices, vulnerability management, and the Secure Software Development Lifecycle. Be ready to provide examples from your past work that demonstrate your expertise in these areas.

✨Emphasise Collaboration Skills

Since the role involves working closely with development teams, be sure to highlight your collaboration skills. Share examples of how you've successfully worked in multi-disciplinary teams to achieve security objectives and drive continuous improvement.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

N
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>