At a Glance
- Tasks: Lead security engineering for a top-tier pharmaceutical client and embed security in every pipeline.
- Company: Join Newpage Solutions, a global leader in digital health innovation with a remote-first culture.
- Benefits: Enjoy competitive pay, flexible work, and opportunities for continuous learning and growth.
- Other info: Collaborative environment focused on creativity, inclusivity, and long-term impact.
- Why this job: Make a real impact on healthcare by developing secure, transformative technologies.
- Qualifications: 8+ years in security engineering with strong cloud expertise, especially in AWS.
The predicted salary is between 80000 - 100000 £ per year.
Location: Remote | Type: Contract
About Newpage Solutions
Newpage Solutions is a global digital health innovation company helping people live longer, healthier lives. We partner with life sciences organizations—including pharmaceutical, biotech, and healthcare leaders—to build transformative AI and data-driven technologies addressing real-world health challenges. From strategy and research to UX design and agile development, we deliver and validate impactful solutions using lean, human-centered practices. We are proud to be Great Place to Work® certified for three consecutive years, hold a top Glassdoor rating, and were named among the "Top 50 Most Promising Healthcare Solution Providers" by CIO Review. As a remote-first company, we foster creativity, continuous learning, and inclusivity, creating an environment where bold ideas thrive and make a measurable difference in people’s lives. Newpage looks for candidates who are invested in long-term impact. Applications with a pattern of frequent job changes may not align with the values we prioritize.
Your Mission
Newpage is hiring a Staff DevSecOps Engineer to lead the security engineering posture of a strategic engagement with a global top-tier pharmaceutical company. As the technical anchor for the account, you will define how secure software is built, shipped, and operated across the client's cloud estate — spanning AWS, Azure, and GCP workloads — from research and clinical data platforms through to commercial and supply-chain systems. The client's strategic direction leans on AWS, and depth there is a meaningful advantage. You will partner closely with the client's CISO organization, cloud platform team, application teams, and quality and compliance functions to embed security as code into every pipeline. This is a hands-on principal-level role for someone who thrives at the intersection of cloud-native engineering, regulatory rigor, and developer experience.
What You’ll Do
- Set DevSecOps Strategy translate regulatory intent into engineering requirements that teams can implement.
- Mentor and coach Newpage and client engineers; raise the bar on secure coding, threat modeling, and incident response across the account.
- Engineer Security Into the Cloud Estate Design and operate hardened, multi-account or multi-subscription landing zones — AWS Control Tower / Organizations / SCPs / Identity Center (preferred), Azure Landing Zones / Management Groups / Policy, or GCP Organization Policy / Folders — with guardrails enforced as code.
- Build paved-road CI/CD pipelines (GitHub Actions, GitLab CI, AWS CodePipeline, Azure DevOps, or Jenkins) with integrated SAST, DAST, SCA, secrets scanning, IaC scanning, container scanning, and SBOM generation.
- Implement policy-as-code using OPA/Rego, Checkov, and cloud-native equivalents (AWS Config Rules / CloudFormation Guard, Azure Policy, GCP Organization Policy); enforce at pull-request time and in production.
- Operationalize cloud-native security services end-to-end — AWS GuardDuty / Security Hub / Macie / Inspector / IAM Access Analyzer / KMS / Secrets Manager / WAF (primary), with working knowledge of Microsoft Defender for Cloud / Sentinel and GCP Security Command Center.
- Lead Kubernetes and container security across managed offerings (EKS preferred; AKS, GKE accepted), including admission control, image signing (Sigstore/Cosign), runtime threat detection (Falco or equivalent), and Pod Security Standards enforcement.
- Drive supply-chain security to SLSA-aligned maturity: signed builds, attested artifacts, dependency provenance, and verified deploys.
- Own Regulated tune findings, suppress noise, and ensure every signal is actionable.
- Run blameless postmortems for security incidents and near-misses; convert lessons into durable engineering improvements.
- Establish security SLOs and meaningful metrics — mean time to remediate, control coverage, drift, and developer-impacting friction.
- Influence Across Client and Practice Build trust with the client's senior security, platform, and quality leadership; become the person they call before launching a new initiative.
- Contribute to Newpage's internal DevSecOps practice: reusable accelerators, case studies, hiring loops, and the next generation of senior engineers across the company.
What You Bring
- 8+ years of professional experience in security engineering, platform engineering, or SRE, with at least 4 years leading DevSecOps initiatives at scale.
- Deep, current expertise with at least one major public cloud at production scale — AWS is strongly preferred (you have personally designed and operated multi-account environments with 50+ accounts); Azure or GCP at equivalent depth will be considered.
- Working familiarity with at least one additional cloud beyond your primary — enough to design controls that translate cleanly across providers.
- Strong hands-on coding skills in at least one of Python, Go, or TypeScript, and fluency in infrastructure-as-code with Terraform (cloud-agnostic mastery preferred; CDK, Bicep, or Pulumi also welcome).
- Demonstrable experience embedding security into CI/CD pipelines and developer workflows for engineering organizations of 200+ developers.
- Working knowledge of Kubernetes security on at least one managed offering (EKS preferred; AKS or GKE accepted) — including network policy, admission control, and supply-chain controls.
- Track record of operating in a regulated industry — pharma, healthcare, financial services, or critical infrastructure — and translating compliance frameworks into engineering controls.
- Excellent written and verbal communication skills; comfortable presenting to a client CISO one day and pairing with a junior engineer the next.
Nice to have
- Direct experience with pharma or life-sciences workloads: GxP, 21 CFR Part 11, Annex 11, CSV/CSA, pharmacovigilance systems, or clinical data platforms.
- Exposure to threat modeling frameworks (STRIDE, PASTA), MITRE ATT&CK.
DEVSECOPS ENGINEER in Nottingham employer: Newpage Solutions
Newpage Solutions is an exceptional employer, offering a remote-first work environment that champions creativity, inclusivity, and continuous learning. As a Great Place to Work® certified company, we provide our employees with meaningful opportunities for growth and development while working on transformative projects in the healthcare sector. Join us to make a real impact in people's lives while enjoying a supportive culture that values bold ideas and long-term commitment.
StudySmarter Expert Advice🤫
We think this is how you could land DEVSECOPS ENGINEER in Nottingham
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend virtual meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to DevSecOps. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common DevSecOps scenarios and challenges. Practice explaining your thought process and how you've tackled security issues in past roles. Confidence is key!
✨Tip Number 4
Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining Newpage Solutions. Plus, it helps us keep track of your application and get you in front of the right people faster.
We think you need these skills to ace DEVSECOPS ENGINEER in Nottingham
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Staff DevSecOps Engineer role. Highlight your relevant experience with cloud platforms like AWS, Azure, or GCP, and showcase how you've embedded security into CI/CD pipelines.
Showcase Your Skills:Don’t just list your skills; demonstrate them! Use specific examples from your past work where you’ve successfully implemented security measures or led DevSecOps initiatives. This will help us see your hands-on experience in action.
Be Clear and Concise:When writing your application, keep it clear and to the point. We appreciate well-structured applications that are easy to read. Avoid jargon unless it's necessary, and make sure your passion for the role shines through!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at Newpage Solutions!
How to prepare for a job interview at Newpage Solutions
✨Know Your Stuff
Make sure you brush up on your knowledge of cloud platforms, especially AWS, as it's a key focus for the role. Be ready to discuss your hands-on experience with security engineering and how you've implemented DevSecOps practices in previous roles.
✨Showcase Your Coding Skills
Since coding is a big part of this job, be prepared to demonstrate your proficiency in languages like Python, Go, or TypeScript. You might even want to bring examples of your work or projects that highlight your skills in infrastructure-as-code using Terraform.
✨Understand the Regulatory Landscape
Familiarise yourself with compliance frameworks relevant to the pharmaceutical and healthcare industries. Be ready to explain how you've translated regulatory requirements into engineering controls in past positions, as this will show your understanding of the industry's unique challenges.
✨Communicate Effectively
This role requires strong communication skills, so practice articulating your thoughts clearly. Whether you're discussing technical details with a client CISO or mentoring junior engineers, being able to convey complex ideas simply will set you apart.