DevSecOps Engineer

DevSecOps Engineer

Full-Time 36000 - 60000 ÂŁ / year (est.) No home office possible
Nordcloud

At a Glance

  • Tasks: Join us to enhance security in cloud environments and automate processes.
  • Company: Be part of Nordcloud, a leader in European cloud innovation.
  • Benefits: Enjoy flexible hours, training budgets, and comprehensive health care.
  • Why this job: Make a real impact on national digital security and shape engineering standards.
  • Qualifications: Experience in DevSecOps, AWS, Azure, and IaC tools like Terraform.
  • Other info: Collaborative culture with opportunities for growth and learning.

The predicted salary is between 36000 - 60000 ÂŁ per year.

Join Nordcloud and be part of the European cloud revolution. We supercharge our customers to innovate in hyperscaler cloud, enabling seamless migration, advanced security, and data-driven success. Currently, we are looking for a DevSecOps Engineer to join our team in the UK. We are seeking an experienced DevSecOps Engineer to help uplift and standardise the security posture across a large-scale public‑sector digital screening programme. The platform spans AWS and Azure, with 20+ cloud‑based services at varying stages of maturity. The goal is to create a coherent, consistent, and modern cybersecurity baseline across all products by embedding security into CI/CD, Infrastructure-as-Code (IaC), and operational processes. You will work closely with product teams, infrastructure engineers, and delivery squads to embed security early ("shift‑left"), automate controls, and ensure consistent guardrails across the entire service portfolio.

Key Responsibilities

  • Security Engineering & Automation
    • Implement and embed security controls throughout CI/CD pipelines, ensuring security is built‑in rather than bolted‑on.
    • Enhance and maintain IaC (Terraform / ARM / Bicep / CloudFormation) ensuring consistent, repeatable, and secure infrastructure deployments across AWS and Azure.
    • Integrate automated security scanning (SAST/DAST/SCA), secrets management, policy enforcement, base image hardening, and runtime protection as part of the delivery workflow.
  • Cloud Security (AWS & Azure)
    • Work with multi‑cloud services to design, implement, and maintain security patterns that can be applied consistently across the portfolio.
    • Configure cloud‑native security tooling (e.g., guardrails, identity policies, network controls) and ensure all services meet agreed security standards.
    • Collaborate on extracting reusable libraries and toolsets to drive standardisation across teams.
  • CI/CD & Platform Engineering
    • Deliver security improvements through changes to CI/CD and IaC repositories, version controlled alongside application code.
    • Build and refine pipelines that support automated testing, deployment, and governance across cloud environments.
    • Ensure teams can continuously monitor, detect, and remediate vulnerabilities through integrated pipeline tooling.
  • Disaster Recovery & Operational Readiness
    • Contribute to DR strategy uplift by defining consistent runbooks, automated processes, and wargaming tools to validate resilience across services.
    • Ensure operational documentation is clear, repeatable, and usable by delivery and support teams.
  • Collaboration & Delivery
    • Work hand‑in‑glove with product teams, architects, and infrastructure engineers to socialise patterns, build capability, and embed practices early.
    • Prioritise work based on an existing cybersecurity risk assessment, ensuring high‑value improvements are delivered first.
    • Support knowledge sharing, coaching, and embedding of security best practices across engineering teams.

Required Skills & Experience

  • Strong background in DevSecOps principles including shift‑left security, automated testing, secure SDLC, and cloud‑native security engineering.
  • Hands‑on experience with AWS and Azure cloud environments.
  • Experience designing secure and scalable architectures, CI/CD pipelines, and infrastructure automation.
  • Proficiency with IaC tools such as Terraform, ARM, Bicep, CloudFormation.
  • Experience integrating security tools into CI/CD (SAST, DAST, dependency scanning, secrets scanning, container scanning).
  • Familiarity with container orchestration and security (Kubernetes/AKS/EKS).
  • Strong understanding of identity, access, network, and policy enforcement across cloud platforms.
  • Ability to document runbooks, DR processes, and operational guidance.
  • Excellent stakeholder engagement skills across engineering, operations, and delivery teams.
  • MUST BE ELIGIBLE FOR SC CLEARANCE.

Desirable Skills

  • Experience contributing to or maintaining shared libraries or open‑source tooling.
  • Knowledge of audit, compliance, and security frameworks.
  • Experience in large public‑sector or regulated environments.

Why this role matters

Your work will directly strengthen the security posture of a major national digital screening platform, ensuring consistency, resilience, and trustworthiness across dozens of critical public‑facing services. You will be instrumental in shaping secure engineering standards that will be adopted across multiple teams and cloud environments.

What we offer:

  • Individual training budget and exam fees for certifications.
  • Flexible working hours and hybrid working model.
  • Company laptop and needed equipment.
  • Local package such as up to 7% matched pension contributions, extensive private health care, Bupa dental plan, and a seasonal ticket loan, enhanced maternity and parental leave, gym expense or well‑being monthly and mobile phone allowance.

Please read our Recruitment Privacy Policy before applying. All applicants must have the right to work in the UK.

About Nordcloud

Nordcloud is a European leader in cloud implementation, application development, managed services and training. It is a recognised cloud‑native pioneer with a proven track record helping organisations leverage public cloud in a way that balances quick wins, immediate savings and sustainable value. Nordcloud is triple‑certified across Amazon Web Services, Microsoft Azure and Google Cloud Platform – with 10 European hubs, over 1,300 employees and has delivered over 1,000 successful cloud projects for companies ranging from midsize to large corporates. Our clients benefit from multi‑cloud expertise that guides best practices, preempts pitfalls, provides essential technical support and steers teams through cultural change. From strategy planning to application management, we take our customers through the whole cloud journey to drive real business outcomes from cloud technology. Learn more at www.nordcloud.com.

Nordcloud values diversity and is dedicated to providing equal opportunities for all candidates and employees.

DevSecOps Engineer employer: Nordcloud

At Nordcloud, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. As a DevSecOps Engineer in the UK, you'll benefit from flexible working hours, a generous training budget, and comprehensive health care packages, all while contributing to impactful public-sector projects that enhance national security. Our commitment to employee growth and well-being, combined with our status as a leading cloud implementation firm, makes Nordcloud an ideal place for those seeking meaningful and rewarding careers.
Nordcloud

Contact Detail:

Nordcloud Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land DevSecOps Engineer

✨Tip Number 1

Network like a pro! Reach out to folks in the industry on LinkedIn or at meetups. A friendly chat can sometimes lead to job opportunities that aren't even advertised.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repo showcasing your DevSecOps projects. This gives potential employers a taste of what you can do and sets you apart from the crowd.

✨Tip Number 3

Prepare for interviews by practising common questions related to DevSecOps. Think about how you can demonstrate your experience with AWS, Azure, and security automation during the chat.

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team at Nordcloud.

We think you need these skills to ace DevSecOps Engineer

DevSecOps Principles
Shift-Left Security
Automated Testing
Secure SDLC
Cloud-Native Security Engineering
AWS
Azure
CI/CD Pipelines
Infrastructure Automation
Terraform
ARM
Bicep
CloudFormation
Security Tool Integration (SAST, DAST, Dependency Scanning, Secrets Scanning, Container Scanning)
Container Orchestration (Kubernetes/AKS/EKS)
Identity and Access Management

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the DevSecOps Engineer role. Highlight your experience with AWS, Azure, and IaC tools like Terraform. We want to see how your skills align with our needs!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cloud security and how you can contribute to our mission at Nordcloud. Keep it engaging and relevant!

Showcase Your Projects: If you've worked on any relevant projects, make sure to mention them! Whether it's automating security controls or designing CI/CD pipelines, we love to see real-world examples of your work.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy!

How to prepare for a job interview at Nordcloud

✨Know Your Cloud Security Inside Out

Make sure you brush up on your knowledge of AWS and Azure security practices. Be ready to discuss how you've implemented security controls in CI/CD pipelines and your experience with IaC tools like Terraform or CloudFormation. This will show that you understand the core responsibilities of a DevSecOps Engineer.

✨Demonstrate Your Shift-Left Mindset

Prepare examples of how you've embedded security early in the development process. Talk about specific instances where you've automated security testing or integrated security tools into CI/CD workflows. This will highlight your proactive approach to security, which is crucial for this role.

✨Showcase Your Collaboration Skills

Since you'll be working closely with product teams and infrastructure engineers, be ready to share experiences where you've successfully collaborated on security initiatives. Discuss how you’ve engaged stakeholders and shared best practices to uplift security standards across teams.

✨Be Ready for Technical Questions

Expect technical questions related to cloud security, automated testing, and disaster recovery strategies. Brush up on your knowledge of security patterns and compliance frameworks. Being well-prepared will help you demonstrate your expertise and confidence during the interview.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>