Senior DevSecOps Engineer in London

Senior DevSecOps Engineer in London

London Temporary 63000 - 77000 £ / year (est.) Home office (partial)
Sanderson Careers

At a Glance

  • Tasks: Engineer and maintain security controls for a cutting-edge cloud platform.
  • Company: Major financial services organisation with a focus on innovation.
  • Benefits: Competitive day rate, hybrid work model, and opportunity to shape security foundations.
  • Other info: Diverse and inclusive workplace with excellent career growth opportunities.
  • Why this job: Tackle modern cloud-native security challenges and make a real impact.
  • Qualifications: Experience in DevSecOps, AWS security, and Kubernetes environments required.

The predicted salary is between 63000 - 77000 £ per year.

Location: London/ Hybrid

Day Rate: Up to £650 (OUTSIDE IR35)

Contract: Initial 6 Months

We're supporting a major financial services organisation delivering a next-generation cloud platform that will underpin multiple strategic programmes and engineering teams. As a result, we're looking for a hands-on DevSecOps Engineer to join the platform security function and help build the guardrails, controls and automation that allow product and engineering teams to scale securely by default. This is an engineering-first role focused on AWS, Kubernetes, CI/CD security and platform protection. You'll work alongside Platform Engineering, Developer Platform and Security Architecture teams to ensure security is embedded into the platform rather than bolted on afterwards.

What You'll Be Doing

  • Engineering and maintaining security controls across a multi-tenant AWS platform
  • Implementing and managing IAM controls including SCPs, Permission Boundaries and ABAC
  • Designing secure workload identity and tenant isolation controls
  • Embedding security into CI/CD delivery pipelines
  • Implementing container, IaC, secrets and software composition scanning
  • Building software supply chain security controls including image signing, verification and SBOM generation
  • Developing Policy-as-Code controls using OPA, Rego, Kyverno or similar technologies
  • Securing and hardening EKS environments through RBAC, Network Policies and Admission Controllers
  • Supporting mTLS, PKI and service-to-service authentication initiatives
  • Driving remediation of security findings and penetration test outcomes
  • Creating reusable security modules, patterns and golden paths for engineering teams

Essential Experience

  • Proven experience within DevSecOps, Cloud Security Engineering or Platform Security
  • Strong AWS security expertise, including IAM, SCPs, Permission Boundaries and ABAC
  • Commercial experience securing Kubernetes environments, ideally EKS
  • Terraform and Infrastructure-as-Code experience
  • Building security controls into CI/CD pipelines
  • Experience with workload identity, PKI and mTLS
  • Strong understanding of software supply chain security
  • Scripting or development capability using Python, Go or similar
  • Ability to work effectively with engineers, platform teams and security architects

Desirable Experience

  • Istio and Service Mesh security
  • AWS Private CA and IAM Roles Anywhere
  • Harness CI/CD
  • OPA, Gatekeeper, Kyverno or OSCAL
  • Sigstore, Cosign, SLSA and SBOM tooling
  • Internal Developer Platform (IDP) security
  • AWS Security Specialty, CKS, CISSP or equivalent certifications
  • Experience within regulated financial services environments

Why Apply?

This is an opportunity to shape the security foundations of a major enterprise platform operating at significant scale. You'll be working on modern cloud-native security challenges across AWS, Kubernetes, platform engineering and software supply chain security, helping define the controls and guardrails that every engineering team will rely upon.

Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

Senior DevSecOps Engineer in London employer: Sanderson Careers

Join a forward-thinking company that values innovation and collaboration, offering a fully remote role as a Technical Architect. With a strong emphasis on employee growth, you will have access to continuous learning opportunities and the chance to mentor junior colleagues, all while contributing to impactful digital solutions. Our inclusive work culture fosters creativity and teamwork, making it an excellent environment for professionals looking to make a meaningful difference in technology.

Sanderson Careers

Contact Details:

Sanderson Careers Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior DevSecOps Engineer in London

Get Engaged in Cybersecurity Communities

Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Sanderson Careers.

Showcase Your Skills Publicly

Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.

Stay On Top of Temp Opportunities

Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Sanderson Careers.

Make Contact with Recruiters Specialising in Cybersecurity

Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Sanderson Careers.

We think you need these skills to ace Senior DevSecOps Engineer in London

AWS Security
Kubernetes Security
CI/CD Security
IAM Controls
SCPs
Permission Boundaries
ABAC

Some tips for your application 🫡

Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Sanderson Careers a clear view of your capabilities right off the bat.

Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.

Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Sanderson Careers; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!

Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Sanderson Careers.

How to prepare for a job interview at Sanderson Careers

Brush Up on Technical Skills

Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Sanderson Careers for the Senior DevSecOps Engineer, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.

Show Your Problem-Solving Prowess

Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!

Demonstrate Your Adaptability

As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Sanderson Careers.

Bring Relevant Certifications

If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Senior DevSecOps Engineer role at Sanderson Careers.