Senior DevSecOps Engineer

Senior DevSecOps Engineer

Temporary 63000 - 77000 £ / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Engineer security controls for a cutting-edge cloud platform in financial services.
  • Company: Major financial services organisation with a focus on innovation and security.
  • Benefits: Competitive day rate, hybrid work model, and opportunity to shape enterprise security.
  • Other info: Initial 6-month contract with potential for significant impact on engineering teams.
  • Why this job: Join a dynamic team tackling modern cloud-native security challenges.
  • Qualifications: Proven DevSecOps experience, strong AWS and Kubernetes security expertise.

The predicted salary is between 63000 - 77000 £ per year.

We're supporting a major financial services organisation delivering a next-generation cloud platform that will underpin multiple strategic programmes and engineering teams. As a result, we're looking for a hands-on DevSecOps Engineer to join the platform security function and help build the guardrails, controls and automation that allow product and engineering teams to scale securely by default. This is an engineering-first role focused on AWS, Kubernetes, CI/CD security and platform protection. You'll work alongside Platform Engineering, Developer Platform and Security Architecture teams to ensure security is embedded into the platform rather than bolted on afterwards.

What You'll Be Doing

  • Engineering and maintaining security controls across a multi-tenant AWS platform
  • Implementing and managing IAM controls including SCPs, Permission Boundaries and ABAC
  • Designing secure workload identity and tenant isolation controls
  • Embedding security into CI/CD delivery pipelines
  • Implementing container, IaC, secrets and software composition scanning
  • Building software supply chain security controls including image signing, verification and SBOM generation
  • Developing Policy-as-Code controls using OPA, Rego, Kyverno or similar technologies
  • Securing and hardening EKS environments through RBAC, Network Policies and Admission Controllers
  • Supporting mTLS, PKI and service-to-service authentication initiatives
  • Driving remediation of security findings and penetration test outcomes
  • Creating reusable security modules, patterns and golden paths for engineering teams

Essential Experience

  • Proven experience within DevSecOps, Cloud Security Engineering or Platform Security
  • Strong AWS security expertise, including IAM, SCPs, Permission Boundaries and ABAC
  • Commercial experience securing Kubernetes environments, ideally EKS
  • Terraform and Infrastructure-as-Code experience
  • Building security controls into CI/CD pipelines
  • Experience with workload identity, PKI and mTLS
  • Strong understanding of software supply chain security
  • Scripting or development capability using Python, Go or similar
  • Ability to work effectively with engineers, platform teams and security architects

Desirable Experience

  • Istio and Service Mesh security
  • AWS Private CA and IAM Roles Anywhere
  • Harness CI/CD
  • OPA, Gatekeeper, Kyverno or OSCAL
  • Sigstore, Cosign, SLSA and SBOM tooling
  • Internal Developer Platform (IDP) security
  • AWS Security Specialty, CKS, CISSP or equivalent certifications
  • Experience within regulated financial services environments

Why Apply?

This is an opportunity to shape the security foundations of a major enterprise platform operating at significant scale. You'll be working on modern cloud-native security challenges across AWS, Kubernetes, platform engineering and software supply chain security, helping define the controls and guardrails that every engineering team will rely upon.

Senior DevSecOps Engineer employer: Sanderson

Join a forward-thinking team as a DevOps Engineer, where you'll thrive in a fully remote environment that champions innovation and collaboration. With a focus on employee growth, you'll gain invaluable experience working with cutting-edge cloud technologies and automation tools, all while contributing to critical AWS-hosted platforms. Our supportive work culture encourages continuous learning and development, making this an ideal opportunity for those looking to advance their careers in a dynamic setting.

S

Contact Details:

Sanderson Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior DevSecOps Engineer

Get Engaged in Cybersecurity Communities

Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Sanderson.

Showcase Your Skills Publicly

Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.

Stay On Top of Temp Opportunities

Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Sanderson.

Make Contact with Recruiters Specialising in Cybersecurity

Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Sanderson.

We think you need these skills to ace Senior DevSecOps Engineer

AWS Security
Kubernetes Security
CI/CD Security
IAM Controls
SCPs
Permission Boundaries
ABAC

Some tips for your application 🫡

Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Sanderson a clear view of your capabilities right off the bat.

Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.

Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Sanderson; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!

Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Sanderson.

How to prepare for a job interview at Sanderson

Brush Up on Technical Skills

Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Sanderson for the Senior DevSecOps Engineer, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.

Show Your Problem-Solving Prowess

Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!

Demonstrate Your Adaptability

As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Sanderson.

Bring Relevant Certifications

If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Senior DevSecOps Engineer role at Sanderson.