At a Glance
- Tasks: Lead DevSecOps practices and enhance security across digital products.
- Company: Capgemini, a prime Digital Delivery Partner for CLIENT.
- Benefits: Competitive daily rate, hybrid work model, and opportunities for professional growth.
- Other info: Join a dynamic team with a focus on innovation and collaboration.
- Why this job: Make a real impact on digital transformation while working with cutting-edge technologies.
- Qualifications: Proven experience in DevSecOps, CI/CD, and cloud environments.
The predicted salary is between 60000 - 80000 £ per year.
Duration: contract to run until 31/03/2027
Location: Hybrid role. Predominantly remote with visits to Bristol and London for events or team meetings when necessary
Rate: up to £690 p/d Umbrella inside IR35
Clearance required: SC Clearance Eligibility is essential
Role purpose / summary
We are seeking an experienced, client-facing Lead DevSecOps Engineer to drive and coordinate DevSecOps practices across multiple digital products delivered as part of a wider CLIENT business and digital transformation programme, where Capgemini is the client’s prime Digital Delivery Partner. Products will be deployed across the CLIENT digital estate (CLIENTCloud), including CLIENT’s instances of Microsoft Azure (CLIENTCloud ACE / i-ACE), AWS (CLIENTCloud ICE) and Oracle Cloud Infrastructure (OCI / CLIENTCloud OCE).
You will embed security, compliance and automation into the software delivery lifecycle, ensuring platforms and applications meet stringent security and operational standards. You will also establish consistent, documented processes used by DevSecOps engineers across each environment, including a coordinated approach for releasing updates across the integrated set of products and platforms in scope.
This role requires deep expertise in CI/CD pipelines, delivery workflows and security tooling across these cloud environments, alongside strong collaboration with developers, DevSecOps engineers, infrastructure engineers and test teams.
Key Responsibilities
- Design, implement, document and continuously improve DevSecOps practices across the delivery teams, including:
- Secure, automated CI/CD pipelines
- Security scanning integrated into build, test and deployment workflows
- Vulnerability lifecycle management, including allowlist processes and risk acceptance where required
- Secrets management and identity/access management
- Policy enforcement for workloads, container images and infrastructure
- Observability, monitoring, logging and audit controls
- Partner with developers to embed secure-by-design engineering and ensure compliance with CLIENT security standards.
- Enable and govern Infrastructure as Code (IaC) practices across teams and environments.
- Contribute to incident response, patching cycles and compliance reporting, ensuring lessons learned are captured and actions tracked.
- Document security processes, controls and operational runbooks in Confluence.
Key Skills and Experience
Essential
- Proven experience as a DevSecOps Lead, establishing and operating DevSecOps ways of working and associated tooling across the following areas (hands-on and leading others):
- CI/CD and GitOps (e.g. GitHub Actions, Argo CD, Argo Rollouts)
- Security and compliance tooling (e.g. Trivy scanning and vulnerability management, HashiCorp Vault, cert-manager)
- Containers and orchestration (e.g. Docker, AWS EKS)
- Infrastructure as Code (e.g. Terraform)
- Observability (e.g. Grafana, Loki)
- Scripting and automation (e.g. Python, Bash)
- Cloud and networking fundamentals (e.g. AWS IAM, S3, network policies)
- Experience delivering within the UK Government Digital Service (GDS) lifecycle on a public sector engagement.
- Experience working with and leading distributed and hybrid teams.
- Demonstrated ability to work across cross-functional teams, particularly with developers, testers and DevSecOps engineers.
- Strong facilitation, communication and stakeholder management skills, with experience influencing at multiple levels.
Highly Desirable
- Experience leading DevSecOps engineering for products hosted on the CLIENT digital estate, spanning Microsoft Azure (CLIENTCloud ACE / i-ACE), AWS (CLIENTCloud ICE) and Oracle Cloud Infrastructure (OCI / CLIENTCloud OCE).
All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!
DevSecOps Engineering Lead in Slough employer: Undisclosed
At Capgemini, we pride ourselves on fostering a dynamic and inclusive work culture that empowers our employees to thrive. As a DevSecOps Engineering Lead, you will benefit from flexible hybrid working arrangements, competitive rates, and the opportunity to collaborate with talented professionals across multiple cloud environments. With a strong focus on employee growth and development, we offer numerous pathways for career advancement while contributing to impactful digital transformation projects within the public sector.
StudySmarter Expert Advice🤫
We think this is how you could land DevSecOps Engineering Lead in Slough
✨Get Engaged in Cybersecurity Communities
Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Undisclosed.
✨Showcase Your Skills Publicly
Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.
✨Stay On Top of Temp Opportunities
Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Undisclosed.
✨Make Contact with Recruiters Specialising in Cybersecurity
Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Undisclosed.
We think you need these skills to ace DevSecOps Engineering Lead in Slough
Some tips for your application 🫡
Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Undisclosed a clear view of your capabilities right off the bat.
Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.
Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Undisclosed; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!
Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Undisclosed.
How to prepare for a job interview at Undisclosed
✨Brush Up on Technical Skills
Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Undisclosed for the DevSecOps Engineering Lead, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.
✨Show Your Problem-Solving Prowess
Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!
✨Demonstrate Your Adaptability
As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Undisclosed.
✨Bring Relevant Certifications
If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the DevSecOps Engineering Lead role at Undisclosed.