Start Your Search Here

push notification bell

Would you like to receive notifications about IT & Computers jobs in London?

push notification bell

You have blocked notifications

Oops! You have blocked notifications. Click here for more info

You have blocked notifications, please check your browser settings.

push notification bell

You're currently subscribed to job notifications

Want to change your notifications for job alerts?

push notification bell

Subscribe to notifications

You will no longer receive notifications

Job Search

Sanderson Recruitment

London / Global

Security Engineer (DevSecOps)

  • £550 - £650 per day

Job Summary

Salary Range:
£550 - £650 per day
Job Type:
Contract
Apply Now

Job Description

Security Engineer (DevSecOps)

Rate - £550 - £650 Inside IR35

Duration - 6 months initial

Location - London once a week on site

Reports to: Head of Security Architecture and Engineering

The role:

This is a hands-on engineering role focused on building security into software as developed and deployed. You'll work across three workstreams alongside three Senior DevSecOps Engineers. You'll pick up work where it's most needed, keep security consistent across all three workstreams and make sure nothing falls between them.

It suits a software, DevOps or platform engineer who has already built security into their day-to-day work and wants to take it further. You'll get exposure to platform, AI and integration security.

What you'll do

Set up and tune security scanning in CI/CD pipelines, cut down false positives and help developers fix real issues.

Build shared security modules, policy libraries and templates that all three teams can reuse.

Review code, infrastructure-as-code and configuration changes for security issues.

Handle day-to-day vulnerability management, including pen test findings: prioritise what's genuinely exploitable, track fixes and check they've worked.

Help run threat modelling sessions in IriusRisk and turn the results into backlog tickets.

Look after secrets management, certificates and access reviews and keep security documentation, control evidence and CAB records up to date.

Be the go-to person when security is blocking a delivery team, cover for the senior engineers when priorities shift and flag where teams are solving the same problem in different ways.

What you'll need

Hands-on experience in software engineering, DevOps or platform engineering with a strong security focus, or in security engineering.

Experience with CI/CD and security scanning tools (SAST, SCA, secrets, IaC and container scanning).

Python or Bash and Terraform.

AWS fundamentals including IAM, plus working knowledge of containers and Kubernetes.

A good grasp of vulnerability management, including CVSS, EPSS and judging whether an issue is really exploitable.

Clear written communication and comfortable switching between teams.

<...

Apply Now

Similar Opportunities

View all jobs