Start Your Search Here

push notification bell

Would you like to receive notifications about Engineering jobs in Surrey?

push notification bell

You have blocked notifications

Oops! You have blocked notifications. Click here for more info

You have blocked notifications, please check your browser settings.

push notification bell

You're currently subscribed to job notifications

Want to change your notifications for job alerts?

push notification bell

Subscribe to notifications

You will no longer receive notifications

Job Search

Oscar Associates Limited

Surrey / Global

DevSecOps Engineer

  • £80,000

Job Summary

Salary Range:
£80,000
Benefits:
Training
Apply Now

Job Description

DevSecOps Engineer - Azure / Application Security

We're working with an established organisation looking to appoint an experienced DevSecOps Engineer to strengthen its Azure deployment and application security capabilities.

This is a hands-on position combining Azure DevOps, cloud infrastructure and application security. You'll take ownership of CI/CD pipelines, Infrastructure-as-Code and security testing, while helping development teams embed secure practices throughout the software delivery lifecycle.

The Role

You'll be responsible for:

Designing and maintaining CI/CD pipelines within Azure DevOps

Deploying Azure applications and infrastructure using Terraform

Supporting Azure services including App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints and Front Door/WAF

Introducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detection

Integrating SAST, DAST, dependency and container scanning into development pipelines

Conducting web application security testing using Burp Suite, OWASP ZAP or similar tools

Identifying and managing vulnerabilities against OWASP Top 10 and CVSS principles

Implementing secrets detection, credential rotation and secure Key Vault practices

Strengthening software supply-chain security through SBOM generation, dependency scanning and artefact signing

Supporting API security testing, threat modelling and third-party penetration tests

Configuring Azure-native security tooling, including Defender for Cloud, Azure Policy, Sentinel and Azure Monitor

Enforcing identity and access controls across Entra ID, RBAC, Conditional Access and PIM

Supporting compliance with frameworks such as Cyber Essentials Plus, ISO 27001 and GDPR

Mentoring junior engineers and helping developers adopt secure coding and deployment practices

What We're Looking For

You'll need:

Around three to five years' experience across DevOps, platform engineering or application security

Strong hands-on experience with Microsoft Azure and Azure DevOps

Proven experience securing web applications in a production environment

</...

Apply Now

Similar Opportunities

View all jobs