TL;DR
DevSecOps Engineer: Engineering, automating, and maintaining security controls across CI/CD pipelines, cloud workloads, and the application lifecycle with an accent on secure by design practices and vulnerability reduction. Focus on integrating security controls into Azure DevOps and GitHub Actions, automating SAST/SCA/DAST, and ensuring adherence to best-in-class security standards.
Location: Onsite in London, England
Company
hirify.global provides enterprise data management solutions and investment intelligence to the global investment community.
What you will do
- Integrate security controls into CI/CD pipelines (Azure DevOps, GitHub Actions, Jenkins).
- Implement automated SAST, SCA, DAST, container scanning, and secrets management.
- Collaborate with Development and DevOps teams to embed secure design principles and practices.
- Engineer and maintain tooling for vulnerability management across code, containers, pipelines, and cloud.
- Automate security guardrails across Azure resources, Kubernetes, API gateways, and serverless workloads.
- Support and enhance security policy deployment (IAM, key vaults, network controls).
Requirements
- Experienced in DevOps or platform engineering with a strong security mindset.
- Hands-on experience with at least one CI/CD platform (Azure DevOps preferred).
- Good understanding of application security principles (OWASP Top 10, SANS/CWE Top 25).
- Experience integrating or running security scanners: SAST, SCA, DAST, IaC scanning.
- Experience with infrastructure as code (Terraform, ARM/Bicep, Helm).
- Familiarity with cloud security (preferably Azure) and container security best practices.
Nice to have
- Kubernetes (AKS), service mesh, container runtime security.
- Experience integrating security telemetry into SIEM/SOAR pipelines.
- Exposure to Zero Trust design principles and automated security testing frameworks.
Culture & Benefits
- Committed to promoting diversity and inclusion throughout the business.
- Focus on improving opportunities regardless of background or circumstances.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →