Senior DevSecOps Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior DevSecOps Engineer (DevSecOps): Delivering secure applications by integrating application security controls into CI/CD pipelines with an accent on SAST, DAST, SCA, secrets detection, and software supply-chain security. Focus on hands-on security enablement across development, platform, operations, and information security, including threat modelling, secure design reviews, and auditable control governance.
Location: North London, UK
Company
is part of Super Group, a digital gaming company behind leading Sports and iGaming brands.
What you will do
- Integrate and operate application security controls in CI/CD pipelines, including SAST, DAST, SCA, secrets detection, and dependency risk scanning.
- Support secure SDLC practices such as branch protection, quality gates, secure build/release controls, and artifact integrity validation.
- Collaborate on threat modelling and secure design reviews; support developers with vulnerability triage and remediation.
- Tune security tooling to reduce false positives and developer friction; maintain security tooling integrations across CI/CD systems (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
- Define DevSec security standards and provide evidence/control mappings for audits, risk assessments, and regulatory reviews.
- Contribute to security enablement initiatives, including cloud-native and container security practices.
Requirements
- Strong grounding in application security concepts and secure coding (OWASP Top 10, API security, dependency risk).
- Hands-on knowledge of SAST, DAST, SCA, and software supply-chain security.
- Hands-on expertise with containers and orchestration platforms (Docker, Kubernetes), including implementing container security across build, registry, and runtime.
- Proven experience securing CI/CD pipelines and developer toolchains.
- Knowledge of Infrastructure as Code (Terraform, Bicep, CloudFormation), secrets/key management, and cloud identity & access management.
- Solid understanding of information security frameworks (e.g., ISO 27001) and experience operating in regulated/audited environments.
Culture & Benefits
- Learning and development programmes to level up quickly.
- Performance feedback to support development and career growth.
- Employee Assistance Programme for you and your family.
- Private health care, life assurance & income protection, and company pension.
Hiring process
- Application review; if no response within 2 weeks, assume the application was not successful.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →