Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
The Lead DevSecOps Engineer is responsible for driving the integration of security principles into the development and operations processes. This role will champion a security-first culture, design and implement robust security controls, and automate security testing and compliance measures. By collaborating closely with development, operations, and security teams, the Lead DevSecOps Engineer will ensure the confidentiality, integrity, and availability of our systems and applications.
Responsibilities:
Secure CI/CD Pipeline Management (Azure DevOps): Design, implement, manage, and optimise secure CI/CD pipelines and related processes within Azure DevOps.
Infrastructure as Code (IaC) with Security: Implement, maintain, and secure infrastructure using Terraform within Azure DevOps pipelines, incorporating security best practices.
Automated Security Testing and Vulnerability Management: Integrate security scanning tools (SAST, DAST, SCA) and implement automated vulnerability management processes.
Security Collaboration and Requirements: Collaborate with security teams to define security requirements and implement security controls across the SDLC.
Secrets Management and Security Monitoring: Implement and manage secrets management solutions (e. g., Azure Key Vault) and security monitoring/logging.
Security Assessments and Hardening: Conduct regular security assessments, penetration testing, and infrastructure hardening to minimise attack surface.
Container Security (Docker/Kubernetes): Implement and manage container security scanning and vulnerability management for Docker and Kubernetes environments.
Network Security within IaC: Implement and manage network security controls within the infrastructure-as-code.
Policy as Code (OPA) Implementation: Implement and manage Policy as Code (OPA) for enforcing security and compliance policies.
DevSecOps Mentorship and Training: Coach and guide engineering teams on secure coding practices and DevSecOps principles.
Requirements:
Leadership and Strategy: Proven experience leading/mentoring DevSecOps or Security Engineering teams, defining technical roadmap, and driving security architecture standards.
Security Metrics and Executive Reporting: Ability to define key risk indicators (KRIs/KPIs), build operational dashboards, and translate technical security metrics into clear executive reports for senior stakeholders.
Languages: Advanced Python (for designing complex automation frameworks, custom tooling, and security integrations).
Cloud Architecture and IaC: Deep expertise in Azure and Terraform.
CI/CD and GitOps: Advanced Azure DevOps pipeline architecture alongside GitOps implementations (FluxCD, Helm, or Kustomize).
Container Security and Orchestration: Production-grade Kubernetes and Docker security architecture, image signing, and runtime defence.
Stakeholder Management: Ability to bridge business risk and technical execution, collaborating with Dev, Sec, and Ops leads.
Nice-to-Have Skills (Secondary / Bonus):
AppSec and Pipeline Security: Designing automated SAST/DAST/SCA governance and vulnerability management reporting workflows.
Offensive Security and Hardening: Hands-on threat modelling, penetration testing background, and infrastructure attack-surface reduction.
Secrets and Identity Architecture: Enterprise-wide secrets lifecycle management (e. g., Azure Key Vault, Vault, IAM governance).
Network and Zero Trust Security: Designing cloud network segmentation and micro-segmentation natively within IaC.
Experience
6-10 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.