- Company Name
- Mentmore Recruitment
- Job Title
- Senior DevSecOps Engineer
- Job Description
-
Job title: Senior DevSecOps Engineer
Role Summary:
Lead the integration of security into the DevOps process, designing and maintaining robust CI/CD pipelines that embed testing, compliance, and monitoring. Collaborate with development and tooling teams to streamline workflows, enforce secure coding practices, evaluate emerging tools, and document best practices. Provide guidance on version control, branching, and secure CI/CD patterns, ensuring high‑quality, compliant releases and continuous improvement of the DevSecOps pipeline.
Expectations:
- Deliver secure, automated CI/CD pipelines that meet quality and compliance standards.
- Reduce security risk in the SDLC through proactive automation and monitoring.
- Influence and educate teams on secure coding, DevOps best practices, and tool usage.
- Evaluate and adopt tools that enhance pipeline efficiency, developer experience, and security posture.
Key Responsibilities:
- Design, implement, and maintain end‑to‑end CI/CD pipelines, integrating unit, integration, security, and compliance tests.
- Automate security testing and compliance checks within pipelines.
- Identify and eliminate bottlenecks in SDLC, creating repeatable deployment, configuration, and monitoring patterns.
- Partner with development teams to onboard standardized DevOps practices, secure coding guidance, and branching strategies.
- Evaluate and recommend tooling (CI/CD, scanning, monitoring) and stay current with industry trends and emerging technologies.
- Document security and DevOps processes, create knowledge‑base articles, and deliver workshops on secure development.
- Assist onboarding of projects and teams to central DevSecOps infrastructure and template pipelines.
Required Skills:
- Proven experience in DevSecOps, Agile software delivery, and SDLC.
- Deep knowledge of CI/CD tooling (GitLab CI, GitHub Actions, Argo CD, Concourse).
- Hands‑on experience with AWS, Azure, or GCP; Docker and Kubernetes container orchestration.
- Familiarity with security standards and frameworks (OWASP, NIST, ISO 27001).
- Strong scripting/automation skills (Bash, Python, YAML).
- Excellent communication skills to explain DevSecOps concepts to technical and non‑technical stakeholders.
- Ability to mentor and influence cross‑functional teams.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Software Engineering, or related field.
- Preferred: Certified AWS Solutions Architect, AWS Certified Security – Specialty, Azure Security Engineer Associate, or equivalent cloud security certifications.
- Additional certifications in DevSecOps, security scanning, or automation tools are a plus.