- Company Name
- Raytheon UK
- Job Title
- DevSecOps Engineer
- Job Description
-
**Job Title:** DevSecOps Engineer
**Role Summary:**
Integrate security into the software development life cycle (SDLC) for defence and aerospace systems. Automate security testing, implement secure container and OS hardening, and enforce compliance with DISA STIG, NIST, CIS, ISO27001, and FIPS standards. Lead efforts to embed a security culture across development teams.
**Expectations:**
- Deliver secure, mission‑critical systems for defence, intelligence, and cyber sectors.
- Drive continuous improvement of security practices and tooling.
- Communicate effectively with developers, QA, and operations to promote security best‑practice adoption.
**Key Responsibilities:**
1. Lead the integration of security practices into the SDLC.
2. Automate security testing in development, integration, and programme test environments.
3. Apply threat modelling, risk assessment, and vulnerability management to all projects.
4. Harden OS (RHEL v9+, Ubuntu Pro) and Windows Server using DISA STIG protocols.
5. Secure rootless containers, NAS file shares, and Active Directory integration.
6. Implement and manage OCI container solutions (Docker, Podman, Kubernetes).
7. Configure and maintain static analysis tools (Sonar, Fortify) and test automation frameworks.
8. Collaborate across software delivery functions to build a company‑wide security culture.
**Required Skills:**
- Linux (RHEL v9+, Ubuntu Pro) security hardening and SELinux expertise.
- Windows Server STIG compliance.
- Container security (Docker, Podman, Kubernetes, rootless containers).
- DISA STIG process implementation.
- Static code analysis (Sonar, Fortify) and automated security testing.
- Threat modelling, risk assessment, and vulnerability management.
- CI/CD tooling (Jenkins, Git, Bitbucket, Jira).
- Experience with configuration management (Ansible, Chef, Puppet, Terraform optional).
- Familiarity with monitoring and observability (Prometheus, Grafana) and artifact repositories (JFrog Artifactory).
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related discipline (preferred).
- Demonstrated compliance with DISA STIG, NIST, CIS, ISO27001, or FIPS standards.
- Certifications such as CompTIA Security+, CISSP, or equivalent are advantageous.
---
Great malvern, United kingdom
On site
31-10-2025