Senior DevSecOps Engineer
Senior DevSecOps Engineer, Threat Modelling, AI, Azure, Cursor, Codex, Anthropic, Permanent
Harris Global are currently looking for a Senior DevSecOps Engineer to join our client on a permanent basis. The role will join an established security function, helping to embed security across the software development life cycle and support the secure delivery of AI powered cloud applications.
Rather than building a function from scratch, you'll be responsible for evolving existing capabilities, enhancing automation and partnering closely with engineering teams to ensure security remains an integral part of the development process.
Responsibilities:
- Lead threat modelling activities across a portfolio of products, ensuring security risks are identified and managed throughout the development life cycle.
- Drive vulnerability management by validating findings, distinguishing genuine risks from false positives and working with engineering teams to prioritise remediation.
- Coordinate and track penetration testing activities, ensuring recommendations are actioned and security improvements are delivered.
- Develop, maintain and enhance DevSecOps tooling and security automation to improve efficiency and reduce manual effort.
- Continuously improve CI/CD security processes and support the ongoing evolution of the organisation's DevSecOps roadmap.
- Collaborate closely with software engineers to provide practical security guidance and support the delivery of secure applications.
- Conduct security design reviews for new products and features, ensuring security considerations are built into solutions from the outset.
- Monitor the effectiveness of security controls, automations and scanning tools, resolving issues and identifying opportunities for improvement.
- Contribute to the secure adoption of AI technologies and cloud-native services across the engineering estate.
Key Skills & Experience:
- Proven experience in a DevSecOps role.
- Must have strong AI experience
- Strong understanding of DevSecOps principles and experience embedding security into modern software development and CI/CD pipelines.
- Experience securing cloud environments, ideally Microsoft Azure.
- Knowledge of application security concepts including threat modelling, vulnerability management and security testing.
- Experience building or enhancing security tooling and automation using Scripting or programming languages.
- Familiarity with security scanning tools, penetration testing processes and vulnerability triage.
- Understanding of secure software development practices and modern engineering environments.
- Exposure to AI-assisted development tools or an interest in securing AI-enabled applications.
- Knowledge of security frameworks, identity and access management, and security best practices.
- Excellent communication and stakeholder management skills with the ability to work collaboratively across engineering teams.
- Experience with offensive security or penetration testing.
- Experience securing containerised and cloud-native applications.
- Familiarity with Azure DevOps, GitHub Actions or similar CI/CD platforms.
- Exposure to Kubernetes, Infrastructure as Code and cloud security tooling.
Senior DevSecOps Engineer, Threat Modelling, AI, Azure, Cursor, Codex, Anthropic, Permanent