SC Cleared DevSecOps Engineer - Inside IR35 - Remote
Role: SC Cleared DevSecOps Engineer
Location: Remote with odd travel to client sites.
Clearances: Must have active SC
About Us:
Solirius Reply, part of the Reply Group, is a technology consultancy and digital transformation partner that helps organisations solve complex challenges through strategy, design, engineering, and delivery.
We work closely with our clients to deliver secure, accessible, user-focused services that evolve with their needs. By combining deep technical expertise with people-centred design, we create solutions that deliver meaningful, lasting impact.
Our consultants partner directly with client teams, embedding into organisations to understand their goals, challenges, and users. This collaborative approach enables us to deliver tailored solutions that drive measurable outcomes across public and private sectors.
Past and present clients include the Ministry of Justice, Department for Education, Ministry of Housing, Communities and Local Government, UEFA, International Olympic Committee, and Mercedes-Benz. Our services span the full digital delivery life cycle, including architecture, engineering, delivery management, user-centred design, business analysis, data, DevOps, and AI.
We operate as a collaborative and inclusive organisation that empowers our people to take ownership, innovate, and develop their expertise. As an equal opportunities employer, we are committed to encouraging equality, diversity, and social mobility, while creating opportunities for our teams to work on meaningful projects that deliver lasting impact.
About You:
You are a motivated and adaptable professional with a strong analytical mindset and a passion for using technology to solve real-world problems. You enjoy working in collaborative, agile teams and take pride in delivering high-quality solutions that make a tangible impact. With strong communication skills and a consultative approach, you're comfortable engaging with clients, understanding their needs, and translating them into effective outcomes.
The Role:
We are seeking an experienced DevSecOps Engineer to help secure, build, and optimise our AWS cloud infrastructure and deployment pipelines. In this role, you will bridge the gap between cloud architecture, pipeline automation, and security engineering. You will actively identify and remediate AWS vulnerabilities, design secure architecture, and embed security practices directly into our CI/CD pipelines and development workflows.
Key Responsibilities
-
CI/CD & Pipeline Security: Build, maintain, and secure automation pipelines using Concourse and GitHub Actions, integrating automated security scanning (SAST/DAST/dependency checks) directly into deployment workflows.
-
Infrastructure as Code (IaC): Design, deploy, and manage scalable cloud infrastructure using Terraform, enforcing security best practices through code reviews and policy-as-code tools.
-
AWS Architecture & Networking: Architect and engineer secure AWS environments, designing robust networking topology (VPCs, transit gateways, security groups, IAM roles, and private endpoints).
-
Vulnerability & CVE Remediation: Proactively identify, assess, and remediate AWS Common Vulnerabilities and Exposures (CVEs) across cloud infrastructure, container environments, and services.
-
Development & Refactoring: Write clean, maintainable automation scripts and microservices using Python and JavaScript, employing Test-Driven Development (TDD) and Behavior-Driven Development (BDD) methodologies.
-
Security Advocacy: Collaborate closely with development and operations teams to champion security-first practices across the software development life cycle (SDLC).
Required Skills & Experience
-
Cloud Engineering: Hands-on expertise with AWS services, AWS security features, and secure network design/architecture.
-
Infrastructure as Code: Proficiency with Terraform for provisioning and managing cloud infrastructure.
-
CI/CD Expertise: Proven track record configuring and managing Concourse and GitHub Actions.
-
Development Skills: Professional proficiency in Python and JavaScript for tooling, automation, and refactoring.
-
Testing Practices: Strong experience applying TDD and BDD frameworks to infrastructure and software codebases.
-
Vulnerability Management: Deep understanding of cloud security standards, AWS security tools (eg, Security Hub, GuardDuty, Inspector), and hands-on experience patching/remediating AWS CVEs.
Desirable Qualifications
-
Relevant certifications such as AWS Certified Security - Specialty or AWS Certified DevOps Engineer - Professional.
-
Knowledge of container security (Docker, Kubernetes) and compliance frameworks (CIS benchmarks, ISO 27001, SOC 2).