DevSecOps Pentester Location: London, UK (Hybrid 23 days onsite) Type: Contract (6 months) | Rate: Market| Start Date: ASAP About the Role Our client, a leading global organization, is looking for an experienced DevSecOps Pentester to join a leading security team in London. Youll perform penetration tests and security assessments across CI/CD pipelines, cloud environments, and applications, integrating automated … Required Skills & Experience Strong application security knowledge (OWASP Top 10, API security). Manual pentesting experience on modern web apps, APIs, and CI/CD pipelines. Deep understanding of DevSecOps practices, secure SDLC, threat modeling, and secure design review. Proficiency in automating security checks using Jenkins, GitLab, Ansible, or similar tools. Secure coding knowledge and familiarity with common developer pitfalls. … fast-paced environments with developers and DevOps teams. Nice to Have OSCP, OSWA, CRTO, GWAPT, GPEN, eWPT certifications. Azure Security Engineer Associate or AWS Security Specialty. Kubernetes security or DevSecOps-focused certifications. Strong analytical, problem-solving, reporting, and customer engagement skills. Why Join Lead security testing in high-impact CI/CD and cloud-native projects. Collaborate with a cutting More ❯
cloud platforms such as AWS, Azure, understanding cloud-native security services, and expertise in configuring security groups, IAM policies, and network access controls. In depth experience and understanding of DevSecOps principles, emphasising the integration of security practices into the DevOps pipeline. This includes knowledge of shift left security, implementing security as code and tools, such as Terraform, Bicep, CloudFormation. Demonstrable More ❯
IaC/CaC tools such as Terraform, Ansible. Monitor, troubleshoot, and optimize systems, networks, and application performance across hybrid environments. Collaborate with security, development, and operations teams to enforce DevSecOps best practic-es. Participate in incident response, root cause analysis, and implement long-term fixes. Maintain and document configurations, processes, and network topologies. Required Qualifications Extensive hands-on experience with More ❯
IaC/CaC tools such as Terraform, Ansible. Monitor, troubleshoot, and optimize systems, networks, and application performance across hybrid environments. Collaborate with security, development, and operations teams to enforce DevSecOps best practic-es. Participate in incident response, root cause analysis, and implement long-term fixes. Maintain and document configurations, processes, and network topologies. Required Qualifications Extensive hands-on experience with More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Robert Half
practices to deliver high-quality software as well as value to end customers as early as possible. You will create large-scale distributed systems out of microservices. Efficiently utilise DevSecOps tools and practices to build and deploy software Oversee or take part in the entire cycle of software consulting and delivery Profile You can skillfully write high-quality, well-tested More ❯
security teams to implement automation around deployment, observability, and compliance. You will identify opportunities to eliminate toil and automate the triage of issues to improve overall operational stability Champion DevSecOps practices by integrating security controls into the platform lifecycle. Successful candidates will have around 7+ years of commercial experience in software engineering, platform engineering, or site reliability engineering, including 3+ More ❯
triggers; ensure data integrity and performance. Integrate with Identity and Access Management (IdAM) systems. Ensure secure coding practices and compliance with platform security posture. Collaborate with UX, QA, and DevSecOps teams to deliver accessible, performant, and maintainable features. Monitor and troubleshoot applications Contribute to design discussions, code reviews, and maintain documentation in Confluence. Essential Technical Skills Languages & Frameworks TypeScript (Proficient More ❯
City of London, London, England, United Kingdom Hybrid / WFH Options
INTEC SELECT LIMITED
years’ experience in security architecture. Proven hands-on experience with SIEM, Proxy, EDR, DLP, and SEG implementations. Strong expertise across cloud (AWS, Azure, GCP), networks, and applications. Familiarity with DevSecOps, zero trust, secure SDLC, and threat modelling. In-depth knowledge of Active Directory security and networking concepts. Relevant certifications (e.g., CISSP-ISSAP, TOGAF, SABSA, AWS/Azure Security). Excellent More ❯
Sheffield, South Yorkshire, England, United Kingdom Hybrid / WFH Options
Reed
PowerShell, JavaScript ) and integration protocols (e.g., LDAP, SAML, OAuth ). Excellent communication and stakeholder management skills. Desirable: Experience with cloud IAM solutions (e.g., Azure AD, AWS IAM ), familiarity with DevSecOps practices and tools, and relevant certifications such as CISSP or CISM. Benefits: Opportunity to work in a hybrid model Engage in a significant project with a historic company undergoing a More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
VIQU IT Recruitment
DevSecOps Engineer – 6-month contract – Outside of IR35 – Remote/London My Customer is seeking a highly skilled DevSecOps Engineer with deep expertise in Cloud Security. This role is critical in strengthening their cloud security posture, ensuring compliance, and embedding security across our development pipelines. The ideal candidate will be hands-on, business-minded, and capable of bridging the gap … between cyber risk and business needs. This is a new DevSecOps role within the organisation. Experience with setting up a DevSecOps environment would be highly beneficial. Skills & Experience from the DevSecOps Engineer Previous experience working in a DevSecOps role – Outside IR35 Strong experience with Wiz – must be able to make recommendations on improvements Proven track record in DevSecOps pipeline design … Cloud Security best practices (identity, monitoring, compliance, and remediation). Ability to create clear architecture and security maps. Strong communication skills to translate technical issues into business context. The DevSecOps Engineer is required to work onsite, 1 day a week in Central London. Apply now to speak with VIQU IT in confidence. Or reach out to Connor Smal via the More ❯
DevOps/DevSecOps Engineer – SC Cleared | AWS Outside IR35 | ASAP Start SR2 is seeking an SC Cleared DevOps Engineer with a strong DevSecOps focus to join a high-impact government programme. This role combines deep technical delivery with the ability to engage, influence, and align central and distributed stakeholders towards secure, modernised ways of working.You’ll manage and evolve secure … security best practice across the delivery lifecycle. You’ll also play a key role in the migration from Kubernetes to serverless architectures. Essential Skills: Active SC Clearance Strong AWS DevSecOps experience (Lambda, S3, CloudWatch, Athena, IAM, RDS) CI/CD: GitLab, GitHub Actions/Enterprise IaC: Terraform Scripting: Python Event-driven architecture: Kafka AWS networking (VPC, subnets, routing) WAF configuration More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Opus Recruitment Solutions Ltd
efficacy testing, rule creation, and tuning. Key Responsibilities: Design and implement custom WAF rules to address security gaps Conduct detailed log analysis to identify and mitigate false positives Support DevSecOps pipeline integration and automation of efficacy testing Advise on web/API attack vectors and mitigation strategies Provide SME input on WAF PoCs, new features, and cost-effective solutions Maintain More ❯
strat hedge fund based in London, is looking for an AWS Cloud Security Engineer to join a growing cloud securty team. Essential skills: demonstrable track record of working in DevSecOps; Deep expert AWS cloud security knowledge; strong awareness of core infrastructure services such as securuty engineering and networking; an understanding of cloud architectural concepts; python scripting; terraform; ansible. Desirable skills More ❯
in Python and/or C#. Familiarity with LangChain, AutoGen, or similar orchestration frameworks. Experience with Azure AI Search, Form Recognizer, and Language Services. Knowledge of CI/CD, DevSecOps practises, and responsible AI frameworks. We are searching for someone with a proven track record of delivering agent-based or GenAI solutions in enterprise or regulated environments. Your enthusiasm and More ❯
in Python and/or C#. Familiarity with LangChain, AutoGen, or similar orchestration frameworks. Experience with Azure AI Search, Form Recognizer, and Language Services. Knowledge of CI/CD, DevSecOps practises, and responsible AI frameworks. We are searching for someone with a proven track record of delivering agent-based or GenAI solutions in enterprise or regulated environments. Your enthusiasm and More ❯
of modern DevOps practices, cloud and container technologies, automation tooling, and software engineering principles. You will work closely with development, security, and operations teams to drive a culture of DevSecOps and continuous improvement. Key Responsibilities Design, build, and maintain scalable CI/CD pipelines using modern DevOps tooling. Implement Infrastructure-as-Code (IaC) to provision and manage cloud/on … infrastructure. Manage container orchestration platforms and develop containerized solutions. Monitor systems and applications for availability, performance, and security compliance. Automate operational tasks including testing, deployment, patching, and scaling. Apply DevSecOps principles to secure applications and infrastructure across SDLC. Collaborate with cross-functional teams (developers, testers, security analysts) to streamline software delivery. Participate in code reviews, architecture design, and incident resolution. More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Sanderson
scalable solutions across complex infrastructure. Key Skills: Deep understanding of Public Sector Security and Cabinet Office Secure by Design Enterprise Risk Infrastructure & Cloud Security Identity & Access Management Container Security & DevSecOps Data Security, PKI, Palo Alto technologies Strong communicator with the ability to present complex issues in plain English to senior stakeholders Collaborative team player with a proactive, hands-on approach More ❯
Newcastle Upon Tyne, Tyne and Wear, North East, United Kingdom
Brightbox GRP Ltd
DevSecOps Engineer Initially 3 Months Remote £450-£550pd (Outside IR35) Position Overview: We are seeking a knowledgeable and dedicated DevSecOps Engineer to join our team. In this role, you will be responsible for ensuring the proven identity of transactions and implementing traceability throughout the development journey. You will conduct regular audits to maintain compliance and security standards, ensuring that our … sovereignty. Identify and resolve any security vulnerabilities in the development process. Develop and maintain scripts to automate processes and improve operational efficiency. Qualifications: Strong understanding of end-to-end DevSecOps processes and best practises. Proven experience with CI/CD tools and practises. Proficiency in Azure cloud services, with a focus on maintaining data sovereignty. Experience in containerization technologies such More ❯
quickly and securely, improving response times and overall public safety. Required Skills Data Stage, RedShift, QuickSight, S3 data migration/ETL both batch and real time data warehouse development DevSecOps Java SQL relational databases GitHub/lab experience Nice to have: Data quality xml AWS Data Specialty certification All profiles will be reviewed against the required skills and experience. Due More ❯
Sheffield, South Yorkshire, Yorkshire, United Kingdom
Networking People (UK) Limited
/Threat/Forensics or CSIRT backgrounds - very experienced with analysing security logs to quickly ascertain TP/FP conviction and the techniques to except Ideally some AppSec/DevSecOps or Ethical Hacking experience - need a good understanding of Web Application attacks and security; they must have deep knowledge of the OWASP Top 10 If they have Hands-on tuning More ❯
Google Cloud Identity) Hands-on experience with IAM platforms such as Okta, ForgeRock, SailPoint, and CyberArk Strong understanding of Zero Trust principles and identity-centric security models Familiarity with DevSecOps practises and CI/CD integration for IAM Excellent stakeholder management skills, with the ability to collaborate with diverse teams across regions Certifications: Certified Identity and Access Manager (CIAM) and More ❯
Google Cloud Identity) Hands-on experience with IAM platforms such as Okta, ForgeRock, SailPoint, and CyberArk Strong understanding of Zero Trust principles and identity-centric security models Familiarity with DevSecOps practises and CI/CD integration for IAM Excellent stakeholder management skills, with the ability to collaborate with diverse teams across regions Certifications: Certified Identity and Access Manager (CIAM) and More ❯
Our customer is looking for a remote contractor to take on this new role Essential experience includes:- Experience of Linux security lockdown in RHEL 9.x and Ubuntu Pro Experience of securing systems using DISA STIG process Configuration and Securing of More ❯
Southampton, Hampshire, United Kingdom Hybrid / WFH Options
Experis
Sector Security Understanding of Cabinet Office "Secure by Design" Strong understanding of: Enterprise risk Infrastructure Security Identity and Access Management Cloud Security Container Security Palo Alto offerings Data Security DevSecOps PKI Ability to communicate and work in a team Ability to present to Senior members of the team, Clients and Partners about complex issues in common English. A hands-on More ❯
and deployment of OS images using MS Autopilot Packaging, deployment, and configuration of approved software Software asset management: licence compliance and harvesting Support for Cyber Security colleagues, embracing the DevSecOps culture Providing technical expertise, guidance, and strategic recommendations to other IT groups Developing and promoting standard operating procedures and schedules Conducting hardware and software audits to ensure compliance General IT More ❯