Talent.com
This job offer is not available in your country.
Senior DevSecOps Engineer - Outside

Senior DevSecOps Engineer - Outside

ExperisBirmingham, England, United Kingdom
14 hours ago
Job type
  • Full-time
Job description

Outside IR35, Dev / Sec Ops Engineer, Azure, AWS, Technical Blueprint, Best practice, Regulatory Environment background. West Midlands, London

We are seeking a Senior DevSecOps Engineer to lead governance, architecture guidance, and assurance for cloud and infrastructure security across Microsoft Azure, AWS, and key SaaS platforms. This role is pivotal in defining technical blueprints, setting security standards, and ensuring regulatory compliance with Cyber Essentials Plus, ISO 27001, and Zero Trust principles.

You will work closely with IT and platform teams to embed best practices, validate implementations, and support audit readiness across IaaS, PaaS, and SaaS environments.

Key Responsibilities

Define and maintain multi-cloud security standards and reference blueprints (e.g. Azure Policy / Initiatives, AWS Control Tower / SCPs)

Own security architecture patterns and contribute to HLD / LLD, threat models, and risk assessments

Set assurance criteria and control evidence requirements for internal teams and third-party vendors

Establish policy-as-code requirements and maintain an exceptions register with expiry and risk ownership

Define identity and access control standards (Entra ID Conditional Access, MFA, PIM; AWS IAM federation)

Govern SaaS security onboarding (SSO, OAuth governance, DLP controls, vendor assessments)

Specify telemetry and logging requirements for Microsoft Sentinel / SOC and review analytics / reporting

Lead compliance mapping for ISO 27001 and curate audit-ready evidence packs

Chair Cloud & Platform Security design reviews and participate in CAB for risk appraisal

Strong regulatory sector experience

Educate and influence teams through guidance, clinics, and coaching sessions

Familiarity with IaaS, PaaS, SaaS risk models and audit frameworks

Excellent written communication and facilitation skills to drive adoption and influence stakeholders

Additional Skills

Certifications : AZ-500, SC-100, SC-200, AZ-700, AWS Security Specialty, CISSP (or equivalents)

Experience with blueprint catalogues and architecture governance processes

Working knowledge of containers / Kubernetes (AKS / EKS) policy models

While this role focuses on governance and assurance, hands-on use may be required for validation :

Azure : Policy / Initiatives, Defender for Cloud, Entra ID, PIM

AWS : Control Tower, SCPs, Security Hub, GuardDuty, IAM

Security & Monitoring : Microsoft Sentinel (KQL), Defender XDR, audit dashboards

Documentation & Governance : Blueprint repositories, risk registers, ITSM / CAB records

If this role is of interest please send your cv to review ASAP

TPBN1_UKTJ

Create a job alert for this search

Senior Engineer • Birmingham, England, United Kingdom