DevSecOps Engineer
Oscar Technology · Surrey · posted 24 days ago
Going rate £48,500UK median £54,647
Home Office going rates from
Occupation
2135Cyber security professionals
Going rate for this occupation: £48,500 · UK median pay £54,647
Home Office going rates from
Where this salary sits
- UK pay for this occupation
- This role£60,000 to £80,000stated
- Going rate£48,500
- UK median£54,647
View these figures as a table
| Percentile | Pay |
|---|---|
| 10th | £32,471 |
| 25th | £42,761 |
| 50th | £54,647 |
| 75th | £71,808 |
| Going rate | £48,500 |
| UK median | £54,647 |
Sponsorship
Sponsorship chance
Low
- Not matched to a licence on the register
- Occupation is eligible for Skilled Worker
- Salary clears the going rate
On the public records we hold, sponsorship for this role looks unlikely: not matched to a licence on the register, and occupation is eligible for Skilled Worker.
We hold the employer, the occupation, a stated salary and the advert's own wording.
Why
Sign in to see how you fit and draft a cover letter
We read this advert for what it asks, check each line against your CV and show you the evidence for every judgement.
Sign inFull advert
DevSecOps Engineer - Azure / Application Security
We're working with an established organisation looking to appoint an experienced DevSecOps Engineer to strengthen its Azure deployment and application security capabilities.
This is a hands-on position combining Azure DevOps, cloud infrastructure and application security. You'll take ownership of CI/CD pipelines, Infrastructure-as-Code and security testing, while helping development teams embed secure practices throughout the software delivery lifecycle.
The Role
You'll be responsible for:
Designing and maintaining CI/CD pipelines within Azure DevOps
Deploying Azure applications and infrastructure using Terraform
Supporting Azure services including App Services, AKS, Azure SQL, Storage, Key Vault, VNets, Private Endpoints and Front Door/WAF
Introducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detection
Integrating SAST, DAST, dependency and container scanning into development pipelines
Conducting web application security testing using Burp Suite, OWASP ZAP or similar tools
Identifying and managing vulnerabilities against OWASP Top 10 and CVSS principles
Implementing secrets detection, credential rotation and secure Key Vault practices
Strengthening software supply-chain security through SBOM generation, dependency scanning and artefact signing
Supporting API security testing, threat modelling and third-party penetration tests
Configuring Azure-native security tooling, including Defender for Cloud, Azure Policy, Sentinel and Azure Monitor
Enforcing identity and access controls across Entra ID, RBAC, Conditional Access and PIM
Supporting compliance with frameworks such as Cyber Essentials Plus, ISO 27001 and GDPR
Mentoring junior engineers and helping developers adopt secure coding and deployment practices
What We're Looking For
You'll need:
Around three to five years' experience across DevOps, platform engineering or application security
Strong hands-on experience with Microsoft Azure and Azure DevOps
Proven experience securing web applications in a production environment
Practical experience using Burp Suite for application security testing
Experience with SonarQube or comparable SAST tooling
Strong knowledge of OWASP Top 10, vulnerability management and remediation
Information from public records, not immigration advice.