DevSecOps Engineer

Graphnet Health

Milton Keynes

Hybrid

GBP 70,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Graphnet Health is seeking a hands-on Azure DevSecOps Engineer to balance DevOps and security engineering. The role focuses on strengthening secure software delivery, cloud security posture and operational resilience within a UK-based environment.

The ideal candidate will switch between CI/CD, IaC automation and vulnerability management, with experience across AKS, App Services, API Management, Azure SQL and Key Vault. Hybrid working with monthly office attendance is expected.

Qualifications

  • Hands-on Azure experience with secure design, deployment and operations of Azure PaaS.
  • Proven DevOps experience building and maintaining CI/CD pipelines.
  • Experience with IaC and automation using Terraform and PowerShell.

Responsibilities

  • Build and improve secure CI/CD pipelines using Azure DevOps and/or GitHub Actions.
  • Embed DevSecOps practices including code scanning and secret scanning.
  • Identify, prioritise and remediate vulnerabilities with security teams.
  • Deploy and harden Azure infrastructure using IaC and least-privilege principles.
  • Support secure Azure platform design across AKS, App Services, API Management, Azure SQL and Key Vault.
  • Improve security visibility with automation, dashboards and alerts.
  • Contribute to threat modelling, policy-as-code and secure engineering guidance.
  • Support DR/BCP testing to ensure services remain recoverable.

Skills

Azure DevSecOps
CI/CD pipelines
Infrastructure as Code
Azure DevOps
GitHub Actions
Terraform
PowerShell
AKS
Container security
Threat modelling

Education

AZ-400 / AZ-500 or equivalent
SC-200 / CISSP / CCSP beneficial

Tools

Microsoft Sentinel
Defender for Cloud
Azure Monitor
Application Insights
Cloudflare / WAF

Job description

Reporting to: Technical Services Manager

Location: Milton Keynes/Homebased - with the expectation to attend Graphnet Group office sites at least once per month, or as and when required for team collaboration days.

Overview:

We are a British healthcare software company delivering market-leading integrated care record and population health solutions. Our Azure-hosted SaaS platform supports critical healthcare services, so security, reliability and resilience are central to everything we do.

We are looking for a hands-on Azure DevSecOps Engineer for a role that is balanced between DevOps engineering and Security engineering, helping us strengthen secure software delivery, cloud security posture and operational resilience.

The ideal candidate will be comfortable switching between DevOps activities such as CI/CD, automation and Infrastructure as Code, and security activities such as vulnerability management, monitoring, cloud hardening and incident response.

Key responsibilities include:
  • Build and improve secure CI/CD pipelines using Azure DevOps and/or GitHub Actions.
  • Embed DevSecOps practices such as code scanning, dependency checks, secret scanning, container scanning and IaC validation.
  • Work with Security, Engineering and Operations teams to identify, prioritise and remediate vulnerabilities and misconfigurations.
  • Deploy and harden Azure infrastructure using Infrastructure as Code, secure configuration and least-privilege principles.
  • Support secure Azure platform design across AKS, App Services, API Management, Azure SQL, networking, Key Vault, monitoring and logging.
  • Improve security visibility through automation, dashboards, alerts and operational tooling.
  • Contribute to threat modelling, security standards, policy-as-code and secure engineering guidance.
  • Support DR/BCP testing to ensure services remain secure, available and recoverable.
Personal Attributes:
  • Works well independently and as part of a collaborative engineering team.
  • Has a strong security mindset and a practical, risk-based approach.
  • Communicates clearly with technical and non-technical stakeholders.
  • Can prioritise work, manage competing demands and follow improvements through to completion.
  • Pays attention to detail and values consistent standards and repeatable processes.
  • Stays current with cloud, security and DevSecOps tools and practices.
Education & Skills Required:
  • Strong hands-on experience with Microsoft Azure, especially secure design, deployment and operation of Azure PaaS services.
  • Proven DevOps experience building and maintaining CI/CD pipelines using Azure DevOps and/or GitHub Actions.
  • Experience with Infrastructure as Code and automation, ideally using Terraform, Azure Verified Modules and PowerShell.
  • Experience with Azure security and operations tooling such as Microsoft Sentinel, Microsoft Defender for Cloud, Azure Monitor and Application Insights.
  • Practical experience with AKS, container security, App Services, API Management, Azure SQL, Key Vault, managed identities and Azure networking.
  • Knowledge of DevSecOps practices including SAST, dependency scanning, secret scanning, IaC scanning, container scanning and automated security gates.
  • Experience supporting vulnerability management, including triage, prioritisation, remediation tracking and collaboration with security teams.
  • Experience with Cloudflare or similar edge security, WAF, DNS and traffic protection technologies.
Advantageous:
  • Healthcare, NHS, Government or other regulated industry experience.
  • Experience with Jira and Confluence for workflow, documentation and audit trails.
  • Knowledge of TCAF, Azure Verified Modules, landing zones or enterprise-scale Azure governance.
  • Knowledge of secure development practices, threat modelling, OWASP or application security testing.
  • Experience supporting ISO 27001 controls, evidence gathering or audit readiness.
Qualifications:
  • Relevant Microsoft Azure certification such as AZ-400 or AZ-500, or equivalent practical experience.
  • Security, cloud or DevSecOps certifications such as SC-200, CISSP, CCSP or similar would be beneficial.

As an equal opportunities’ employer, we welcome applications from individuals of all backgrounds. However, for you to be eligible for this role, you must have a valid right to work in the UK for the entire duration of your employment, as we are unable to provide routes to sponsorship currently.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Azure DevOps Engineer
Senior Azure DevOps Engineer

Graphnet Health • Milton Keynes

Hybrid
GBP 70,000 - 90,000
DevOps Engineer
DevOps Engineer

Adria Solutions Ltd • Manchester

Hybrid
GBP 60,000 - 85,000
Private medical and dental insurance
Life assurance and enhanced parental >
Birthday off
+1
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources • City Of London

Hybrid
GBP 72,000 - 88,000
Azure DevOps Engineer
Azure DevOps Engineer

GCS Recruitment • Deepcar

On-site
GBP 70,000 - 95,000
DevOps Engineer
DevOps Engineer

MBR Partners • United Kingdom

Remote
GBP 70,000 - 110,000
Great benefits package
Azure DevSecOps Engineer – Secure CI/CD & Cloud
Azure DevSecOps Engineer – Secure CI/CD & Cloud

Graphnet Health • Milton Keynes

Hybrid
GBP 70,000 - 110,000
Senior Cloud Engineer - Azure DevOps
Senior Cloud Engineer - Azure DevOps

UBDS Digital • Greater London

On-site
GBP 85,000 - 120,000
Senior Azure Cloud Engineer (SC Cleared)
Senior Azure Cloud Engineer (SC Cleared)

Lorien • Greater London

Hybrid
GBP 90,000 - 130,000
DevOps Infrastructure Engineer
DevOps Infrastructure Engineer

donorflex CRM • Cardiff

Hybrid
GBP 55,000 - 75,000
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources Ltd. • Greater London

Hybrid
GBP 80,000 - 90,000
London office
Remote/hybrid work
Excellent benefits package