DevSecOps Engineer

Methods

Worcester

On-site

GBP 70,000 - 90,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

LinkedIn Learning
Wellness programme
Office social events
25 days leave + 10 days
Paid volunteering days

Job summary

Methods is a UK-based IT services consultancy delivering secure, end-to-end digital transformation from government to private sector clients. This role focuses on building secure, automated infrastructure, embedding security across the SDLC and enabling repeatable, auditable releases.

You will work with cross-functional teams to implement IaC, secure pipelines, and cloud/on-premise hybrid environments, while ensuring compliance and rapid delivery of trusted software solutions.

Qualifications

  • Experience in DevSecOps and secure SDLC practices.
  • Proven ability to design and implement secure CI/CD pipelines.
  • Strong knowledge of cloud and on-premise hybrid environments.

Responsibilities

  • Develop and maintain IaC with Terraform or YAML equivalents.
  • Automate deployment, configuration and releases with security controls.
  • Embed security throughout the SDLC and pipeline tooling.
  • Manage CI/CD pipelines with security scanning and compliance checks.
  • Oversee platform security, including secrets and access controls.
  • Apply secure-by-design principles aligned to guidance.
  • Identify risks and implement mitigations.
  • Monitor infrastructure, apps and security tooling for threats.
  • Collaborate with engineering, security and business teams.
  • Conduct peer reviews of infrastructure and deployment code.
  • Document and manage deployment risks.

Skills

DevSecOps
Terraform
Kubernetes
Docker
CI/CD pipelines
Security by design
SDLC security
Agile delivery
Cross-functional collaboration
SAST/DAST tooling

Tools

Terraform
Ansible
SonarQube
Trivy
Kubernetes

Job description

  • Develop and maintain Infrastructure as Code (Terraform, YAML or equivalent).
  • Automate deployment, configuration and operational processes to enable secure and repeatable releases.
  • Embed security controls throughout the software development lifecycle (SDLC).
  • Implement and maintain CI/CD pipelines, including security scanning and compliance checks.
  • Manage platform security, including secrets, certificates, tokens and access controls.
  • Apply secure-by-design principles and align solutions with NCSC guidance.
  • Identify security risks and vulnerabilities and implement appropriate mitigations.
  • Monitor infrastructure, applications and security tooling to detect threats and issues.
  • Work with engineering, architecture, security and business teams to deliver secure solutions.
  • Conduct peer reviews of infrastructure and deployment code.
  • Ensure deployment risks are understood, documented and appropriately managed.
  • Support regulatory and security compliance requirements.
  • Experience working within Agile delivery environments.
  • Strong DevOps/DevSecOps experience supporting enterprise platforms.
  • Experience designing and implementing hybrid on-premise and cloud solutions.
  • Strong understanding of infrastructure, networking and platform security.
  • Experience with Kubernetes, Docker and container platforms.
  • Experience with Terraform, Ansible and infrastructure automation tooling.
  • Experience with CI/CD pipelines and release management processes.
  • Experience integrating security tooling into delivery pipelines.
  • Understanding of SaaS, PaaS and IaaS service models.
  • Ability to work effectively with cross-functional teams, particularly Security and Engineering.
  • Desirable Skills & Experience
  • Experience supporting and troubleshooting live production environments.
  • Experience working within multidisciplinary delivery teams.
  • Experience deploying and managing infrastructure using Terraform.
  • Experience building and deploying containerised applications.
  • Experience implementing application and infrastructure monitoring solutions.
  • Experience with SAST, DAST and software supply chain security tooling (e.g. SonarQube, Trivy).
  • Experience with on-premises DevOps toolchains and platforms.

This role will require you to have or be willing to go through Security Clearance. As part of the onboarding process candidates will be asked to complete a Baseline Personnel Security Standard; details of the evidence required to apply may be found on the government website Gov.UK. If you are unable to meet this and any associated criteria, then your employment may be delayed, or rejected . Details of this will be discussed with you at interview.

Methods is passionate about its people; we want our colleagues to develop the things they are good at and enjoy.

Methods is a £100M+ IT Services Consultancy who has partnered with a range of central government departments and agencies to transform the way the public sector operates in the UK. Established over 30 years ago and UK-based, we apply our skills in transformation, delivery, and collaboration from across the Methods Group, to create end-to-end business and technical solutions that are people-centred, safe, and designed for the future. Our human touch sets us apart from other consultancies, system integrators and software houses - with people, technology, and data at the heart of who we are, we believe in creating value and sustainability through everything we do for our clients, staff, communities, and the planet. We support our clients in the success of their projects while working collaboratively to share skill sets and solve problems. At Methods we have fun while working hard; we are not afraid of making mistakes and learning from them. Predominantly focused on the public-sector, Methods is now building a significant private sector client portfolio. Methods was acquired by the Alten Group in early 2022.

  • Development - access to LinkedIn Learning, a management development programme, and training
  • Wellness - 24/7 confidential employee assistance programme
  • Social - office parties, breakfast Tuesdays, monthly pizza Thursdays, Thirsty Thursdays, and commitment to charitable causes
  • Time Off - 25 days of annual leave a year, plus bank holidays, with the option to buy 10 extra days each year
  • Volunteering - 2 paid days per year to volunteer in our local communities or within a charity organisation
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

Methods Business and Digital Technology • Ross-on-Wye

On-site
GBP 90,000 - 120,000
LinkedIn Learning access
Management development program
Training
Cyber Security Architect
Cyber Security Architect

Methods Business and Digital Technology • Greater London

On-site
GBP 60,000 - 80,000
25 days annual leave plus bank holidays
Flexible working options
24/7 employee assistance programme
+5
Cyber Security Architect
Cyber Security Architect

Methods Business and Digital Technology Ltd • Greater London

Hybrid
GBP 55,000 - 75,000
24/7 confidential employee assistance programme
25 days annual leave plus bank holidays
Pension scheme with employer contribution
+3
Modern Workplace Engineer
Modern Workplace Engineer

Methods Business and Digital Technology • Greater London

On-site
GBP 70,000 - 100,000
Development opportunities
Wellness programmes
Pension scheme
+5
Modern Workplace Engineer
Modern Workplace Engineer

Methods • Greater London

On-site
GBP 65,000 - 100,000
LinkedIn Learning access
Wellness programme
Office parties & social events
+2
Competency Centre Manager
Competency Centre Manager

Methods • City of Westminster

Hybrid
GBP 70,000 - 110,000
Wellness 24/7 confidential employeeass
25 days annual leave
Pension Salary Exchange Scheme
+3
Senior Cyber Analyst
Senior Cyber Analyst

Methods Business and Digital Technology • Greater London

Hybrid
GBP 70,000 - 110,000
Flexible Working
Wellness Programme
Pension
+4
Senior Cyber Analyst
Senior Cyber Analyst

Methods • Greater London

On-site
GBP 90,000 - 130,000
Autonomy to develop
Flexible working
Private medical insurance
+1
Technical Architect - On site (SC Cleared)
Technical Architect - On site (SC Cleared)

Methods • Ledbury

Hybrid
GBP 55,000 - 75,000
24/7 confidential employee assistance programme
25 days of annual leave
Season ticket loan
Technical Architect - On site (SC Cleared)
Technical Architect - On site (SC Cleared)

Methods • Gloucester

On-site
GBP 60,000 - 80,000
24/7 employee assistance programme
25 days annual leave plus bank holidays
Private medical insurance
+2