Senior DevSecOps Engineer - Outside

New Yesterday

Outside IR35, Dev/Sec Ops Engineer, Azure, AWS, Technical Blueprint, Best practice, Regulatory Environment background. West Midlands, LondonWe are seeking a Senior DevSecOps Engineer to lead governance, architecture guidance, and assurance for cloud and infrastructure security across Microsoft Azure, AWS, and key SaaS platforms. This role is pivotal in defining technical blueprints, setting security standards, and ensuring regulatory compliance with Cyber Essentials Plus, ISO 27001, and Zero Trust principles.You will work closely with IT and platform teams to embed best practices, validate implementations, and support audit readiness across IaaS, PaaS, and SaaS environments.Key ResponsibilitiesDefine and maintain multi-cloud security standards and reference blueprints (e.g. Azure Policy/Initiatives, AWS Control Tower/SCPs)Own security architecture patterns and contribute to HLD/LLD, threat models, and risk assessmentsSet assurance criteria and control evidence requirements for internal teams and third-party vendorsEstablish policy-as-code requirements and maintain an exceptions register with expiry and risk ownershipDefine identity and access control standards (Entra ID Conditional Access, MFA, PIM; AWS IAM federation)Govern SaaS security onboarding (SSO, OAuth governance, DLP controls, vendor assessments)Specify telemetry and logging requirements for Microsoft Sentinel/SOC and review analytics/reportingLead compliance mapping for ISO 27001 and curate audit-ready evidence packsChair Cloud & Platform Security design reviews and participate in CAB for risk appraisalStrong regulatory sector experienceEducate and influence teams through guidance, clinics, and coaching sessionsFamiliarity with IaaS, PaaS, SaaS risk models and audit frameworksExcellent written communication and facilitation skills to drive adoption and influence stakeholdersAdditional SkillsCertifications: AZ‑500, SC‑100, SC‑200, AZ‑700, AWS Security Specialty, CISSP (or equivalents)Experience with blueprint catalogues and architecture governance processesWorking knowledge of containers/Kubernetes (AKS/EKS) policy modelsWhile this role focuses on governance and assurance, hands-on use may be required for validation:Azure: Policy/Initiatives, Defender for Cloud, Entra ID, PIMAWS: Control Tower, SCPs, Security Hub, GuardDuty, IAMSecurity & Monitoring: Microsoft Sentinel (KQL), Defender XDR, audit dashboardsDocumentation & Governance: Blueprint repositories, risk registers, ITSM/CAB recordsIf this role is of interest please send your cv to review ASAP #J-18808-Ljbffr
Location:
West Midlands, England, United Kingdom
Job Type:
FullTime

We found some similar jobs based on your search