Principal DevSecOPS Engineer

Posted 20 November 2024
Salary 100000-110000
LocationLondon
Job type Permanent
Discipline Cyber Security
Reference71460
Contact NameDean Charlton
Remote working Remote

Job description

Principal Consultant: Elevate Your Career in Cloud Security

**Location**: Based in or within easy commuting distance of London.

Are you passionate about cloud security and eager to make a significant impact in the industry? This role offers an exceptional platform to showcase your expertise, engage with the community, and drive innovation in cloud-native security

Why This Role Stands Out:

- Professional Growth: Engage with Special Interest Groups and Technical Advisory Groups, enhancing your knowledge and influence within the industry.
- Community Engagement: Represent company at user groups and conferences, both in the UK and internationally, positioning yourself as a thought leader.
- Skill Development: Deliver Kubernetes Security and Threat Modelling training, refining your skills and sharing your knowledge with peers.
- Diverse Experiences: Participate in a variety of activities, from pre-sales engagements to consulting, ensuring no two days are the same.

Key Responsibilities:

- Lead Threat Modelling engagements or design Cloud Native security architectures (AWS, GCP, Azure).
- Conduct Security Operations and Incident Response within cloud environments, including defining events and running table-top exercises.
- Manage commercial penetration testing engagements, with a focus on cloud-native environments.
- Oversee consulting engagements, run workshops, and present findings to project security authorities.
- Apply Kubernetes and container experience across platforms such as EKS, GKE, AKS, and OpenShift.
- Implement DevSecOps principles and engineering practices.
- Automate security tests and harden CI/CD pipelines.
- Utilise security tooling, ranging from enterprise solutions like Aqua and Prisma Cloud to open-source tools like falco and kube-hunter.
- Adhere to hardening guides, compliance standards, and MITRE ATT&CK frameworks.

Desired Skills and Experience:

- Active participation in the open source, security, or DevOps community.
- Comfortable presenting at user groups and conferences.
- Pre-sales or sales experience.
- Security-related qualifications (OSCP, Cloud Provider Security certifications, CISSP) are advantageous.
- Proficiency with CLI tooling, Golang or Python, Vault, service mesh, in-toto, Tekton Chains, SPIFFE, and/or Sigstore.
- Knowledge of Terraform and cloud infrastructure best practices (IaC, regulated systems).

This role is perfect for a seasoned professional ready to take their career to the next level. If you have a passion for cloud security and a desire to lead and innovate, this is the ideal position for you.

Apply below!