DevSecOps Engineer
Job Description
DevSecOps Engineer
\nLocation: London (Hybrid 2-3 Days Per Week)
\nSalary: £65,000 - £90,000 + Benefits
\nType: Permanent
\n\nAbout the Company
\n167 Solutions is partnering with an innovative technology organisation that is scaling its cloud engineering and platform capabilities. We are seeking a hands-on DevSecOps Engineer who can embed security directly into the software development life cycle while remaining actively involved in engineering, automation, cloud infrastructure, and platform delivery.
\nThis is not a traditional security administration or governance role. We are looking for an engineer who writes code, builds automation, develops cloud-native solutions, and integrates security into modern software delivery practices.
\n\nThe Opportunity
\nAs a DevSecOps Engineer, you will work closely with Software Engineers, Platform Engineers, Cloud Architects, and Security teams to build secure-by-design solutions across AWS environments.
\nYou will be responsible for automating security controls, improving cloud security posture, developing CI/CD pipelines, and implementing security tooling within a fast-paced engineering environment.
\nThe successful candidate will have strong software engineering capabilities alongside cloud and security expertise.
\n\nKey Responsibilities
\n- \n
- Design, build and maintain secure AWS cloud infrastructure. \n
- Develop and maintain Infrastructure as Code using Terraform and AWS-native tooling. \n
- Build security controls directly into CI/CD pipelines. \n
- Develop automation scripts and tooling using Python, Go, TypeScript, or similar languages. \n
- Implement container security across Kubernetes and Docker environments. \n
- Integrate security scanning, vulnerability management, and compliance controls into engineering workflows. \n
- Collaborate with software development teams to improve secure coding practices. \n
- Develop and maintain monitoring, logging, and incident response automation. \n
- Support threat modelling and secure architecture reviews. \n
- Drive DevSecOps best practices across engineering teams. \n
- Contribute to platform engineering and cloud-native application delivery. \n
Required Experience
\n- \n
- Proven experience in a DevSecOps, Platform Engineering, Site Reliability Engineering, or Software Engineering role. \n
- Strong AWS experience including services such as: \n
- IAM \n
- ECS/EKS \n
- Lambda \n
- CloudWatch \n
- VPC \n
- Secrets Manager \n
- Security Hub \n
- GuardDuty \n
- Hands-on software development experience using: \n
- Python \n
- Go \n
- TypeScript \n
- Java (desirable) \n
- Strong Terraform and Infrastructure as Code experience. \n
- Experience building and maintaining CI/CD pipelines. \n
- Experience with Docker and Kubernetes. \n
- Strong understanding of secure software development practices. \n
- Experience integrating security tooling into development workflows. \n
- Familiarity with modern observability and monitoring platforms. \n
Desirable Experience
\n- \n
- AWS Security Speciality certification. \n
- Experience with Open Policy Agent (OPA). \n
- Experience with GitHub Actions, GitLab CI or Jenkins. \n
- Knowledge of container runtime security. \n
- Experience within highly regulated or enterprise-scale environments. \n
- Exposure to cloud-native security platforms and zero-trust architectures. \n
- Understanding of SOC2, ISO27001, NIST or Cyber Essentials frameworks. \n
What Success Looks Like
\n- \n
- Security becomes embedded within the engineering life cycle rather than acting as a gatekeeper. \n
- Automated controls reduce risk without slowing delivery. \n
- Development teams can deploy securely and confidently. \n
- Cloud environments remain scalable, resilient, and secure by design. \n
- Engineering and security teams operate as a single delivery function. \n
Why Apply?
\n- \n
- Work on modern AWS cloud platforms. \n
- Engineering-first culture. \n
- Opportunity to shape DevSecOps practices across the organisation. \n
- Significant investment in cloud, platform, and security capabilities. \n
- Exposure to cutting-edge automation and cloud-native technologies. \n
- Genuine influence on technical direction and security strategy. \n
