Senior DevSecsOps Engineer

at  CFP Energy UK Ltd

Remote, Scotland, United Kingdom -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate09 Jul, 2024Not Specified10 Apr, 20241 year(s) or aboveAzure,Platforms,Aws,Security Operations,ArchitectureNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

Job Summary:
Our mission is to facilitate the transition to a low-carbon economy by providing innovative financial solutions to our clients.
We are not just any energy and sustainability group; we’re a dynamic, award-winning powerhouse! At the forefront of environmental innovation, we lead the charge in providing cutting-edge solutions for large-scale energy consumers. From guiding small business to corporate giants on their journey to achieve net zero emissions to expertly managing risks and supplying vital power and gas resources, we do it all. But wait, there’s more! We’re not content with just excelling in our current ventures - we thrive on pioneering new businesses and seizing energy investment opportunities.
Overview:
We are looking for a highly skilled, highly experienced Senior DevSecOps engineer to join a growing function within the business, focussing on infrastructure, automation, security practices and providing tooling solutions to streamline the path-to-live for development teams.
Our ideal candidate will be passionate about best practices within technology teams, fully supportive of what the group is doing and who wishes to make a difference.

EXPERIENCE REQUIRED:

  • 5+ years of experience managing infrastructure in Azure, AWS or GCP.
  • 3+ years of experience in DevSecOps role or security operations.
  • 1 + years of experience configuring and supporting production firewalls.
  • 1 + years of hands-on SIEM configuration and support.
  • Expertise with IaC tooling (Hashicorp Terraform).
  • Expertise with token / secret management tools (Hashicorp Vault).
  • Expertise with monitoring and alerting platforms, such as ELK, DataDog, Grafana, Loki, etc.
  • Expertise with Docker / Kubernetes and Helm design and implementation.
  • Fundamental understanding of networking, ingress, and DNS along with WAF.
  • Fundamental understanding of GIT/version control and SDLC build pipelines.
  • Experience with GitHub Actions.
  • Exposure to microservices architecture and experience with API Gateways.Object-orientated and non-object-orientated coding is highly advantageous.
-

Responsibilities:

  • Drive shift left security culture uptake by assisting with security training friendly phishing campaigns as well as conducting brown bag sessions with all staff.
  • Assist with the implementation of security gamification, chaos engineering practices, and SBOM implementation.
  • Support and secure our existing CI/CD pipelines and assist with migration from monoliths to microservices.
  • Experience with containerisation and maintaining, optimising, and securing Azure Kubernetes Clusters.
  • Drive alerting and monitoring solutions to provide teams with better optics of the live application ecosystem, using tools such as Grafana, Prometheus, Loki, or ELK.
  • Demonstrating a solid understanding of the SDLC and other continuous delivery frameworks and methodologies, such as SCRUM and Kanban.
  • Utilise configuration management tools and Infrastructure tools such as Terraform, Ansible, Chef or Pulumi.
  • Proven expertise in secrets management software and processes, using tools like Hashicorp Vault or Azure Key Vault.
  • Proven experience in obtaining and managing major industry compliance certifications and practices (ISO27k, SOC and GDPR).
  • Adhere to agile methodologies and Kanban processes and have a coaching mindset with the ability to understand and adapt to diverse cultures and hierarchies.
  • An ability to drive innovation by discovering new technologies, reviewing tooling, and making suggestions on improving our current stack and architecture.
  • Drive the change you seek and be an autonomous, proactive, confident, credible, and persuasive team player.
  • Collaborate and support developers, analysts, and data scientists to continually improve and innovate.
  • Conduct SAST and DAST testing as well as penetration testing and threat simulations to identify potential risks.
  • Have a practical understanding of firewall networking, ingress, VPNs, and DNS to ensure seamless integration and communication within the infrastructure estate.


REQUIREMENT SUMMARY

Min:1.0Max:5.0 year(s)

Information Technology/IT

IT Software - Other

Software Engineering

Graduate

Computer science or similar

Proficient

1

Remote, United Kingdom