Provide specialist DevSecOps expertise to help design, establish and mature secure, reliable software delivery practices.
Develop clear, practical policies, processes and standard operating procedures.
Advise on and support the selection, deployment and ongoing configuration of DevSecOps toolchains and technology stacks.
Work collaboratively with engineering, security and operational stakeholders to translate technical and assurance requirements into effective, workable solutions.
Design, build and maintain high-assurance CI/CD environments that support secure software development, testing and deployment.
Contribute hands-on capability to the setup and evolution of cloud and on-premises development and sandbox environments, supporting experimentation and use-case validation.
Establish and document processes to support the ongoing operation, maintenance and uplift of CI/CD environments throughout their lifecycle.
Support the delivery and operation of pre-release testing environments, including implementing automated regression testing wherever practical.
Assist with the assessment, testing and validation of vendor-supplied software updates as well as internally developed or enhanced capabilities.
Provide practical support to software procurement, development, configuration and integration activities
Implement secure development approaches using containerisation and orchestration technologies (such as Kubernetes).
Design solutions aligned to relevant security controls and accreditation requirements, supporting platforms through formal assurance processes.
Requirements
Tertiary qualification in Software Engineering, Computer Science, Information Technology, Systems Engineering, or a related discipline
Significant experience working as a Software Engineer, DevOps or DevSecOps specialist in complex technical environments
Proven capability developing and documenting DevSecOps frameworks, including policies, processes and standard operating procedures
Demonstrated experience operating development and testing environments aligned with DevSecOps and CI/CD principles
Strong working knowledge of cloud platforms and on-premises environments, and how to integrate them securely
Experience supporting or integrating vendor-supplied enterprise software (e.g. PLM, CAD or similar complex platforms)
Practical experience using containerisation and orchestration technologies (e.g. Docker, Kubernetes)
Ability to interpret and apply information security controls (including ISM-aligned requirements) and support systems through security accreditation processes.
Strong stakeholder engagement skills, with the ability to translate technical and assurance requirements between engineering, security and operational teams
Excellent written and verbal communication skills, particularly for producing clear technical documentation and guidance.
Proven ability to work independently as a senior specialist contractor, delivering outcomes with minimal supervision
Experience working in government, defence, critical infrastructure or other high-assurance environments
Tech Stack
Cloud
Docker
Kubernetes
Benefits
Competitive package to retain and attract the best talent