img
Permanent

Senior DevOps Engineer (Security Compliance specialist) (Remote UK)

Cambridge
money-bag £80,000-95,000 per annum
Posted Today

Senior DevOps Engineer (Security Compliance specialist) (Remote UK)

Apolitical

Employment Type Full timeLocation Hybrid ·London, UK 3 days/week in our London officeSalary £80,000 - £95,000 (GBP) compensation benchmarking powered by RavioSeniority SeniorClosing: This role has no specific closing date.Perks and benefits

Work from home optionEmployee Assistance ProgrammeEnhanced maternity and paternity leavePaid emergency leaveMentoring/coachingSalary sacrificeTeam social eventsTeam lunchesCycle to work schemeFree fruitFree soft drinksCandidate happiness

8.24 (1268)Job Description

OverviewLocation:

Remote UKVisa sponsorship:

UK national or visa holder preferred, but not a dealbreaker.Background checks:

Due to the nature of the work we do with global governments and partners, all employees need to pass background checks, verifying your identity, education (if relevant), work history, sanctions, criminal record, adverse financial history and right to work.Salary expectations:

We aim for transparency on salary bands. If our range is misaligned with your expectations, we’d welcome an open conversation as early as possible.Recruiters:

We don''t need any agency support. Please do not get in contact.RoleApolitical is the global peer-to-peer platform for people transforming government. Our engineering team ships a modern, TypeScript-first stack—Kubernetes on GKE, Helmfile-driven releases, and GitHub Actions pipelines—serving public-sector professionals in 170+ countries. We’re looking for a Senior DevOps Engineer who pairs operational excellence with a passion for security and data compliance. You’ll harden our infrastructure, steer us through ISO27001 and GDPR audits, and make it effortless for product squads to ship secure code at speed.You’ll be our internal security-minded DevOps authority—sharing ownership of the CI/CD tool-chain, cloud infrastructure and compliance controls that keep our platform safe, fast and auditable.Tasks and remitPlatform hardening

– Maintain and evolve GKE + Helmfile deployments, Terraform modules and GitHub Actions workflows with security best practices baked-in.Compliance liaison

– Partner with our Data Protection Officer to interpret regulatory requirements (ISO27001, GDPR, DPAs) and translate them into technical controls, policies and run-books.Audit and pen-test lead

– Coordinate external auditors, manage evidence collection, track remediation tickets and present technical posture to stakeholders.Threat and vulnerability management

– Run container-image scanning (Snyk), dependency SBOM generation and orchestrate patch cycles across clusters.Incident readiness

– Own on-call playbooks, drill tabletop exercises, ensure logs/metrics/traces meet forensic standards.Security advocacy

– Mentor engineers on secure-by-default patterns; propose and deliver projects (e.g. cluster network policies, secrets rotation, OIDC federation) that raise our security bar.This role is exciting if you’re eager to grow technically and professionally in a supportive, pragmatic team. You’ll be empowered to own code, propose improvements and understand how your work impacts our users.You will be:An experienced DevOps/SRE with deep knowledge of container orchestration (Kubernetes) and infrastructure-as-code.Fluent in CI/CD (GitHub Actions, Argo/CD or similar) and observability tooling.Comfortable mapping ISO27001 controls to real-world pipelines and cloud resources.A clear communicator who can bridge product squads, external auditors and non-technical stakeholders.Managing people—this is an individual-contributor role with broad cross-team influence.Timelines may vary depending on individual onboarding and support needs, but we expect most team members to achieve the following milestones:Within one month, you will…Ship your first secure Helmfile release to QA.Complete onboarding deep-dive of existing CI/CD, Terraform and security policies.Shadow DPO on open compliance items to build context.Within three months, you will…Lead the next quarterly vulnerability scan and deliver remediation plan.Introduce SBOM + container image scanning gates to GitHub Actions.Publish updated incident-response runbook and run a tabletop drill.Within six months, you will…Own technical track for ISO27001 surveillance audit—zero major non-conformities.Deliver at least two security posture projects (e.g. cluster network policies, secret rotation automation).Define long-term security roadmap and metrics dashboard consumed by leadership.About youThis is a great fit if you…Thrive at the intersection of DevOps and security, turning controls into code.Have led (or heavily contributed to) at least one successful external compliance audit.Enjoy mentoring engineers and championing a culture of "secure by default".Are pragmatic—optimising for measurable risk reduction and developer velocity.Let us know if you have…Hands-on GCP experience (GKE, Cloud SQL, IAM, Secret Manager).Contributed to SRE practices (SLIs, SLOs, error budgets) or chaos engineering.This likely won’t be the right role if you…Prefer narrowly scoped, siloed security roles.Are uncomfortable owning end-to-end delivery—from Terraform plan to audit evidence pack.Don’t meet every single expectation? Studies have shown that women and people of colour are less likely to apply to jobs unless they meet every single qualification. Apolitical is dedicated to building a diverse and inclusive workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.ApplicationThe Applied platform asks some demographic questions before you start your application. No one at Apolitical sees the answers to these demographic questions with your application. We only see summary statistics to help us check if our candidate pool is balanced and if everyone has an equal chance to get hired irrespective of their background. If you prefer, you can easily opt out of answering these ..... full job details .....

Other jobs of interest...

Be Applied Ltd
CambridgeToday
money-bag£150,000-200,000 per annum
Harrington Starr
Cambridge
money-bag£200,000 per annum (£200.00 per month)
Experis UK
Cambridge
money-bag£150,000-200,000 per annum
Gearset Limited
Cambridge
money-bag£150,000-200,000 per annum

Perform a fresh search...

  • Create your ideal job search criteria by
    completing our quick and simple form and
    receive daily job alerts tailored to you!

Jobs. Straight to your inbox!