Talent Apply
Log in
All jobs
DM

DevSecOps Engineer

dr martens

About this role

Job title: DevSecOps Engineer

About the Role The DevSecOps Engineer will be a core member of the Brand Experience team, embedding security across the full software delivery lifecycle for our Next.js storefront and BFF on AWS. You’ll help ensure secure, compliant, and high-velocity delivery in a DTC digital commerce environment.

What You'll Do

  • Design and operate secure-by-default AWS foundations for Next.js and BFF workloads, including VPC design, segmentation, edge/CDN protections, and resource-level controls aligned to least privilege.
  • Own Infrastructure as Code (IaC) security standards using Terraform and/or CloudFormation, embedding policy-as-code and reusable hardened modules.
  • Define and enforce baselines for IAM, KMS, networking, logging, and account/landing-zone guardrails.
  • Build and harden CI/CD pipelines with integrated SAST, DAST, SCA, IaC scanning, container image scanning, and secrets detection.
  • Implement software supply chain controls: signed commits, artifact signing, SBOM generation, dependency provenance, and protected release paths.
  • Enable progressive delivery, zero/low-downtime deployments, and safe rollback patterns without compromising security gates.
  • Operate continuous vulnerability discovery across cloud, container, application and dependency layers; drive risk-based prioritisation and remediation SLAs.
  • Lead threat modelling and secure design reviews for new features, partnering with engineering and architecture to identify and mitigate risks early.
  • Define and operate web application protections for storefront and BFF endpoints.
  • Own secrets management and rotation, eliminating hard-coded credentials across services and pipelines.
  • Implement encryption in transit and at rest, certificate lifecycle management, and key governance using KMS.
  • Govern human and workload identity: federation, OIDC for pipelines, role-assumption patterns, and just-in-time access.
  • Operationalise compliance for digital commerce: GDPR-aligned data handling, PCI-DSS scope reduction, and customer data protection through automation and guardrails.
  • Automate evidence capture, control validation, and audit-ready reporting; partner with InfoSec, Legal and Privacy stakeholders.
  • Maintain security policies, exception management, and risk registers relevant to the DTC platform.
  • Build security observability: centralised logging, security telemetry, anomaly detection, and alerting using CloudWatch/Datadog/SIEM or equivalent.
  • Participate in on-call rotation; lead security incident triage, coordinate response, and deliver high-quality RCAs with prevention actions.
  • Define SLIs/SLOs for security-relevant signals.
  • Provide self-service security tooling, golden paths, and pre-approved patterns so engineers can move fast safely.
  • Produce clear runbooks, playbooks, secure coding guidance and threat-modelling templates to reduce operational and cognitive load on engineers.
  • Champion a security-first culture through coaching, lightweight reviews, and visible metrics.

What We're Looking For

  • Must-have hands-on experience securing and operating production workloads on AWS, and embedding security into IaC with policy-as-code and modular hardened patterns.
  • Strong background designing and maintaining secure CI/CD pipelines with integrated SAST, DAST, SCA, IaC and container scanning.
  • Experience with vulnerability management, threat modelling, and risk-based remediation across cloud, application and dependency layers.
  • Working knowledge of web application security.
  • Strong operational discipline: incident response, RCA, change management, and runbook-driven operations.
  • Ability to collaborate effectively with cross-functional product teams and communicate security risk in clear, actionable terms.
  • Technical skills: AWS security fundamentals; containers/serverless security; secrets management; security tooling across the SDLC; observability and SIEM concepts; scripting; familiarity with Next.js build/deploy patterns and security implications.

Compensation & Benefits

  • Not disclosed

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →