About this role
Job title: DevSecOps Engineer
About the Role The DevSecOps Engineer will be a core member of the Brand Experience team, embedding security across the full software delivery lifecycle for our Next.js storefront and BFF on AWS. You’ll help ensure secure, compliant, and high-velocity delivery in a DTC digital commerce environment.
What You'll Do
- Design and operate secure-by-default AWS foundations for Next.js and BFF workloads, including VPC design, segmentation, edge/CDN protections, and resource-level controls aligned to least privilege.
- Own Infrastructure as Code (IaC) security standards using Terraform and/or CloudFormation, embedding policy-as-code and reusable hardened modules.
- Define and enforce baselines for IAM, KMS, networking, logging, and account/landing-zone guardrails.
- Build and harden CI/CD pipelines with integrated SAST, DAST, SCA, IaC scanning, container image scanning, and secrets detection.
- Implement software supply chain controls: signed commits, artifact signing, SBOM generation, dependency provenance, and protected release paths.
- Enable progressive delivery, zero/low-downtime deployments, and safe rollback patterns without compromising security gates.
- Operate continuous vulnerability discovery across cloud, container, application and dependency layers; drive risk-based prioritisation and remediation SLAs.
- Lead threat modelling and secure design reviews for new features, partnering with engineering and architecture to identify and mitigate risks early.
- Define and operate web application protections for storefront and BFF endpoints.
- Own secrets management and rotation, eliminating hard-coded credentials across services and pipelines.
- Implement encryption in transit and at rest, certificate lifecycle management, and key governance using KMS.
- Govern human and workload identity: federation, OIDC for pipelines, role-assumption patterns, and just-in-time access.
- Operationalise compliance for digital commerce: GDPR-aligned data handling, PCI-DSS scope reduction, and customer data protection through automation and guardrails.
- Automate evidence capture, control validation, and audit-ready reporting; partner with InfoSec, Legal and Privacy stakeholders.
- Maintain security policies, exception management, and risk registers relevant to the DTC platform.
- Build security observability: centralised logging, security telemetry, anomaly detection, and alerting using CloudWatch/Datadog/SIEM or equivalent.
- Participate in on-call rotation; lead security incident triage, coordinate response, and deliver high-quality RCAs with prevention actions.
- Define SLIs/SLOs for security-relevant signals.
- Provide self-service security tooling, golden paths, and pre-approved patterns so engineers can move fast safely.
- Produce clear runbooks, playbooks, secure coding guidance and threat-modelling templates to reduce operational and cognitive load on engineers.
- Champion a security-first culture through coaching, lightweight reviews, and visible metrics.
What We're Looking For
- Must-have hands-on experience securing and operating production workloads on AWS, and embedding security into IaC with policy-as-code and modular hardened patterns.
- Strong background designing and maintaining secure CI/CD pipelines with integrated SAST, DAST, SCA, IaC and container scanning.
- Experience with vulnerability management, threat modelling, and risk-based remediation across cloud, application and dependency layers.
- Working knowledge of web application security.
- Strong operational discipline: incident response, RCA, change management, and runbook-driven operations.
- Ability to collaborate effectively with cross-functional product teams and communicate security risk in clear, actionable terms.
- Technical skills: AWS security fundamentals; containers/serverless security; secrets management; security tooling across the SDLC; observability and SIEM concepts; scripting; familiarity with Next.js build/deploy patterns and security implications.
Compensation & Benefits
- Not disclosed