About this role
Role Overview
We are seeking a Lead Software Engineer (DevSecOps) to drive the hands-on delivery of automated, secure, and reliable software delivery capabilities across our product engineering organization. This role is responsible for building, operating, and continuously improving CI/CD pipelines, infrastructure automation, and embedded security controls that enable product teams to ship frequently, safely, and at scale.
You will operate as a senior, hands-on engineer and technical lead for a DevSecOps and platform automation team, turning DevSecOps strategy and reference architectures into working, production-grade solutions. You will guide and mentor engineers, own delivery of key platform capabilities, and partner closely with product teams, architects, and Security to embed best practices into day-to-day engineering.
Core Mission
Deliver the automation, pipelines, and platform capabilities that make secure, compliant, and reliable software delivery the default for every product team.
Key Responsibilities
CI/CD & Delivery Platform Engineering
- Build, maintain, and continuously improve automated CI/CD pipelines for: Microservices, APIs, and platform services
- Infrastructure-as-Code
- AI/ML and Agentic AI workloads
- Implement and evolve reusable pipeline templates and blueprints that are secure by default, self-service, and easy for product teams to adopt
- Implement progressive delivery capabilities, including blue-green and canary deployments, feature flags, and controlled rollouts
- Own the day-to-day health, performance, and reliability of delivery pipelines, reducing build times and pipeline failures
- Onboard product teams and new services onto standard pipelines and platform blueprints
DevSecOps & Supply Chain Security
- Implement and tune security controls embedded in pipelines, including: SAST, DAST, and SCA
- Container and image scanning
- IaC security and policy checks
- SBOM generation and verification
- Implement secure software supply chain practices, including provenance, artifact signing, dependency governance, and secrets management and rotation
- Work with Security teams to convert policies into automated, enforceable controls and quality gates
- Triage security findings with product teams, drive timely remediation, and reduce false positives and friction for developers
Cloud, Infrastructure & Automation
- Engineer and maintain platform automation using: Kubernetes and container platforms
- Infrastructure-as-Code (Terraform, CloudFormation, ARM/Bicep, etc.)
- GitOps patterns for infrastructure and application delivery
- Build and maintain reusable IaC modules and shared packages to reduce drift and standardise provisioning
- Automate secure, repeatable environment provisioning for dev, test, staging, and production, including multi-tenant and regulated workloads
- Automate repetitive operational tasks to reduce engineer cognitive load and manual tickets
- Optimise pipelines and infrastructure for cost, speed, and reliability
Observability, Reliability & Resilience
- Integrate observability into delivery pipelines and platforms, including metrics, logs, and traces (e.g., OpenTelemetry), deployment health checks, and automated rollback signals
- Implement and report on DORA and deployment reliability metrics (deployment frequency, lead time, change failure rate, MTTR)
- Support SRE-aligned practices such as error budgets, runbooks, and post-incident reviews
- Participate in incident response and on-call rotation for delivery and platform services, driving fast detection and recovery
- Contribute to disaster recovery automation and regular recovery testing
Technical Leadership & Team Enablement
- Act as technical lead for a DevSecOps and platform automation team, setting priorities, breaking down work, and owning delivery commitments
- Translate standards and reference architectures defined with Principal Engineers and Architects into practical, working implementations
- Conduct code and design reviews for pipelines, IaC, and automation, ensuring quality, security, and maintainability
- Coach and mentor engineers in DevSecOps, CI/CD, and platform engineering practices
- Create clear documentation, runbooks, and golden-path guidance that help product teams self-serve
- Champion best practices through enablement, collaboration, and continuous improvement
Required Experience & Skills
DevSecOps & Platform Engineering
- 8+ years of software engineering experience, including at least 4 years focused on DevSecOps, CI/CD, and platform automation
- Proven experience building and operating automated delivery pipelines and platform capabilities in production
- Experience leading or acting as technical lead for a small engineering team or workstream
- Solid understanding of software supply chain security principles
CI/CD Tooling & Automation
- Strong hands-on experience with CI/CD systems (e.g., GitHub Actions, GitLab CI, Azure DevOps, Jenkins)
- Experience with artifact repositories and container registries
- Proficiency with pipeline-as-code and building reusable templates
- Exposure to self-service developer platforms or internal developer portals
Cloud & Infrastructure
- Strong experience with at least one major cloud platform (Azure preferred; AWS or GCP also valued)
- Hands-on experience with Kubernetes and container orchestration
- Strong Infrastructure-as-Code skills, particularly Terraform
- Working knowledge of cloud networking, identity, and secrets management
Security & Compliance
- Hands-on experience integrating SAST, DAST, and SCA tools (e.g., SonarQube, Black Duck, or similar) into pipelines
- Experience with container, cloud, and IaC security scanning
- Familiarity with policy-as-code (e.g., OPA or similar)
- Awareness of compliance frameworks (SOC 2, ISO 27001, PCI, etc.) and how they translate into engineering controls
Engineering Mindset
- Strong coding and scripting skills in one or more languages (e.g., Python, Go, PowerShell, Bash)
- Strong troubleshooting skills across pipelines, containers, and cloud infrastructure
- Pragmatic, delivery-focused approach that balances security, speed, and developer experience
- Clear written and verbal communication skills, with the ability to explain technical topics to engineers and stakeholders
- Comfortable using AI-assisted development tools to accelerate engineering and automation work
Nice to Have
- Experience supporting AI/ML or Agentic AI pipelines
- Familiarity with GitOps tooling (Argo CD, Flux)
- Experience in regulated or highly audited environments
- Contributions to internal developer platforms or golden paths
- Relevant certifications (e.g., Azure DevOps Engineer Expert, Certified Kubernetes Administrator, HashiCorp Terraform Associate)
Our Interview Practices
To maintain a fair and genuine hiring process, we kindly ask that all candidates participate in interviews without the assistance of AI tools or external prompts. Our interview process is designed to assess your individual skills, experiences, and communication style. We value authenticity and want to ensure we’re getting to know you—not a digital assistant. To help maintain this integrity, we ask to remove virtual backgrounds and include in-person interviews in our hiring process. Please note that use of AI-generated responses or third-party support during interviews will be grounds for disqualification from the recruitment process.
Applicants may be required to appear onsite at a Wolters Kluwer office as part of the recruitment process.