DevSecOps Engineer (Pipeline)- 12 Month Contract - Hybrid in Sheffield - Inside IR35
Role Overview
We are looking for a DevSecOps Engineer (Pipeline Security) to join on a 12-month hybrid contract based in Sheffield. The role focuses on embedding security controls into developer workflows that use AI-generated code, including SAST integration, secrets scanning, and secure CI/CD pipeline design - driving software supply chain security across an agentic software development life cycle.
Key Responsibilities
- Embed security controls into CI/CD pipelines for AI-generated code including SAST, secrets scanning, dependency scanning, and container scanning
- Implement policy-as-code guardrails and secure pipeline patterns for agentic software development life cycle environments
- Drive software supply chain security initiatives including SBOM generation, signed artefacts, and provenance tracking
- Partner with engineering teams to remediate findings and reduce time-to-fix across pipeline security vulnerabilities
- Contribute to the wider engineering excellence programme, promoting secure-by-design principles across developer tooling and workflows
Top 5 Skills
- Hands-on DevSecOps experience with strong knowledge of CI/CD platforms including GitHub, GitLab, and Jenkins
- Proven experience integrating SAST, DAST, secrets scanning, and dependency and container scanning tools into CI/CD pipelines
- Experience implementing policy-as-code and infrastructure-as-code security controls within enterprise engineering environments
- Knowledge of software supply chain security practices including SBOM, signed artefacts, and provenance frameworks such as SLSA
- Confident, client-facing professional with strong communication and collaboration skills - comfortable working across engineering and security teams in fast-paced delivery environments
Contract Details:
- Rate: £550 per day Inside IR35
- Location: Hybrid (2x a week) in Sheffield
- Contract Length: 12 - Month Initial Contract