Requirements
- Experience working in MOD or Home Office project environments
- Strong knowledge of network and system security, including firewalls, IDS/IPS, micro-segmentation, and host security.
- Understanding of secure coding practices and common vulnerabilities (OWASP Top 10, SANS Top 25).
- Expertise in identity and access management (IAM), including RBAC, ABAC, JWT and Cookie based authentication.
- Incident detection and response in MOD environments.
- Security compliance and regulatory frameworks (e.g., NIST, CIS Benchmarks).
- Experience working with Kubernetes at an administrative level
- Strong leadership and mentoring abilities.
- Effective communication with development, operations, and security teams.
- Ability to advocate for security best practices in a DevOps culture.
Nice to Have
- Expertise in Kubernetes security (e.g., RBAC, network policies, pod security standards, secrets management).
- Knowledge of container runtime security (e.g., container escapes, rootless containers, sandboxing).
- Image security best practices, including scanning, signing, and provenance verification.
- Secure deployment patterns using Tanzu & Kubernetes.
- Runtime security monitoring.
- Secure CI/CD pipeline design with security testing using like Git and SonarQube.
- Implementation of Infrastructure as Code (IaC) security (e.g., Terraform, Ansible).
- Secrets management in CI/CD pipelines using Vault or Kubernetes Secrets.
- Security automation and policy enforcement using tools like GitHub Actions, GitLab CI and Jenkins.
- Strong knowledge of cloud security principles in a containerised environment.
- Kubernetes security posture management (KSPM) using tools like Trivy.
- Secure ingress/egress controls, service mesh security (e.g., Istio).
- Encryption strategies for data at rest, in transit, and in use.
- Network security best practices for Tanzu container networking (e.g., NSX, Rancher)
- Compliance monitoring and security auditing for cloud-native environments.
- Scripting skills in Python, PowerShell for security automation.
- API security knowledge (e.g., OAuth, JWT, API gateways, rate limiting).
- Experience with Security as Code for automated policy enforcement.
Benefits
- Contributory Pension Scheme
- Private Medical Insurance
- 33 days Annual Leave (including public and privilege holidays)
- Access to Flexible benefits (including life assurance, health schemes, gym memberships, annual buy and sell holidays and a cycle to work scheme)
- Flexi-Time
Work Arrangement
Hybrid
Additional Information
- Security Clearance Required - DV (Developed Vetting)
- Occasional travel to other UK sites
- On-site 4/5 days a week


