Methods Business and Digital Technology is hiring a

DevSecOps (contract) - Cyber

Great Malvern, United Kingdom
Contractor

 

Methods Business and Digital Technology Limited

Methods is a £100M+ IT Services Consultancy who has partnered with a range of central government departments and agencies to transform the way the public sector operates in the UK. Established over 30 years ago and UK-based, we apply our skills in transformation, delivery, and collaboration from across the Methods Group, to create end-to-end business and technical solutions that are people-centred, safe, and designed for the future.

Our human touch sets us apart from other consultancies, system integrators and software houses - with people, technology, and data at the heart of who we are, we believe in creating value and sustainability through everything we do for our clients, staff, communities, and the planet.

We support our clients in the success of their projects while working collaboratively to share skill sets and solve problems. At Methods we have fun while working hard; we are not afraid of making mistakes and learning from them.

Predominantly focused on the public-sector, Methods is now building a significant private sector client portfolio.

Methods was acquired by the Alten Group in early 2022.

Requirements

Requirements

  • The development, management and supporting of the infrastructure that underpins the platforms, applications, anddata which support the business..
  • Automating where possible to facilitate the rapid delivery of approved capabilities to their respective environments in a secure manner..
  • Must have good experience in developing Infrastructure as Code to automate the creation of infrastructure from development all the way to production.
  • Should be passionate about improving ways of working and best practices by understanding the customer and the market trends.
  • Understanding the needs of stakeholders and conveying this to the target audience.  
  • Testing and examining code written by others and providing an approval as part of the governance and review process.
  • Ensuring that systems are safe and secure against cybersecurity threats when developing by keeping in mind that the systems must be secure by design.
  • Familiar with the NCSC secure design principles.
  • Familiar with managing the security of platforms whether they’re on cloud or on-premises, including administration of secrets, tokens, and certificates.
  • Working with the team (business, architecture, engineers, security, data) to ensure that development and delivery follows established processes and works as intended.
  • Planning out projects and being involved in project management decisions.
  • Responsible for the design, security, and maintenance of on-prem/cloud infrastructure.
  • Making and guiding effective decisions, explaining clearly how the decision has been reached with the ability to understand and resolve technical disputes across varying levels of complexity and risk.
  • Communicating effectively across organisational, technical, and political boundaries to understand the context and how to make complex and technical information and language simple and accessible for non-technical audiences.
  • Understanding of how to expose data from systems (for example through APIs), link data from multiple systems, and deliver streaming services.
  • Ensuring that risks associated with deployment are adequately understood and documented.
  • Integrating security features in the software development life cycle.
  • Identification and probable security risks, with their mitigating strategies.
  • Implementation of security controls.
  • Monitoring the infrastructure and the threat to security.
  • Ensuring regulatory compliances for standards of security.
  • Early detection of security vulnerabilities
  • Faster deployment of secure software
  • By following better compliance with security standards and regulations
  • Greater visibility into security risks and threats
  • Have experience or familiarity with working in an agile delivery methodology 

Ideal Candidates will demonstrate:

  • Experience working  with many teams especially security would be beneficial.
  • Solid infrastructure design experience for on-prem environments to implement or migrate applications and databases.
  • Have experience with hybrid designs between on-premise and cloud
  • Solid experience in a range of technologies and be able to make assessments as to what is best to be used for the projects and the organisation. As well as suggest and develop innovative approaches within constrained projects and environments.
  • Strong experience in software development change/release management processes and technical governance to fully understand the typical lifecycle and maintenance of live systems.
  • Ability to work with containerization platforms such as Kubernetes, PKS, Docker; provisioning software including Ansible, Terraform, YAML; and application/infrastructure/data performance analysis and monitoring.
  • Experience of functional and non-functional testing.
  • Experience with automated deployment of applications, databases and infrastructure.
  • Understanding of the government digital service (GDS) manual and standards across Discovery/Alpha/Beta/Live phases.
  • Understanding of SaaS, PaaS, IaaS technologies, and the implications of their use compared with bespoke development.
  • Being able to provide training, support, and mentoring to the wider business.
  • Knowledge of how to ensure that risks associated with deployment are adequately understood and documented.

Desirable Skills & Experience:

  • Worked as part of a system support team managing live systems and triaging & resolving incidents to resolution, including management of known defects and issues.
  • Worked as part of a multi-disciplinary project team.
  • Experience with Terraform and YAML to deploy on-prem/cloud infrastructure.
  • Experience with automation tools to build and deploy containerized applications.
  • Experience implementing effective instrumentation to monitor applications.
  • Experience implementing SAST and DAST tooling in deployment pipelines like Trivvy and SonarQube.
  • Experience with on-prem DevOps tooling.

This role will require you to have or be willing to go through Security Clearance. As part of the onboarding process candidates will be asked to complete a Baseline Personnel Security Standard; details of the evidence required to apply may be found on the government website Gov.UK. If you are unable to meet this and any associated criteria, then your employment may be delayed, or rejected . Details of this will be discussed with you at interview. 

Benefits


Apply for this job

Please mention you found this job on AI Jobs. It helps us get more startups to hire on our site. Thanks and good luck!

Get hired quicker

Be the first to apply. Receive an email whenever similar jobs are posted.

Report this job
Apply for this job