Hands-on DevSecOps role bridging Security, Platform and CloudOps to implement deployable, repeatable AWS security controls. Responsibilities include automating vulnerability and patch management, deploying and maintaining security tooling (CrowdStrike, Tenable, ManageEngine, Fortinet, Cloudflare), securing Kubernetes/EKS and serverless, building IaC/GitOps automation (Terraform, CloudFormation, Crossplane, ArgoCD), and producing operational runbooks, SLAs and dashboards for sustained operational health across a multi-product SaaS AWS estate.
Forterro is seeking a Senior DevSecOps Engineer to close the operational gap between Security tooling requirements, Platform automation and CloudOps execution across a multi-product AWS SaaS estate. This is a hands-on engineering role responsible for making security controls deployable, repeatable, measurable and operationally reliable.
The role is a dedicated for Security function but embedded within the Cloud Platform / Platform Engineering team so that it has the practical authority to implement controls through infrastructure-as-code, GitOps workflows, CI/CD pipelines and operational runbooks. Security will define risk, policy and control intent; Platform will provide automation patterns; CloudOps will maintain and patch operational systems; this role owns the bridge between those teams and ensures security tooling and configuration are successfully implemented and handed over.
You will take hands-on ownership of cloud workload protection, vulnerability and patch management automation, network perimeter controls, container and serverless security, and deployment health for security tooling such as CrowdStrike, Tenable, ManageEngine, Fortinet, Cloudflare and AWS-native security services. The role must close the gap by turning security requirements into working automation, verified configuration and clear operational acceptance criteria.
The role is a dedicated for Security function but embedded within the Cloud Platform / Platform Engineering team so that it has the practical authority to implement controls through infrastructure-as-code, GitOps workflows, CI/CD pipelines and operational runbooks. Security will define risk, policy and control intent; Platform will provide automation patterns; CloudOps will maintain and patch operational systems; this role owns the bridge between those teams and ensures security tooling and configuration are successfully implemented and handed over.
You will take hands-on ownership of cloud workload protection, vulnerability and patch management automation, network perimeter controls, container and serverless security, and deployment health for security tooling such as CrowdStrike, Tenable, ManageEngine, Fortinet, Cloudflare and AWS-native security services. The role must close the gap by turning security requirements into working automation, verified configuration and clear operational acceptance criteria.
Responsibilities
Key ResponsibilitiesCloud Security Engineering - AWS
- Design, implement and maintain AWS security controls across IAM, networking, encryption, logging, account governance and guardrails.
- Implement and maintain AWS-native security services and governance patterns, including AWS Organizations, Control Tower, Service Control Policies, IAM Access Analyzer, Security Hub, GuardDuty, Inspector, Config, CloudTrail, KMS and centralised logging where applicable.
- Harden AWS accounts, services and workloads against CIS Benchmarks and Forterro security baselines, including documented exception and waiver processes for product-specific differences.
- Translate security requirements into infrastructure-as-code, policy-as-code and reusable automation modules that can be deployed consistently across multiple products and environments.
- Own the reliable deployment, configuration and operational health of security tooling across cloud and workload environments.
- Ensure CrowdStrike Falcon endpoint and cloud workload protection is deployed, healthy, version-compliant and reporting correctly, including failed agent deployment remediation and coverage reporting.
- Ensure Tenable scanning coverage is complete and reliable across cloud assets, with remediation workflows, exception handling and evidence reporting agreed with the Security team.
- Operate and improve ManageEngine-based patch tooling and workflows, ensuring patch automation, compliance reporting, failure handling and maintenance windows are clear and repeatable.
- Troubleshoot failed security-tool deployments and configuration drift across IAM, networking, Kubernetes, host agents, APIs, CI/CD and platform automation.
- Operationalise vulnerability and patch management processes across the AWS estate, ensuring scan coverage, triage, remediation ownership and closure tracking are measurable.
- Define, automate and report patch SLAs based on severity, asset criticality and business impact, including exception handling, rollback evidence and stakeholder communication.
- Work with Security to prioritise risk and with CloudOps/Product teams to execute remediation safely through approved change-control processes.
- Create dashboards and reports for patch compliance, vulnerability ageing, failed deployments, risk acceptance and remediation trends.
- Implement, maintain and audit Fortinet firewall controls, including rule sets, segmentation, VPNs, policy reviews and configuration validation under change control.
- Manage and validate Cloudflare services including WAF, DNS, CDN, DDoS protection and Zero Trust / access policies, using configuration-as-code where practical.
- Partner with Security on policy intent while ensuring configuration is implemented accurately, tested and operationally supportable.
- Secure and harden Kubernetes clusters, including Amazon EKS, RBAC, network policies, admission controls, secrets management, runtime controls and image provenance.
- Integrate container image scanning, registry scanning, software composition analysis, secrets scanning and SBOM generation into CI/CD and runtime processes.
- Establish and enforce baseline configurations and CIS Kubernetes Benchmark compliance using policy-as-code tooling such as OPA/Gatekeeper or Kyverno where appropriate.
- Secure AWS Lambda and event-driven serverless services through least-privilege execution roles, dependency and code scanning, runtime monitoring, event-source control and API Gateway/WAF guardrails.
- Implement and maintain infrastructure-as-code and automation using Terraform, Crossplane, CloudFormation where required, Ansible, Helm, Python, Bash/PowerShell and YAML.
- Integrate security controls into GitLab CI/CD and GitOps workflows such as ArgoCD, including SAST, SCA, secrets scanning, IaC scanning, container scanning, policy gates and exception workflows.
- Automate routine security operations including scanning, patch orchestration, configuration drift detection, evidence gathering and compliance reporting.
- Convert repeatable runbooks into idempotent automation and reusable deployment patterns that CloudOps and product teams can consume safely.
- Create clear runbooks, operational acceptance criteria, handover packs, service documentation, diagrams and support guidance for CloudOps and product teams.
- Define and maintain a practical RACI for security tooling deployment and operation, reducing ambiguity between Security, Platform, CloudOps and product teams.
- Participate in incident response and post-incident reviews where security tooling, control failures, vulnerability exposure or patch failures are involved.
- Mentor engineers on secure practices and support continuous improvement across Platform Engineering, CloudOps and product delivery teams.
- Evaluate new security technologies and products, produce evaluation reports, and recommend improvements aligned to business risk and SaaS platform strategy.
Skills, Knowledge & Expertise
Required Qualifications
- 5+ years of hands-on experience in DevSecOps, Cloud Security Engineering, Platform Engineering, SRE or senior cloud engineering roles.
- Strong working knowledge of AWS security architecture and services, including IAM, networking, encryption, logging, Organizations/SCPs, Security Hub, GuardDuty, Inspector, Config, CloudTrail and KMS.
- Practical experience deploying, configuring or operating security tools such as CrowdStrike, Tenable, ManageEngine, Fortinet firewalls and Cloudflare.
- Strong experience with infrastructure-as-code, GitOps and CI/CD tooling such as Terraform, CloudFormation, Ansible, Helm, ArgoCD, GitLab CI/CD and Git.
- Proficiency with scripting and automation using Python, Bash, PowerShell and YAML.
- Experience securing Kubernetes/EKS, container platforms and serverless workloads, including RBAC, network policies, admission controls, image scanning, secrets management and runtime monitoring.
- Solid grasp of vulnerability management, patch management, risk-based remediation, change control, SLAs and compliance evidence.
- Hands-on ability to troubleshoot failed automation, configuration drift and deployment failures across cloud, network, endpoint, Kubernetes and CI/CD layers.
- Experience operating in a multi-team, multi-product SaaS or enterprise cloud environment.
- Excellent communication, stakeholder management and ownership mindset, with the ability to reduce ambiguity between Security, Platform, CloudOps and product teams.
- Relevant certifications such as AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, GIAC, Terraform Associate or equivalent experience.
- Experience with SIEM/SOAR platforms, security incident response and threat-informed remediation.
- Familiarity with compliance frameworks such as ISO 27001, SOC 2, NIST and CIS.
- Experience implementing policy-as-code
- Experience in SaaS platform standardisation, shared services, mergers/acquisitions integration or multi-account AWS governance.
About
Forterro is a federation of ERP software and services companies serving small to mid market companies around the globe, with offices in UK, Germany, Sweden, Switzerland, France, Poland, Bulgaria, India, Morocco and USA. At Forterro, we invest in and help to fortify both local and niche ERP software businesses.Our product line businesses are local, not localized and vertical, not verticalized.
Similar Jobs
Cloud • Security • Software • Cybersecurity • Automation
Lead a team that integrates third-party and modular features into GitLab's Dedicated SaaS platform. Ensure high availability (99.99%+), drive operational excellence, automate toil, own incident management, prioritize via data, recruit and develop engineers, and use AI to boost productivity and guide technical strategy.
Top Skills:
Ai ToolingDevOpsDistributed SystemsIncident ManagementSaaSSre
Blockchain • Software • Cryptocurrency • Web3
Design, build, test, and deploy smart contracts and decentralized applications. Maintain blockchain integrations and backend services, optimize for security and gas efficiency, contribute to architecture and technical strategy, conduct code reviews, mentor junior engineers, and collaborate with product, frontend, and security teams.
Top Skills:
AnchorAvalancheBnb ChainCi/CdCloud InfrastructureDaosDatabasesDefiEthereumEthers.JsFoundryGitGoHardhatNftsNode.jsPolygonPythonRustSmart ContractsSolanaSolidityTruffleTypescriptWallet IntegrationsWeb3.Js
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The role involves developing and improving a Windows kernel mode sensor for cybersecurity, leading projects, and collaborating across platforms to enhance endpoint security features.
Top Skills:
AgileC++GitWindows Os Kernel Development
What you need to know about the Belfast Tech Scene
If asked to name the birthplace of the RMS Titanic, you might not say Belfast. Similarly, if asked to name Europe's leading destination for foreign direct investment in new software development, Belfast might not come to mind. Yet, both are true. The city has emerged as a tech powerhouse, recently ranked among the best in the U.K. for tech careers — especially for software developers. It also leads the U.K. with the highest percentage of software development jobs advertised.



