
Lead Software Engineer – DevSecOps & Platform Automation
- 🇬🇧 United Kingdom
- Hybrid
- Staff / Principal
- 1 day ago
- DevSecOps
- CI/CD
- Microservices
- IaC
- AI/ML
- SAST
- DAST
- Secrets Management
- triage
- Kubernetes
- Terraform
- CloudFormation
- Bicep
- GitOps
- OpenTelemetry
- Incident Response
- Disaster Recovery
- GitHub Actions
- GitLab CI
- Azure DevOps
- Jenkins
- Azure
- AWS
- GCP
- SonarQube
- SOC2
- ISO 27001
- Python
- PowerShell
- Bash
- AI
- Argo
Role Overview
We are seeking a Lead Software Engineer (DevSecOps) to drive the hands-on delivery of automated, secure, and reliable software delivery capabilities across our product engineering organization. This role is responsible for building, operating, and continuously improving CI/CD pipelines, infrastructure automation, and embedded security controls that enable product teams to ship frequently, safely, and at scale.Â
You will operate as a senior, hands-on engineer and technical lead for a DevSecOps and platform automation team, turning DevSecOps strategy and reference architectures into working, production-grade solutions. You will guide and mentor engineers, own delivery of key platform capabilities, and partner closely with product teams, architects, and Security to embed best practices into day-to-day engineering.Â
Core MissionÂ
Deliver the automation, pipelines, and platform capabilities that make secure, compliant, and reliable software delivery the default for every product team.Â
Key ResponsibilitiesÂ
CI/CD & Delivery Platform EngineeringÂ
- Build, maintain, and continuously improve automated CI/CD pipelines for:Â
- Microservices, APIs, and platform servicesÂ
- Infrastructure-as-CodeÂ
- AI/ML and Agentic AI workloadsÂ
- Implement and evolve reusable pipeline templates and blueprints that are secure by default, self-service, and easy for product teams to adoptÂ
- Implement progressive delivery capabilities, including blue-green and canary deployments, feature flags, and controlled rolloutsÂ
- Own the day-to-day health, performance, and reliability of delivery pipelines, reducing build times and pipeline failuresÂ
- Onboard product teams and new services onto standard pipelines and platform blueprintsÂ
DevSecOps & Supply Chain SecurityÂ
- Implement and tune security controls embedded in pipelines, including:Â
- SAST, DAST, and SCAÂ
- Container and image scanningÂ
- IaC security and policy checksÂ
- SBOM generation and verificationÂ
- Implement secure software supply chain practices, including provenance, artifact signing, dependency governance, and secrets management and rotationÂ
- Work with Security teams to convert policies into automated, enforceable controls and quality gatesÂ
- Triage security findings with product teams, drive timely remediation, and reduce false positives and friction for developersÂ
Cloud, Infrastructure & AutomationÂ
- Engineer and maintain platform automation using:Â
- Kubernetes and container platformsÂ
- Infrastructure-as-Code (Terraform, CloudFormation, ARM/Bicep, etc.)Â
- GitOps patterns for infrastructure and application deliveryÂ
- Build and maintain reusable IaC modules and shared packages to reduce drift and standardise provisioningÂ
- Automate secure, repeatable environment provisioning for dev, test, staging, and production, including multi-tenant and regulated workloadsÂ
- Automate repetitive operational tasks to reduce engineer cognitive load and manual ticketsÂ
- Optimise pipelines and infrastructure for cost, speed, and reliabilityÂ
Observability, Reliability & ResilienceÂ
- Integrate observability into delivery pipelines and platforms, including metrics, logs, and traces (e.g., OpenTelemetry), deployment health checks, and automated rollback signalsÂ
- Implement and report on DORA and deployment reliability metrics (deployment frequency, lead time, change failure rate, MTTR)Â
- Support SRE-aligned practices such as error budgets, runbooks, and post-incident reviewsÂ
- Participate in incident response and on-call rotation for delivery and platform services, driving fast detection and recoveryÂ
- Contribute to disaster recovery automation and regular recovery testingÂ
Technical Leadership & Team EnablementÂ
- Act as technical lead for a DevSecOps and platform automation team, setting priorities, breaking down work, and owning delivery commitmentsÂ
- Translate standards and reference architectures defined with Principal Engineers and Architects into practical, working implementationsÂ
- Conduct code and design reviews for pipelines, IaC, and automation, ensuring quality, security, and maintainabilityÂ
- Coach and mentor engineers in DevSecOps, CI/CD, and platform engineering practicesÂ
- Create clear documentation, runbooks, and golden-path guidance that help product teams self-serveÂ
- Champion best practices through enablement, collaboration, and continuous improvementÂ
Required Experience & SkillsÂ
DevSecOps & Platform EngineeringÂ
- 8+ years of software engineering experience, including at least 4 years focused on DevSecOps, CI/CD, and platform automationÂ
- Proven experience building and operating automated delivery pipelines and platform capabilities in productionÂ
- Experience leading or acting as technical lead for a small engineering team or workstreamÂ
- Solid understanding of software supply chain security principlesÂ
CI/CD Tooling & AutomationÂ
- Strong hands-on experience with CI/CD systems (e.g., GitHub Actions, GitLab CI, Azure DevOps, Jenkins)Â
- Experience with artifact repositories and container registriesÂ
- Proficiency with pipeline-as-code and building reusable templatesÂ
- Exposure to self-service developer platforms or internal developer portalsÂ
Cloud & InfrastructureÂ
- Strong experience with at least one major cloud platform (Azure preferred; AWS or GCP also valued)Â
- Hands-on experience with Kubernetes and container orchestrationÂ
- Strong Infrastructure-as-Code skills, particularly TerraformÂ
- Working knowledge of cloud networking, identity, and secrets managementÂ
Security & ComplianceÂ
- Hands-on experience integrating SAST, DAST, and SCA tools (e.g., SonarQube, Black Duck, or similar) into pipelinesÂ
- Experience with container, cloud, and IaC security scanningÂ
- Familiarity with policy-as-code (e.g., OPA or similar)Â
- Awareness of compliance frameworks (SOC 2, ISO 27001, PCI, etc.) and how they translate into engineering controlsÂ
Engineering MindsetÂ
- Strong coding and scripting skills in one or more languages (e.g., Python, Go, PowerShell, Bash)Â
- Strong troubleshooting skills across pipelines, containers, and cloud infrastructureÂ
- Pragmatic, delivery-focused approach that balances security, speed, and developer experienceÂ
- Clear written and verbal communication skills, with the ability to explain technical topics to engineers and stakeholdersÂ
- Comfortable using AI-assisted development tools to accelerate engineering and automation workÂ
Nice to HaveÂ
- Experience supporting AI/ML or Agentic AI pipelinesÂ
- Familiarity with GitOps tooling (Argo CD, Flux)Â
- Experience in regulated or highly audited environmentsÂ
- Contributions to internal developer platforms or golden pathsÂ
- Relevant certifications (e.g., Azure DevOps Engineer Expert, Certified Kubernetes Administrator, HashiCorp Terraform Associate)Â
Â
Our Interview Practices
To maintain a fair and genuine hiring process, we kindly ask that all candidates participate in interviews without the assistance of AI tools or external prompts. Our interview process is designed to assess your individual skills, experiences, and communication style. We value authenticity and want to ensure we’re getting to know you—not a digital assistant. To help maintain this integrity, we ask to remove virtual backgrounds and include in-person interviews in our hiring process. Please note that use of AI-generated responses or third-party support during interviews will be grounds for disqualification from the recruitment process.
Applicants may be required to appear onsite at a Wolters Kluwer office as part of the recruitment process.
Lead Software Engineer – DevSecOps & Platform Automation · Wolters Kluwer Tax and Accounting Nederland B.V.