DevSecOps ISM Specialist
Technical Consultancy, London
DevSecOps ISM Specialist
Technical Consultancy, London

The team you'll be working with:

Flexible remote-working options

As an Application Security DevSecOps Specialist at NTT DATA, you will integrate security best practices throughout the software development lifecycle (SDLC), implement secure coding standards, and design automation frameworks to ensure robust application security. Collaborate with development teams to establish secure, modernized workflows, embed security tooling in CI/CD pipelines, and secure cloud-native environments. This role offers opportunities to work in cutting-edge agile settings, delivering high-impact security initiatives across diverse industries.

Please note, to be considered for this position you must be eligible for SC clearance

 

What you'll be doing:

Core Responsibilities

  • Security in SDLC
  • Incorporate security controls and standards into all phases of the software development lifecycle (SDLC).
  • Collaborate with developers to adopt secure coding practices, including OWASP compliance.
  • Conduct threat modeling and evaluate design documents to identify security vulnerabilities.
  • Establish security requirements and acceptance criteria for application development projects.

DevSecOps Automation

  • Design and implement security automation within CI/CD workflows using tools for SAST, DAST, IAST, SCA and compliance monitoring.
  • Develop custom security testing frameworks compatible with agile and DevSecOps models.
  • Conduct infrastructure-as-code (IaC) configuration checks and enforce compliance policies.
  • Automate secrets scanning, credential hygiene practices, and dependency vulnerability reviews.

Application Security Testing

  • Execute static (SAST) and dynamic (DAST) application security assessments.
  • Perform manual penetration testing and secure code reviews to detect risks.
  • Analyze application dependencies and third-party components, ensuring vulnerability remediation.
  • Validate security fixes via rigorous regression testing and secure deployment methods.

Security Training and Awareness

  • Prepare training initiatives for developers on secure coding practices, application security principles, and DevSecOps workflows.
  • Create and disseminate security documentation, guidelines, and playbooks for developers and architects.
  • Mentor engineers to adopt security-first product development and incident prevention strategies.
  • Establish and support developer security champion programmes within agile teams.

Cloud and Container Security

  • Implement robust security controls for containerized workloads in Docker, Kubernetes, and similar platforms.
  • Design and secure API endpoints and microservices architectures.
  • Leverage cloud security services on AWS, Azure, or GCP to deliver secure, scalable solutions.
  • Advocate for best practices in secret management, repository vaulting, and cloud-native application monitoring.

Required Qualifications

  • Technical Skills
  • Proficiency in multiple programming languages (e.g., Java, Python, JavaScript, Go, .NET).
  • Extensive experience deploying application security tools like SonarQube, Checkmarx, Veracode, OWASP ZAP.
  • Expertise in CI/CD tools and platforms (e.g., Jenkins, GitHub Actions, Azure DevOps).
  • Solid understanding of container orchestration technologies (e.g., Kubernetes, Docker).
  • Familiarity with cloud platforms (AWS, Azure, GCP) and IaC assessment tools (Terraform, CloudFormation).

Security Expertise

  • Advanced knowledge of the OWASP Top 10 vulnerabilities, secure coding techniques, and cryptographic best practices.
  • Proficiency in API security testing and securing microservices.
  • Hands-on involvement in framework-based security compliance efforts (ISO 27001, GDPR, SOC 2).

What experience you'll bring:

Preferred Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or equivalent experience.
  • 2 to 4 years of direct experience in application security engineering.
  • Familiarity with implementing container security policies and securing high-performance CI/CD development ecosystems.

Success Metrics (6–12 Months)

  • Secure at least 10 client applications through DevSecOps implementation.
  • Achieve 30–40% reduction in vulnerabilities in production environments.
  • Ensure full automation coverage of 90%+ security testing workflows within CI/CD pipelines.
  • Deliver bi-monthly security training, resulting in measurable adoption increases of secure coding practices.

Who we are:

We’re a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.

Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women’s Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network.

For more information on Diversity, Equity and Inclusion please click here: Creating Inclusion Together at NTT DATA UK | NTT DATA

what we'll offer you:

We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.

You can find more information about NTT DATA UK & Ireland here: https://uk.nttdata.com/

We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a proud Disability Confident Committed Employer - we are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.

Back to search Email to a friend Apply now

Location
Epworth House, London

“Upon joining the NTT DATA UK family, you will experience a culturally diverse organisation living our values of Clients First, Teamwork and Foresight as we partner with our customers every day.

At NTT DATA UK, we are proud to support and invest in our people. We offer a variety of rewarding career paths and opportunities to develop professionally - with access to cutting edge innovation.”

Niccolo Spataro, CEO, NTT DATA UK

NTT DATA
#loveyourwork
Apply
Jobs at NTT DATA

Browse all