No Clearance required
DV process will start upon selection
Location: Huntingdon, Cambridgeshire
Required (Core Skills)
- Experience working in MOD or Home Office project environments
- Strong knowledge of network and system security, including firewalls, IDS/IPS, micro-segmentation, and host security.
- Hands-on experience with the following security products: Trellix, Ivanti, ClearSwift, Yubikey
- Understanding of secure coding practices and common vulnerabilities (OWASP Top 10, SANS Top 25).
- Expertise in identity and access management (IAM), including RBAC, ABAC, JWT and Cookie-based authentication.
- Incident detection and response in MOD environments.
- Security compliance and regulatory frameworks (e.g., NIST, CIS Benchmarks).
- Experience working with Kubernetes at an administrative level
Soft Skills
- Strong leadership and mentoring abilities.
- Effective communication with development, operations, and security teams.
- Ability to advocate for security best practices in a DevOps culture.
Desirable Skills
- Containerization Security
- Expertise in Kubernetes security (e.g., RBAC, network policies, pod security standards, secrets management).
- Knowledge of container runtime security (e.g., container escapes, rootless containers, sandboxing).
- Image security best practices, including scanning, signing, and provenance verification.
- Secure deployment patterns using Tanzu & Kubernetes.
- Runtime security monitoring.
- Secure CI/CD pipeline design with security testing using tools like Git and SonarQube.
- Implementation of Infrastructure as Code (IaC) security (e.g., Terraform, Ansible).
- Secrets management in CI/CD pipelines using Vault or Kubernetes Secrets.
- Security automation and policy enforcement using tools like GitHub Actions, GitLab CI, and Jenkins.
- Strong knowledge of cloud security principles in a containerised environment.
- Kubernetes security posture management (KSPM) using tools like Trivy.
- Secure ingress/egress controls, service mesh security (e.g., Istio).
- Encryption strategies for data at rest, in transit, and in use.
- Network security best practices for Tanzu container networking (e.g., NSX, Rancher).
- Compliance monitoring and security auditing for cloud-native environments.
- Scripting skills in Python, PowerShell for security automation.
- API security knowledge (e.g., OAuth, JWT, API gateways, rate limiting).
- Experience with Security as Code for automated policy enforcement.
#J-18808-Ljbffr…