Senior DevSecOps Engineer — Scientific SaaS / Biopharma
Remote: EU/UK based
We are supporting a search for a Senior DevSecOps Engineer to join a growing scientific software organisation building a SaaS platform for biopharmaceutical process development and manufacturing.
This is an important hire for the business because security is becoming increasingly embedded into the way the platform is engineered, deployed, and operated.
Rather than joining a mature security organisation simply to maintain existing controls, the successful person will have the opportunity to shape how security is built into the organisation’s engineering practices from the ground up.
The mandate covers the entire software development and delivery lifecycle, with responsibility for defining security policies, guardrails, automation, monitoring, and secure-by-default engineering practices across a platform handling sensitive scientific and biopharmaceutical data.
You would work closely with DevOps, backend, data, infrastructure, and broader engineering teams, combining hands-on security engineering with governance and enablement. The aim is not to create a security function that slows engineering down, but to build systems that allow teams to develop and deploy securely by default.
This includes everything from CI/CD security and software supply-chain controls through to cloud and Kubernetes security, identity and access management, threat detection, incident response, policy-as-code, and alignment with relevant regulatory and security frameworks.
The role will focus on:
- Defining security policies, engineering standards, and platform guardrails
- Implementing policy-as-code and automated compliance controls
- Embedding SAST, DAST, SCA, secret scanning, and infrastructure scanning into CI/CD
- Building secure-by-default engineering templates and practices
- Strengthening software supply-chain security, including SBOMs, artifact signing, and vulnerability management
- Building threat-detection, logging, monitoring, and alerting capabilities
- Establishing incident-response runbooks and leading remediation when required
- Hardening cloud environments, containers, and Kubernetes workloads
- Strengthening IAM, secrets management, encryption, and network security
- Supporting alignment with frameworks including SOC 2, ISO 27001, GxP/GAMP 5, OWASP, NIST, and CIS standards
- Building a stronger culture of security ownership across engineering
We are looking for someone with:
- 6+ years within DevSecOps, Security Engineering, DevOps, or SRE with a significant security focus
- Strong experience embedding security tooling into CI/CD pipelines
- Cloud security experience across Azure, AWS, or GCP
- Experience securing containers and Kubernetes environments
- Strong Terraform experience
- Experience with policy-as-code technologies such as OPA/Rego
- Python, Bash, Go, or comparable automation skills
- Experience with security monitoring, SIEM/SOAR, CSPM, and threat detection
- Strong understanding of secure SDLC and threat modelling
- Experience defining incident-response processes
- Knowledge of software supply-chain security
Experience within regulated environments, biopharma, GxP, GAMP 5, GDPR, or similar environments would be valuable but is not the sole focus.
This is an excellent opportunity for someone who wants security ownership rather than simply ownership of individual tools. The role will have direct influence over how a sophisticated scientific SaaS platform protects its infrastructure, software, data, customers, and future growth.
Apply here or if you know someone from your network, please let me know.