DevSecOps Engineer

Ocean InfinityLondon, VA
£90,000Hybrid

About The Position

Ocean Infinity is seeking a DevSecOps Engineer to join their Cyber Security team. This role involves working closely with developers to enhance software delivery speed and security. The DevSecOps Engineer will own the Secure Development Life Cycle, implementing controls proportionate to risk to accelerate delivery rather than hinder it. The position focuses on security within the build process, including software for vessels and autonomous systems. Collaboration with the OT/Marine Cyber Security Engineer is expected for the build-to-run process. The role is suitable for individuals with a range of experience, from recent graduates with strong secure development fundamentals to established practitioners, and includes hands-on technical work, structured development, and mentoring.

Requirements

  • Grounded in secure software development, with solid fundamentals or experience as an application security practitioner.
  • Comfortable working within modern development pipelines and version control systems.
  • Ability to automate security testing within development pipelines.
  • Experience with code analysis and dependency scanning tooling, with the ability to differentiate real risks from noise.
  • Familiarity with cloud environments, ideally Microsoft Azure, including secure configuration and monitoring.
  • Proficiency in threat modeling and translating outputs into actionable remediation for development teams.
  • Confidence in applying controls proportionate to risk and explaining this judgment to both engineers and senior leaders.
  • Excellent communication skills, with the ability to write practical security guidance for developers.
  • Critical thinking skills and initiative.
  • Driven, proactive, and able to work autonomously with minimal supervision towards company goals.
  • Open and receptive to new and different ideas.
  • Willingness to travel up to 25% of the time, both domestically and internationally, for security audits and assurance work.

Nice To Haves

  • A recognized security or cloud certification (e.g., CSSLP, CISSP, or a Microsoft Azure security certification).
  • Experience with ISO/IEC 27001 or UK Ministry of Defence supply chain security requirements.
  • Exposure to operational technology, robotics, maritime, or other safety-critical software.
  • Experience securing machine learning pipelines or setting governance for the use of large language model tools in development.
  • Awareness of data protection and product security regulations (e.g., GDPR, EU Cyber Resilience Act).
  • Experience mentoring or guiding less experienced engineers.

Responsibilities

  • Own and maintain the Secure Development Life Cycle, defining security checks within development workflows for all Ocean Infinity software, including enterprise applications, vessel-bound autonomy and payload software, and Data Services pipelines.
  • Integrate security into development and release pipelines, incorporating automated code analysis, dynamic testing, and dependency checking to identify weaknesses early.
  • Manage secrets across development pipelines and enforce a no-credentials-in-code standard.
  • Conduct threat modeling on new and modified systems, translating findings into prioritized, proportionate fixes for developers.
  • Secure the artificial intelligence and machine learning development pipeline, covering model provenance, training-data lineage, and the secure delivery of autonomy and analytics models, and establish guidelines for AI tool usage in development.
  • Support the secure configuration of build, deployment, and cloud-hosted development environments, primarily in Microsoft Azure.
  • Define and maintain procedures for software testing and for managing supplier firmware and software uploads.
  • Produce software assurance evidence for certifications, client due diligence, and UK Ministry of Defence supply chain requirements.
  • Own and manage the vulnerability disclosure program, and collaborate with external auditors, consultants, and suppliers to enhance software supply chain security.
  • Create clear security guidance for developers and provide concise briefings to leadership, auditors, and clients.

Benefits

  • Opportunities for development beyond the role across multiple disciplines.
  • Inclusive and respectful work environment.
  • Commitment to safety, equality, and education.
  • Focus on environmental responsibility.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service