Posted on: 30/06/2026
SO, WHATS THE STORY?
The DTC team consists of agile squads delivering Dr. Martens global digital commerce experience. We have adopted a customer-centric strategy and use modern engineering practices to serve our customers in a manner that is authentic with the brand values.
The DevSecOps Engineer will be a core member of the Brand Experience team, enabling reliable, secure and compliant delivery of our Next.js (React) storefront with a Backend-for-Frontend (BFF) pattern hosted on AWS. The team operates a You Build It, You Run It model where security is engineered in - not bolted on.
This role focuses on embedding security across the entire software delivery lifecycle: secure cloud foundations, hardened pipelines, automated threat and vulnerability management, identity and secrets governance, runtime protection, and audit-ready compliance - so product teams ship faster, with confidence, while meeting global performance, privacy and regulatory expectations in a digital commerce environment.
As the DevSecOps Engineer, you will :
1. AWS Cloud & Platform Security :
- Design and operate secure-by-default AWS foundations for Next.js and BFF workloads, including VPC design, segmentation, edge/CDN protections, and resource-level controls aligned to least privilege.
- Own Infrastructure as Code (IaC) security standards using Terraform and/or CloudFormation, embedding policy-as-code (e.g., Checkov, tfsec, OPA/Conftest) and reusable hardened modules.
- Define and enforce baselines for IAM, KMS, networking, logging, and account/landing-zone guardrails (e.g., AWS Config, Security Hub, GuardDuty, SCPs).
2. Secure CI/CD & Software Supply Chain :
- Build and harden CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins, AWS-native tooling) with integrated SAST, DAST, SCA, IaC scanning, container image scanning, and secrets detection.
- Implement software supply chain controls: signed commits, artifact signing, SBOM generation, dependency provenance, and protected release paths.
- Enable progressive delivery, zero/low-downtime deployments, and safe rollback patterns without compromising security gates.
3. Threat & Vulnerability Management :
- Operate continuous vulnerability discovery across cloud, container, application and dependency layers; drive risk-based prioritisation and remediation SLAs.
- Lead threat modelling and secure design reviews for new features, partnering with engineering and architecture to identify and mitigate risks early.
- Define and operate web application protections (WAF, bot mitigation, rate limiting) for storefront and BFF endpoints.
4. Identity, Secrets & Data Protection :
- Own secrets management and rotation (e.g., AWS Secrets Manager, Parameter Store, HashiCorp Vault), eliminating hard-coded credentials across services and pipelines.
- Implement encryption in transit and at rest, certificate lifecycle management, and key governance using KMS.
- Govern human and workload identity: federation, OIDC for pipelines, role-assumption patterns, and just-in-time access.
5. Compliance, Risk & Governance :
- Operationalise compliance for digital commerce : GDPR-aligned data handling, PCI-DSS scope reduction, and customer data protection through automation and guardrails.
- Automate evidence capture, control validation, and audit-ready reporting; partner with InfoSec, Legal and Privacy stakeholders.
- Maintain security policies, exception management, and risk registers relevant to the DTC platform.
6. Observability, Detection & Incident Response :
- Build security observability: centralised logging, security telemetry, anomaly detection, and alerting using CloudWatch/Datadog/SIEM (or equivalent).
- Participate in on-call rotation; lead security incident triage, coordinate response, and deliver high-quality RCAs with prevention actions.
- Define SLIs/SLOs for security-relevant signals (e.g., mean time to detect/respond, patch latency, control coverage).
7. Developer Enablement & Security Culture :
- Provide self-service security tooling, golden paths, and pre-approved patterns so engineers can move fast safely.
- Produce clear runbooks, playbooks, secure coding guidance and threat-modelling templates to reduce operational and cognitive load on engineers.
- Champion a security-first culture through coaching, lightweight reviews, and visible metrics.
The Stuff That Sets You Apart :
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1649994