DevSecOps Engineer (Associate Consultant / Consultant)
Muss:PythonGitAWSDockerKubernetesCloudBackendQA/TestAgileCI/CDTDDAISecurityHybrid
The DevSecOps Engineer is the primary technical delivery resource for the AI Platform and supports the full software development lifecycle, including AI pipelines, backend services, infrastructure provisioning, CI/CD automation, security controls and system integrations.
The DevSecOps Engineer shall demonstrate proficiency in:
- a) developing agentic AI and document-processing solutions using approved Government AI services;
- b) building and operating cloud-native solutions on AWS GCC;
- c) developing secure APIs and enterprise integrations;
- d) implementing DevSecOps pipelines, infrastructure-as-code, monitoring and security controls;
- e) developing systems that handle legally sensitive and personal data; and
- f) working effectively in Agile, multidisciplinary delivery teams.
- g) Experience with OutSystems Platform integration will be advantageous.
Responsibilities
- Work with Business owner, business analyst and solution architect to translate user stories into technical requirements;
- Develop and maintain API integrations with STREAM, CAMP and any other required systems;
- Design and build the agentic AI pipeline, including LLM API integration, prompt engineering, skill and context design, structured output schemas, confidence scoring, and error handling;
- Work with Software Quality Engineer to develop automation and processes to deploy, manage, scale and monitor applications in data centres and cloud environments;
- Troubleshoot and resolve system and application issues, participating in on-call escalations for critical incidents;
- Take ownership of end-to-end infrastructure and security solutions across the products and relevant systems;
- Deploy and manage monitoring tools to track infrastructure performance, utilisation and health;
- Implement configuration management systems for business continuity and automate disaster recovery measures;
- Ensure provision of virtual machines, databases, application containers and licenses for development teams;
- Configure and maintain CI/CD pipelines, incorporating streamlined change management and release processes;
- Develop scripts and automation tools to support software build, integration and deployment across development and production environments;
- Automate the configuration management of development, QA, and production workloads;
- Design, build, optimise and monitor automation systems to identify bottlenecks and maximise service availability;
- Implement security practices that comply with industry standards to protect MinLaw's data and infrastructure;
- Plan, implement and monitor system security architecture, including threat and risk assessments;
- Perform security checks, such as vulnerability assessments and system hardening, and troubleshoot security incidents; and
- Apply secure configurations and best practices when implementing security controls in infrastructure and applications
Required Experience & Skills
Mandatory
- Degree or diploma in Computer Science, Computer or Electronics Engineering, IT or related disciplines.
- Passion for automation, standardisation, and best practices in infrastructure and security.
- Strong understanding of the Software Development Life Cycle (SDLC), Test-Driven Development (TDD), Continuous Integration (CI), and Continuous Delivery (CD).
- Track record in agentic AI system design with multi-agent pipeline, Bedrock AgentCore, orchestration and MCP Server, RAG knowledge base, HITL architecture.
- Experience in regulatory or compliance contexts where agent outputs must be accurate, auditable and structured for legal decision-makers is a significant advantage.
- Experience working with high availability, high performance and high-security multi-data centre systems and hybrid cloud environments.
- Proficiency in at PowerShell, Python.
- Experience with Git and modern branching workflows.
- Strong understanding of container technologies (Docker, Kubernetes).
- Experience with infrastructure monitoring and observability tools.
- Strong ability to troubleshoot complex issues across system resources and application stacks.
- Experience with CI/CD pipelines (GitHub Actions, GitLab CI).
- Experience with disaster recovery planning, system backup, and restore processes.
- Knowledge of RPM-based software packaging and deployment;
- Experience implementing security controls within CI/CD pipelines and cloud-native architectures.
- Hands-on experience with security assessments, vulnerability scanning and system hardening.
- Strong understanding of network infrastructure, including firewalls, subnets, routing and access controls.
- Experience performing security assessments in government or highly regulated environments.
Added advantage
- Security certifications such as CREST, CISSP, CISM or relevant cloud security credentials.
- Experience working in an organisation that successfully implemented DevSecOps transformation.
- Hands-on experience with API security, secrets management and zero-trust architectures.
- Experience developing and deploying systems on GCC.
- Experience building on OutSystems Platform and/or experience building applications designed to operate as part of a larger shared platform.
- Legal regulatory domain familiarity: Contextual knowledge on legal, enforcement or insolvency workflows to better understand how users interact with the system and how it should help them.
Skill Level:
- Associate Consultant to Consultant