DevSecOps Engineer
The Company
Nomia helps companies reduce cost, manage risk, and increase efficiency for non-strategic third-party spend. We act as an extension of our customer's procurement team by executing the end-to-end sourcing, supplier onboarding and contracting process for indirect categories of spend.
We are focused on delivering an innovative and disruptive procurement solution to our customers to make managing non-strategic spend simpler, more transparent, and better value.
We are a global team based in the United Kingdom, Singapore, Dubai, Poland, and the United States.
Please note, Nomia operates on a hybrid model, with 3 days a week in the office, and 2 days a week working remotely.
The Role
As we scale, keeping the platform secure, resilient and reliably shippable is mission-critical, and the DevSecOps Engineer owns exactly that: our cloud infrastructure, our environments and our security posture.
This is a hands-on role that builds security and reliability in, rather than bolting them on. You’ll run and harden our Azure estate, automate how we deploy and monitor, and make sound security a built-in property of the platform, so every team can ship quickly and safely.
Reporting to the Release Manager, you will sit within the Engineering team and work closely with our engineers across all of our product squads. You will own the infrastructure, environments and security that every team relies on to build and release.
Key Responsibilities
Cloud infrastructure and environments
Own and optimise our Azure infrastructure, ensuring environments are secure, scalable, resilient and cost-effective as the platform expands into new markets.
Implement and manage Infrastructure-as-Code (IaC) standards and practices, ensuring environments are consistent, repeatable and fully version-controlled across the software lifecycle.
Proactively monitor, maintain and improve platform infrastructure, identifying opportunities to enhance performance, reliability, availability and operational efficiency.
Security
Own the platform's security posture, including identity and access management, secrets management, network security, API security and secure-by-default engineering practices.
Lead vulnerability management and security remediation activities, ensuring risks are identified, prioritised and resolved before reaching production environments.
Support security governance, incident response, compliance and data protection requirements, helping maintain a secure and resilient platform.
Deployment and delivery
Build, maintain and continuously improve CI/CD pipelines and GitHub-based deployment processes, enabling frequent, reliable and automated software releases.
Drive the adoption of source control and deployment automation across Azure services, ensuring infrastructure and platform components are managed through repeatable, auditable release processes.
Partner with engineering and release management teams to deliver safe, observable and reversible deployments that support platform stability, customer commitments and business SLAs.
Requirements
Essential Criteria
Proven experience in a DevOps, DevSecOps or SRE role, running production cloud infrastructure at scale.
Strong hands-on Azure expertise (or a comparable major cloud, with the ability to work in Azure).
Infrastructure as Code experience (Terraform, Bicep, ARM or equivalent).
Experience building and maintaining CI/CD pipelines for frequent, safe releases.
Solid security fundamentals: identity and access management, secrets management, network security, and vulnerability and dependency scanning.
Experience in observability tooling (Datadog or equivalent) for monitoring, logging and alerting.
A bias to automation, and strong communication with both engineers and non-specialist stakeholders.
Strong hands-on experience with GitHub and GitHub Actions, including creating and maintaining deployment pipelines for applications and Azure services across multiple environments
Desirable Criteria
Containerisation and orchestration (Docker, Kubernetes).
A relevant security certification (e.g. Azure Security Engineer, CISSP).
Experience in a regulated or compliance-sensitive B2B SaaS environment.
Familiarity with TypeScript / Node.js and workflow-orchestration tooling.
General Information
Adhere to Nomia's data protection and information security policies at all times.
Promote diversity and inclusion in line with Nomia's core values.
This is a hybrid role, with two office days per week required, potentially more during training or as requested by your supervisor.
Contribute to continuous improvement in systems and processes.
Please note that this role description is a guideline, and duties may evolve over time.
- Department
- Tech
- Location
- Bangalore
- Remote status
- Hybrid
- Employment type
- Full-time
About Nomia
Nomia Ltd is a Procurement Management Company.
Our specialist and experienced teams drive category and geographical insights underpinned and supported by our cloud based Nomia platform. Enabling Nomia to help transform sourcing activities for customers spend.
By combining our AI driven platform with specialism, Nomia enhances spend transparency, lowers costs, boosts compliance, minimises supply chain-risk and enables material ESG impact.