Last week I had coffee with a client who asked me what a DevSecOps engineer actually does all day. It wasn't the first time I'd fielded this question. Despite the role becoming one of the hottest tickets in tech recruitment, there's still remarkable confusion about what these professionals contribute beyond vague notions of "shifting security left" and "pipeline integration."
As someone who's placed over 20 DevSecOps specialists in the past 18 months alone, I've developed a pretty clear picture of what the day-to-day really involves. And it's a far cry from the job descriptions I still see floating around.
The reality of DevSecOps in 2026
Forget the neat little diagrams showing DevSecOps as the perfect intersection of three disciplines. In reality, most DevSecOps engineers spend their days knee-deep in code reviews, wrestling with automated scanning tools, and trying to convince developers that security gates aren't just bureaucratic nuisances.
A typical day varies wildly depending on company maturity. At organisations just beginning their DevSecOps journey, engineers often find themselves doing more evangelism than engineering - building buy-in from reluctant development teams who view security as a bottleneck.
At more mature companies, the role becomes increasingly technical. But it's never just about the tools.
Morning: Triage and firefighting
Most DevSecOps engineers I've placed start their day reviewing security scan results. Static application security testing (SAST) and dynamic application security testing (DAST) tools run overnight, generating findings that need quick assessment.
The tools themselves create massive problems. False positives are rampant. One engineer I placed at a London fintech told me he spends roughly 40% of his time simply tuning and customising scanning tools to reduce noise - a fact completely absent from his job description.
"What drives me mad," he said, "is that vendors never mention the tuning overhead when they're selling you the product."
By mid-morning, there's usually at least one security gate that's blocking a deployment. This is where the real work happens - collaborating with developers to understand whether a flagged vulnerability is genuine, exploitable, and how urgently it needs addressing.
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
The tools landscape has completely transformed
While we're on the subject of tools, the DevSecOps toolchain has undergone a seismic shift since the early 2020s. Most organisations now run containerised environments with mesh architectures, which means security needs to be implemented differently.
The days of having separate SAST and DAST tools are largely behind us. The convergence towards unified application security platforms is almost complete, with most enterprises now using integrated solutions that cover everything from code scanning to runtime protection.
Semgrep has become the de facto standard for code scanning, especially since its LLM integration in late 2024 dramatically reduced false positives. Snyk remains dominant in the dependency scanning space. But there's been an interesting resurgence of open-source tools, particularly ZAP by Checkmarx, the open-source DAST tool formerly known as OWASP ZAP, which has become increasingly capable for dynamic testing after Checkmarx hired all three of its core developers in September 2024 and committed to keeping it free.
Policy as code has become non-negotiable. Every DevSecOps engineer I've placed in the past year needs OPA (Open Policy Agent) proficiency. Job descriptions still rarely mention it.
But what's fascinating is how few job descriptions mention any of this.
Afternoon: The endless meetings
After lunch, the calendar fills up. Stand-ups with development teams. Security reviews of new features. Alignment meetings with compliance teams. Tutorials for developers on secure coding practices.
One DevSecOps lead I placed at a major retailer blocks out two hours every Wednesday for "security champions" - developers from each team who get extra security training and act as advocates within their teams.
This relational aspect of the role is what candidates consistently underestimate. You need technical chops, absolutely. But you also need to be part diplomat, part teacher, part salesperson.
The skills gap is getting worse
I've seen roughly 30% more DevSecOps vacancies cross my desk since January, but the candidate pool isn't growing at nearly the same rate. Companies are desperate for people who understand both modern development practices AND security principles.
The most common pain point I hear from hiring managers? Finding engineers who can code securely themselves, not just identify issues in others' code. The ability to contribute security fixes directly, rather than just flagging problems, has become a critical differentiator.
Secondly, cloud security expertise has become non-negotiable. With most organisations running multi-cloud environments, understanding the security models of AWS, Azure and GCP is baseline knowledge now.
How to actually get hired
So you want to break into DevSecOps? The conventional advice about certifications (CySA+, Security+) still holds, but it's no longer enough to differentiate you.
What's working in 2026:
-
Demonstrable coding skills. Your GitHub profile matters more than your CV. Show me secure code you've written, vulnerability fixes you've contributed, or security tools you've built.
-
Cloud certifications with a security focus. AWS Security Specialty or Azure Security Engineer Associate certificates instantly make you more attractive.
-
Container security experience. Kubernetes is everywhere now, and securing containerised workloads requires specialist knowledge that's in desperately short supply.
But the real secret? Find opportunities to practice DevSecOps principles in your current role, even if that's not your job title. Volunteer to be a security champion. Set up basic SAST tools in your team's CI pipeline. Conduct threat modeling workshops.
The salary question
Compensation. DevSecOps engineers command premium salaries, and the range has widened significantly. DevSecOps engineers command premium salaries, and the range has widened significantly.
In London, junior DevSecOps engineers (2-3 years experience) typically earn £65-75K. Mid-level roles (4-6 years) command £80-95K. Senior and lead positions regularly break the £100K barrier, with some financial services firms paying up to £140K base for specialist skills.
Contract rates have seen even steeper increases. Daily rates of £650-850 are now standard for experienced contractors in central London.
But salary inflation is creating problems. I've seen candidates with just enough technical keywords on their CV secure interviews for roles they're completely unsuitable for. The result is an increasingly rigorous technical assessment process.
Looking ahead
The most successful DevSecOps engineers I've placed share one quality: they recognise that their job isn't really about finding vulnerabilities. It's about building secure systems by default.
In practical terms, this means spending less time on reactive scanning and more on proactive measures like creating secure libraries, templates, and components that development teams actually want to use.
Is DevSecOps here to stay as a distinct role? I'm not convinced. I suspect we're in a transitional period where dedicated security engineering skills are needed to transform development practices. But the end goal is surely that all software engineers incorporate security naturally into their work.
For now though, if you're considering this career path, there's never been a better time to jump in. The market needs you desperately.
Just be prepared for a lot more meetings than you're expecting.
Sophie Chen is a specialist technology recruitment consultant who has placed over 100 security professionals in the past three years. She writes about hiring trends in cybersecurity and DevOps.
