Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Queen Square Recruitment Limited
a major financial player. Collaborate on high-scale, multi-cloud projects using cutting-edge technologies (AWS, Azure, GCP). Be part of a forward-thinking environment focused on automation, DevSecOps, and cloud-native security. Key Responsibilities Define and lead the enterprise-wide cloud security architecture strategy. Act as a trusted security advisor to senior leadership and engineering teams. Guide the … solutions across applications, infrastructure, and data platforms. Perform threat modelling, architecture reviews, and propose mitigation strategies. Ensure alignment with European regulatory standards (e.g., GDPR, PSD2, DORA, NIS2). Embed DevSecOps into SDLC and CI/CD pipelines using IaC and automation tools. Drive adoption of Zero Trust principles, secure APIs, container security, and logging strategies. What Were Looking For 15+ … NIST CSF, ISO 27001, CSA CCM, PCI DSS). Expert-level knowledge of IAM, network security, encryption, API and application security, container security, and SIEM strategies. Proven leadership in DevSecOps practices and securing modern development pipelines. Certifications such as CISSP, CCSP, AWS Security Specialty, TOGAF, or equivalents are highly desirable. Esther Urtecho Senior Delivery Consultant London | Bristol | Amsterdam More ❯
protect BCG's global operations and users, while enabling innovation and agility across BCG Core, BCG X, and CT worldwide. This role is also accountable for embedding security within DevSecOps practices, enforcing automation at scale, and applying Site Reliability Engineering (SRE) principles across all security services. The role requires strong partnership with ISRM, with a focus on balancing and prioritizing … architecture and engineering roadmap focused on prevention, detection, and rapid response. Drive continuous improvement of security posture while aligning with business needs, regulatory requirements, and user experience expectations. Champion DevSecOps practices to embed security early into development and delivery workflows. Security Platform Engineering: Lead end-to-end engineering for identity and access management (IAM), including authentication, authorization, and privileged access … as CISSP, CCSP, CISM, AWS/Azure Security Specialty, or equivalent. Experience with tools like Okta, Azure AD, CrowdStrike, Tanium, Zscaler, Vault, and other modern security platforms. Familiarity with DevSecOps principles, Infrastructure as Code, and secure software development practices. Who You'll Work With Work Environment & Additional Information: Hybrid or on-site work model. Occasional travel may be required for More ❯
development and cloud-hosting estate. Partnering closely with Information Security, Engineering, and Product teams, you will embed secure-by-design principles throughout the software-development lifecycle (SDLC), champion modern DevSecOps practices, and ensure that security is a first-class citizen in everything we build and operate. This role reports directly to the Chief Technology Officer (CTO) and maintains a dotted … refine the technical security roadmap that aligns with business objectives, industry best practice (e.g., NIST CSF, OWASP SAMM), and compliance frameworks (SOC 2, ISO 27001, GDPR). Secure SDLC & DevSecOps - Build and maintain guardrails for static/dynamic analysis, container and IaC scanning, SBOM management, and supply-chain security; automate enforcement through CI/CD pipelines. Cloud & Infrastructure Security - Design More ❯
DevSecOps Engineer - Permanent (£65k - £78K + bonus, benefits) We are working with a globally renowned and industry leading UK brand who are going through an exciting phase of growth across their wider Security function, resulting in the need for a DevSecOps Engineer. As a DevSecOps Engineer, you will work within a newly established team in a role that sees you … provide hands-on Application Security and DevSecOps responsibilities, as well as being involved in various strategic activities. Your duties would include setting-up, securing and enhancing pipelines, scripting and automation, as well as looking at how things are done, what improvements can be made, supporting cyber change initiatives and driving security awareness/practices as necessary. This role will continue … the opportunity for progression and development unavailable at most companies of a similar size, who also offer some of the best perks & benefits available! Key skills and experience required: DevSecOps experience Application Security expertise across SAST, DAST & SCA Background and experience in Software Development/Scripting/Automation Ability to work in a fast-paced environment Ability to work on More ❯
Your new company Working for a globally renowned financial organisation. Your new role Working for this globally renowned financial exchange organisation as a Senior DevSecOps (IAM) Engineer you will play a key role within the Information Security Team. This is an exciting transformation role which offers significant responsibility and opportunity to help shape and deliver the next generation of the … systems across their full lifecycle - from design, deployment to operations and maintenance - while thriving in a fast-paced environment. What you'll need to succeed Strong experience as a DevSecOps Engineer/Security/DevOps Engineer. Great programming ability with Python or Powershell - you know your languages! Deep experience in IAM (Identity Access Management) e.g Active Directory! Strong knowledge of More ❯
Employment Type: Contract
Rate: £750.0 - £850.0 per day + £750-850 Per Day Inside IR35
Your new company Working for a globally renowned financial organisation. Your new role Working for this globally renowned financial exchange organisation as a Senior DevSecOps (IAM) Engineer you will play a key role within the Information Security Team. This is an exciting transformation role which offers significant responsibility and opportunity to help shape and deliver the next generation of the … systems across their full lifecycle - from design, deployment to operations and maintenance - while thriving in a fast-paced environment. What you'll need to succeed Strong experience as a DevSecOps Engineer/Security/DevOps Engineer. Great programming ability with Python or Powershell - you know your languages! Deep experience in IAM (Identity Access Management) e.g Active Directory! Strong knowledge of More ❯
Your new company Working for a globally renowned financial organisation. Your new role Working for this globally renowned financial exchange organisation as a Senior DevSecOps (IAM) Engineer you will play a key role within the Information Security Team. This is an exciting transformation role which offers significant responsibility and opportunity to help shape and deliver the next generation of the … systems across their full lifecycle - from design, deployment to operations and maintenance - while thriving in a fast-paced environment. What you'll need to succeed Strong experience as a DevSecOps Engineer/Security/DevOps Engineer. Great programming ability with Python or Powershell - you know your languages! Deep experience in IAM (Identity Access Management) or Active Directory! Some knowledge of More ❯
Employment Type: Contract
Rate: £775 - £850.0 per day + £750-850 Per Day Inside IR35
Your new company Working for a globally renowned financial organisation. Your new role Working for this globally renowned financial exchange organisation as a Senior DevSecOps (IAM) Engineer you will play a key role within the Information Security Team. This is an exciting transformation role which offers significant responsibility and opportunity to help shape and deliver the next generation of the … systems across their full lifecycle - from design, deployment to operations and maintenance - while thriving in a fast-paced environment. What you'll need to succeed Strong experience as a DevSecOps Engineer/Security/DevOps Engineer. Great programming ability with Python or Powershell - you know your languages! Deep experience in IAM (Identity Access Management) or Active Directory! Some knowledge of More ❯
Milton Keynes, Buckinghamshire, United Kingdom Hybrid / WFH Options
Allica Bank
with various teams, such as Engineering, Platform, Risk, and Compliance, to address any security concerns and implement necessary measures. Role Description We are looking for an experienced and dynamic DevSecOps Engineerto join our security team. The role will be pivotal in building, leading and enhancing our security posture. You will lead a team of security engineers, drive security initiatives and More ❯
and scalable platforms across public and hybrid cloud environments, working closely with architects, SMEs, and engineering squads to shape and implement the next generation of infrastructure-as-code and DevSecOps pipelines. As a Cloud Platform Engineer, you will: Build and automate IaaS and PaaS platforms across public, private, and hybrid cloud environments Create and manage solutions such as landing zones … container platforms, DevSecOps pipelines, observability stacks, and integration layers Use modern tooling like Terraform , CI/CD pipelines , and cloud-native security frameworks Collaborate with product teams, cloud architects, and stakeholders to rapidly deliver working solutions Apply Agile delivery principles (Scrum, Kanban, SAFe) within a cross-functional team Contribute to the continuous improvement of platform design, cloud governance, and DevOps … cloud or hybrid platforms Implementing cloud-native operations, observability, or SRE practices Working with Kubernetes, container orchestration, and modern networking patterns Securing cloud infrastructure and deploying secure coding practices (DevSecOps) Migrating legacy workloads to the cloud using agile methodologies Working within product-led or platform team models This is an opportunity to join a fast-growing, delivery-focused organisation with More ❯
application teams to drive cloud security initiatives and align with the broader security strategy. Enhance and secure CI/CD pipelines across multiple applications by embedding secure coding and DevSecOps best practices. Develop automation tools and scripts to streamline security processes, monitor key security metrics, and support operational demands. Stay up to date with emerging threats, industry trends, and mitigation … techniques to continually improve cloud security controls. Required Skills and Experience: Minimum 3 years in a DevSecOps capacity and 5+ years in cloud security or engineering roles. Strong expertise in AWS cloud services and associated security features; familiarity with Azure is advantageous. Solid understanding of networking, systems engineering, and cybersecurity within cloud environments. Hands-on experience with Infrastructure as Code More ❯
application teams to drive cloud security initiatives and align with the broader security strategy. Enhance and secure CI/CD pipelines across multiple applications by embedding secure coding and DevSecOps best practices. Develop automation tools and scripts to streamline security processes, monitor key security metrics, and support operational demands. Stay up to date with emerging threats, industry trends, and mitigation … techniques to continually improve cloud security controls. Required Skills and Experience: Minimum 3 years in a DevSecOps capacity and 5+ years in cloud security or engineering roles. Strong expertise in AWS cloud services and associated security features; familiarity with Azure is advantageous. Solid understanding of networking, systems engineering, and cybersecurity within cloud environments. Hands-on experience with Infrastructure as Code More ❯
Farnborough, Hampshire, South East, United Kingdom Hybrid / WFH Options
Talent Locker
security policies and documentation * Managing risk using frameworks like NIST 800-53 and producing key security artefacts (RMAs, Security Aspects, Test Plans, etc.) * Working with cross-functional teams including DevSecOps, Software, Infrastructure and Agile delivery * Leading on security assurance processes across the programme lifecycle * Providing strategic guidance on cyber security, threat mitigation, and compliance * Engaging with MOD stakeholders, accreditors, and … data inspection etc.) * Familiarity with JSP 604/453 and MOD assurance frameworks * High standards in documentation and stakeholder communication * Currently DV (Developed Vetting) Cleared Bonus if you have: DevSecOps, Agile or CI/CD experience, or exposure to tools like Azure, AWS, Kubernetes, NodeJS, MongoDB, or Kafka Do you want to work on some of the best projects in More ❯
Farnborough, Hampshire, South East, United Kingdom Hybrid / WFH Options
Talent Locker
security policies and documentation * Managing risk using frameworks like NIST 800-53 and producing key security artefacts (RMAs, Security Aspects, Test Plans, etc.) * Working with cross-functional teams including DevSecOps, Software, Infrastructure and Agile delivery * Leading on security assurance processes across the programme lifecycle * Providing strategic guidance on cyber security, threat mitigation, and compliance * Engaging with MOD stakeholders, accreditors, and … data inspection etc.) * Familiarity with JSP 604/453 and MOD assurance frameworks * High standards in documentation and stakeholder communication * Currently DV (Developed Vetting) Cleared Bonus if you have: DevSecOps, Agile or CI/CD experience, or exposure to tools like Azure, AWS, Kubernetes, NodeJS, MongoDB, or Kafka Do you want to work on some of the best projects in More ❯
Nottingham, Nottinghamshire, United Kingdom Hybrid / WFH Options
Commify
the adoption of modern engineering practices and productivity tools, including AI-powered tooling such as GitHub Copilot and Cursor to enhance developer velocity and code quality. Champion Continuous Delivery & DevSecOps: Implement and mature modern continuous delivery practices, including feature flagging, trunk-based development, automated quality gates, and embedding application security tooling (SAST, SCA) directly into the development workflow. Engage Commercially … first culture. Proven experience leading platform and product migrations from on-premise to the cloud, ideally utilising serverless technologies on Microsoft Azure. Strong experience implementing modern continuous delivery and DevSecOps best practices, including feature flagging, trunk-based development, A/B testing, and automated quality and security gates (SAST, SCA). Expertise in driving Agile transformations and implementing Agile at More ❯
Pathogen Programme. In this critical role, you will take ownership of the full lifecycle and infrastructure that powers our cutting-edge data platform. Working closely with data engineers and DevSecOps teams, you will ensure our platforms are efficient, secure, scalable, and fully aligned with the evolving needs of our research teams and scientists driving global pathogen research. Key Responsibilities: Manage … with EIT standards. Collaborate with architects and engineers to build optimized data platform components, including genomic variant stores, sequence stores, and databases tailored for pathogen analytics. Work with the DevSecOps engineer to ensure all deployments are automated using a standard toolchain. Enable engineers to perform common tasks using automated self-service scripts. Lead the systems administration and operations of our More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
Junglee Games India Private Limited
modelling, and security tooling (e.g. SAST, DAST, SCA, IaC scanning, container security, etc.), ensuring consistency and maturity in how applications are built and maintained. By aligning teams with modern DevSecOps principles, developer enablement, and security automation, the role plays a critical part in improving the overall security posture of Flutter's software estate. Overall, the Senior Product Security Architect is … integration experience is a plus Familiarity with industry frameworks and standards: OWASP SAMM, OWASP ASVS, BSIMM, NIST SSDF, ISO 27034. Lead teams and projects. This could be as an DevSecOps team lead, security architect, or manager for SSDLC initiatives. Professional certifications in security are highly valued, such as CISSP/CSSLP, CISM, and/or other AppSec-specific certifications. What More ❯
our DevOps Integrations team, you'll design and build user-centric tooling that empowers development teams worldwide. You'll be responsible for architecting and coding complex integrations across our DevSecOps toolchain, driving security and efficiency into every stage of the software delivery lifecycle. Key Responsibilities Plugin Development & SupportArchitect, implement, and maintain Gradle, Maven, npm, and PyPI plugins for SBOM collection … engineers to evolve plugin feature sets and ensure robust error handling and observability. Microservices & APIs Design, develop, and support RESTful microservices in Java 17 (and occasionally Go) to expose DevSecOps capabilities. Package and deploy services to OpenShift/Kubernetes clusters, ensuring scalability and high availability. DevSecOps Toolchain Integration Integrate with and extend APIs for Synopsys BlackDuck, Snyk, OWASP Dependency-Track … to onboard and troubleshoot integrations. Produce clear, user-focused documentation, sample code, and run regular "office hours" to drive adoption. Stay current on containerization, cloud-native patterns, and emerging DevSecOps best practices. Propose and prototype enhancements to tooling, workflows, and our overall security posture. Required Skills & Experience Software Engineering 5+ years in web-based Java development (Java 8+), including build More ❯
Birmingham, West Midlands, West Midlands (County), United Kingdom
ARM
note - The selected candidate must be eligible for UK Security Clearance *** The Security Development and Test Director is responsible for overseeing the secure software development lifecycle, security testing, and DevSecOps practices at both strategic and operational levels. The role ensures the effectiveness of security practices in software development, manages security testing, drives operational maturity improvements, and oversees secure coding practices. … profitability analysis. o Monitor expenses and identify cost reduction opportunities. o Ensure profitability through forecasting and margin analysis. o Refine pricing models and maximise billable utilisation. * Secure Architecture and DevSecOps Integration o Define and govern secure architecture standards across development teams, ensuring alignment with enterprise security policies, regulatory requirements, and industry frameworks (e.g., NIST, OWASP, ISO 27001). o Lead … security scanners. o Establish architectural review boards and security design checkpoints to validate that new systems and applications meet defined security requirements before deployment. o Drive continuous improvement in DevSecOps maturity, using metrics and feedback loops to refine processes, reduce risk exposure, and accelerate secure delivery. o Collaborate with enterprise architects, engineering leads, and product owners to ensure security is More ❯
redefining how enterprise-grade security is built, deployed, and continuously improved. They're now seeking a Security Development and Test Director to lead their secure software engineering function, drive DevSecOps maturity, and embed security across the development lifecycle. This is a client-facing, commercially strategic position – ideal for a security leader who thrives at the intersection of technical delivery and … business growth. Why join? Shape and scale a modern secure-by-design function in a high-growth global firm Strategic autonomy to influence architecture standards, DevSecOps integration, and engineering culture Engage directly with major enterprise clients and shape security roadmaps that matter Be part of a company recognised for its DEI leadership and investment in career development What you’ll … within CI/CD workflows Owning security tooling strategy (SAST, DAST, SCA, container scanning) and driving adoption across development pipelines Building and mentoring high-performing teams in secure coding, DevSecOps, and threat modelling Leading engagements with major clients during pre-sales, delivery and review phases Managing financials, resource planning, and service maturity across the Secure SDLC portfolio Acting as escalation More ❯
redefining how enterprise-grade security is built, deployed, and continuously improved. They're now seeking a Security Development and Test Director to lead their secure software engineering function, drive DevSecOps maturity, and embed security across the development lifecycle. This is a client-facing, commercially strategic position - ideal for a security leader who thrives at the intersection of technical delivery and … business growth. Why join? Shape and scale a modern secure-by-design function in a high-growth global firm Strategic autonomy to influence architecture standards, DevSecOps integration, and engineering culture Engage directly with major enterprise clients and shape security roadmaps that matter Be part of a company recognised for its DEI leadership and investment in career development What you'll … within CI/CD workflows Owning security tooling strategy (SAST, DAST, SCA, container scanning) and driving adoption across development pipelines Building and mentoring high-performing teams in secure coding, DevSecOps, and threat modelling Leading engagements with major clients during pre-sales, delivery and review phases Managing financials, resource planning, and service maturity across the Secure SDLC portfolio Acting as escalation More ❯
+ £6,000 Car Allowance | Senior Director Level This is a rare opportunity for an accomplished leader in secure development to shape and drive the future of secure architecture, DevSecOps integration, and software security testing across large-scale transformation programmes. You'll work at both strategic and operational levels, embedding secure-by-design principles across software pipelines while driving improvements … oversee secure development and testing strategy across the SDLC Define and govern secure architecture and ensure alignment with enterprise policies and industry frameworks (e.g. OWASP, NIST, ISO 27001) Drive DevSecOps integration into CI/CD pipelines, embedding SAST, DAST, SCA and container security tools Own the security testing process, improving automation, coverage, and remediation velocity Champion secure design, threat modelling … the function, including budgeting, utilisation, pricing and profitability Lead architectural governance, review boards, and secure design checkpoints Coach and upskill development and QA teams in security best practice and DevSecOps maturity Act as the senior escalation point for clients and internal teams, ensuring delivery excellence What You'll Bring: 10+ years in secure software development, with 5+ in senior/ More ❯
NIST SP800, MOD JSPs, DEFSTANs, and airworthiness directives (e.g., DO-326A, DO-178C). Design secure cloud and hybrid environments using Azure and AWS, incorporating Zero Trust Architecture and DevSecOps methodologies. Collaborate with cross-functional teams to embed cybersecurity into digital transformation initiatives. Evaluate emerging threats, technologies, and regulatory changes to inform strategic security decisions. Support certification and assurance processes … Experience with cross-domain solutions and secure communications systems. Knowledge of MBSE, SysML, and enterprise architecture tools (e.g., Sparx EA, Cameo). Exposure to secure software development practices and DevSecOps pipelines. More ❯
Gloucester, Gloucestershire, South West, United Kingdom
Omega Resource Group
high-quality software solutions in a mission-focused environment. We are looking for someone with a strong software engineering background and hands-on experience in modern practices such as DevSecOps, cloud migration, microservices architecture, and infrastructure as code. In this role, you will provide both technical direction and personnel leadership, supporting the development of innovative, scalable systems, while mentoring a … activities including architecture, development, deployment, and testing. Essential Skills & Experience: Proficiency in one or more software languages: Java, C/C++, Python, TypeScript, ReactJS Understanding of modern engineering practices: DevSecOps, cloud platforms, IaC tools, SRE Experience working with microservice architectures and containerised environments. Strong leadership and mentoring skills, with the ability to inspire and guide a team. Excellent communication skills More ❯
Microsoft Azure Lead Software Security Engineer with Development Background, .NET, Microsoft Stack Developer, DevSecOps, CISSP, CEH, CSSLP, Mainly Remote Software Security Engineer Lead is required to work for a fast-growing and exciting company based in Central London. However, this will mainly be remote and the expectation is to go into the office circa twice a week. Please read in … full before applying We need someone with a Microsoft tech-stack background who has experience as a Azure DevSecOps Consultant or even a good old fashioned Unix/Linux Systems Administrator. We want someone with a development/some form of coding background who has blossomed into Software Security/Cloud Security engineer. We NEED for you to have strong … knowledge of Cloud Software Security (NOT Networking or Infrastructure) Software Security related Certification such as CISSP, CEH (Certified Ethical Hacker) or CSSLP (Certified Secure Software Lifecycle Professional) Passion for DevSecOps and with knowledge of Terraform, Bicep, Sonar Clous, Wiz, and other security product like Trivy Experience with cloud computing platforms such as Microsoft Azure A strong understanding of software development More ❯