DevSecOps Champion

DevSecOps Champion

Full-Time 36000 - 60000 £ / year (est.) No home office possible
Go Premium
IBM

At a Glance

  • Tasks: Help clients integrate security into every stage of software development.
  • Company: Join IBM CIC, a leader in tech innovation and consulting.
  • Benefits: Enjoy flexible working, training opportunities, and competitive benefits.
  • Why this job: Make a real impact on security practices in modern applications.
  • Qualifications: Experience in DevSecOps and application security is preferred.
  • Other info: Diverse teams, career growth, and a culture that values your ideas.

The predicted salary is between 36000 - 60000 £ per year.

Overview

Introduction

At IBM CIC, we provide technical and industry expertise to a wide range of public and private sector clients in the UK. A career in IBM CIC means you\\\’ll have the opportunity to work with leading professionals across multiple industries to improve the hybrid cloud and AI journey for the most innovative and valuable companies in the world. You will get the chance to deliver effective solutions, driving meaningful business change for our clients, using some of the latest technology platforms. Curiosity and a constant quest for knowledge serve as the foundation to success here. You\\\’ll be encouraged and supported to constantly reinvent yourself, focusing on skills in demand in an ever changing market. You\\\’ll be working with diverse teams, coming up with creative solutions which impact a wide network of clients, who may be at their site or one of our CIC or IBM locations. Our culture of evolution centres on long-term career growth and development opportunities in an environment that embraces your unique skills and experience.

We offer:

  • Many training opportunities from classroom to e-learning, mentoring and coaching programs and the chance to gain industry recognized certifications
  • Regular and frequent promotion opportunities to ensure you can drive and develop your career with us
  • Feedback and checkpoints throughout the year
  • Diversity & Inclusion as an essential and authentic component of our culture through our policies and process as well as our Employee Champion teams and support networks
  • A culture where your ideas for growth and innovation are always welcome
  • Internal recognition programs for peer-to-peer appreciation as well as from manager to employees
  • Tools and policies to support your work-life balance from flexible working approaches, sabbatical programs, paid paternity leave, maternity leave and an innovative maternity returners scheme
  • More traditional benefits, such as 25 days holiday (in addition to public holidays), private medical, dental & optical cover, online shopping discounts, an Employee Assistance Program, life assurance and a group personal pension plan of an additional 5% of your base salary paid by us monthly to save for your future.

In this role, you\\\’ll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers), where we deliver deep technical and industry expertise to a wide range of public and private sector clients around the world. Our delivery centers offer our clients locally based skills and technical expertise to drive innovation and adoption of new technology.

Your role and responsibilities

As a DevSecOps Champion within CyberDefend, you will help clients integrate security into every stage of the software development lifecycle. You will act as a trusted advisor on application security, guiding development teams to adopt secure coding practices, mitigate vulnerabilities, and implement security guardrails in hybrid and multicloud environments. This role combines deep technical expertise, hands-on DevSecOps practices, and consulting skills to enable organizations to build resilient, secure applications while minimizing risk across modernized software landscapes.

Responsibilities

  • Embed security practices throughout the SDLC, from design and development to deployment and operations.
  • Lead Threat Modeling exercises to identify, quantify, and mitigate application security risks.
  • Advise on and implement secure coding practices to prevent common vulnerabilities such as SQL injection, XSS, and insecure deserialization.
  • Conduct Static and Dynamic Application Security Testing (SAST/DAST) and provide actionable remediation guidance.
  • Guide teams in API security implementation, including authentication, authorization, and rate limiting.
  • Implement security controls for containerized and microservices architectures, ensuring secure deployment pipelines.
  • Configure and manage Web Application Firewalls (WAFs) to protect critical web applications.
  • Support application security vulnerability management, analyzing high-risk findings and developing mitigation plans while minimizing false positives.
  • Promote DevSecOps methodologies and OWASP Top 10 awareness across development teams and stakeholders.
  • Collaborate with cloud, IAM, and infrastructure teams to ensure security guardrails are effectively applied in multicloud environments.

Required education

None

Preferred education

Bachelor\\\’s Degree

Required technical and professional expertise

  • Hands-on experience in DevSecOps practices and application security.
  • Proficiency in secure coding practices and familiarity with common web vulnerabilities.
  • Experience with SAST and DAST tools for application security testing.
  • Knowledge of Threat Modeling techniques and risk assessment for applications.
  • Understanding of API security, container security, and microservices security.
  • Familiarity with Web Application Firewalls (WAFs).
  • Working knowledge of Secure SDLC and OWASP Top 10 principles.
  • Experience in managing or advising on application security vulnerabilities and remediation planning.
  • Strong consulting and communication skills to translate security requirements into actionable developer guidance.

As an equal opportunities\\\’ employer, we welcome applications from individuals of all backgrounds. However, for you to be eligible for this role, you must have the valid right to work in the UK. Unfortunately, we do not offer visa sponsorship and have no future plans to do so. You must be a resident in the UK and have been living continuously in the UK for the last 3-5 years. You must be able to hold or gain a UK government security clearance.

Preferred technical and professional experience

  • Experience implementing security guardrails in application modernization programs on hybrid/multicloud platforms.
  • Familiarity with cloud IAM integration in DevSecOps pipelines.
  • Professional certifications such as CSSLP, CISSP, CCSP, or DevSecOps-related certifications.
  • Experience with automation/orchestration tools (e.g., Ansible, Terraform) in application security contexts.
  • Hands-on experience with enterprise DevSecOps pipelines, CI/CD security tooling, or secure infrastructure as code.

ABOUT BUSINESS UNIT

IBM Consulting is IBM\\\’s consulting and global professional services business, with market leading capabilities in business and technology transformation. With deep expertise in many industries, we offer strategy, experience, technology, and operations services to many of the most innovative and valuable companies in the world. Our people are focused on accelerating our clients\\\’ businesses through the power of collaboration. We believe in the power of technology responsibly used to help people, partners and the planet.

YOUR LIFE @ IBM

In a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.

Being an IBMer means you\\\’ll be able to learn and develop yourself and your career, you\\\’ll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.

Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.

Are you ready to be an IBMer?

ABOUT IBM

IBM\\\’s greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.

Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we\\\’re also one of the biggest technology and consulting employers, with many of the Fortune 500 companies relying on the IBM Cloud to run their business.

At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it\\\’s time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.

IBM is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.

OTHER RELEVANT JOB DETAILS

IBM wants you to bring your whole self to work and for you this might mean the ability to work flexibly. If you are interested in a flexible working pattern, please talk to our recruitment team to find out if this is possible in the current working environment.

#J-18808-Ljbffr

DevSecOps Champion employer: IBM

At IBM CIC, we pride ourselves on fostering a culture of innovation and continuous learning, making us an exceptional employer for those looking to advance their careers in technology. Our commitment to employee growth is evident through extensive training opportunities, regular promotions, and a supportive environment that values diversity and inclusion. With flexible working arrangements and a comprehensive benefits package, including generous leave policies and health coverage, we ensure our employees can thrive both personally and professionally in the heart of the UK's tech landscape.
IBM

Contact Detail:

IBM Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land DevSecOps Champion

✨Tip Number 1

Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even local tech events. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects and contributions. This is a great way to demonstrate your expertise in DevSecOps and application security to potential employers.

✨Tip Number 3

Prepare for interviews by practicing common questions and scenarios related to DevSecOps. Think about how you would handle specific security challenges and be ready to discuss your thought process. Confidence is key!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search.

We think you need these skills to ace DevSecOps Champion

DevSecOps Practices
Application Security
Secure Coding Practices
Threat Modeling
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
API Security
Container Security
Microservices Security
Web Application Firewalls (WAFs)
Secure Software Development Lifecycle (SDLC)
OWASP Top 10 Principles
Vulnerability Management
Consulting Skills
Communication Skills

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the DevSecOps Champion role. Highlight your relevant experience in application security and DevSecOps practices, and don’t forget to mention any specific tools or methodologies you’ve used that align with the job description.

Showcase Your Skills: Use your written application to demonstrate your technical expertise. Include examples of how you've embedded security practices in the software development lifecycle and any successful projects where you’ve mitigated vulnerabilities. This is your chance to shine!

Be Clear and Concise: Keep your application straightforward and to the point. Use clear language and avoid jargon unless it’s relevant to the role. We want to see your skills and experience without having to sift through unnecessary fluff.

Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way to ensure it gets into the right hands. Plus, you’ll find all the details you need about the role and our company culture there.

How to prepare for a job interview at IBM

✨Know Your Stuff

Make sure you brush up on your DevSecOps knowledge, especially around secure coding practices and common vulnerabilities. Be ready to discuss specific tools like SAST and DAST, and how you've used them in past projects.

✨Show Your Problem-Solving Skills

Prepare to share examples of how you've tackled security challenges in the software development lifecycle. Think about times you've led Threat Modeling exercises or implemented security guardrails, and be ready to explain your thought process.

✨Communicate Clearly

Since this role involves advising teams, practice explaining complex security concepts in simple terms. Use examples from your experience to demonstrate how you can translate security requirements into actionable guidance for developers.

✨Embrace Curiosity

IBM values a constant quest for knowledge, so show your enthusiasm for learning. Discuss any recent training, certifications, or new technologies you've explored that relate to DevSecOps, and express your eagerness to continue growing in this field.

DevSecOps Champion
IBM
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>