DevSecOps Architect

DevSecOps Architect

Apprenticeship 60000 - 84000 £ / year (est.) Home office (partial)
M

At a Glance

  • Tasks: Architect and build secure automation for our engineering teams to ship code efficiently.
  • Company: Join Multiverse, the UK's first EdTech unicorn transforming workforce skills.
  • Benefits: Enjoy 27 days holiday, health perks, hybrid work, and a vibrant office culture.
  • Why this job: Be at the forefront of AI and tech, making a real impact on security practices.
  • Qualifications: Experience in cloud security, automation, and CI/CD pipelines is a plus.
  • Other info: Diverse team with a commitment to inclusion and personal growth.

The predicted salary is between 60000 - 84000 £ per year.

Multiverse is the upskilling platform for AI and Tech adoption. We have partnered with 1,500+ companies to deliver a new kind of learning that transforms today’s workforce. Our upskilling apprenticeships are designed for people of any age and career stage to build critical AI, data, and tech skills. Our learners have driven $2bn+ ROI for their employers, using the skills they’ve learned to improve productivity and measurable performance.

In June 2022, we announced a $220 million Series D funding round co-led by StepStone Group, Lightspeed Venture Partners and General Catalyst. With a post-money valuation of $1.7bn, the round makes us the UK’s first EdTech unicorn. We have ambitious plans to continue scaling with a strong operational footprint and 800+ employees. We are building a world where tech skills unlock people’s potential and output.

We are looking for a DevSecOps Architect to join our Information Security team. In this role, you will be a collaborative and strategic partner to our engineering teams, helping design the automation that enables us to ship secure code at velocity. You will advocate for a "Security by Design" culture, ensuring that robust security practices are seamlessly integrated into the fabric of our product development processes.

We are committed to building a diverse and inclusive team. We believe that different perspectives and backgrounds are what make our company and our products stronger.

What You’ll Be Doing

  • Your goal is to architect and build a frictionless security environment where the secure path is the easiest path for our developers.
  • Architect Automated Security Pipelines: Partner with the Platform team to design and implement advanced automated security controls (SAST, DAST, SCA) within our CI/CD pipelines, providing engineers with rapid, high-fidelity feedback.
  • Infrastructure and Policy as Code: You will guide the security architecture for our AWS environment by treating infrastructure as software enabling secure and scalable deployments and ensure automated compliance.
  • Threat Detection Engineering: Engineer advanced threat detection capabilities by integrating platform logs and event data (including RabbitMQ) into our SIEM (Google Security Operations). You will develop and tune YARA-L rules to proactively identify and respond to threats.
  • Collaborative Design and Threat Modelling: Partner with engineering squads during the design phase of new features, facilitating collaborative threat modelling sessions to build security in from the start.
  • Developer Enablement: Create feedback loops that deliver security insights directly into developer workflows (e.g., automated PR comments), enabling teams to self-remediate and learn continuously.

What You Will Bring

We are looking for a pragmatic architect who combines technical expertise with a passion for enabling engineering excellence. You do not need to meet every single point below to apply. If you are passionate about security automation and modern, AI-driven engineering practices, we want to hear from you.

  • Core Skills and Experience:
  • Cloud Security Architecture: Experience designing secure, scalable architectures on cloud platforms. (We use AWS, but if you have strong experience in GCP or Azure, we are happy to support your transition).
  • Infrastructure as Code: Experience securing Terraform codebases and building secure modules for other teams to use.
  • CI/CD Orchestration: Experience with modern pipelines (e.g., CircleCI, GitHub Actions, or GitLab) and integrating security steps.
  • Automation Engineering: Ability to write script and code (e.g., Python, Typescript) to build integrations and tooling.
  • Modern Detection Engineering: An interest in or experience with modern detection engineering (e.g., Google Chronicle, YARA-L, or similar SIEM tools).
  • Architecture Patterns: Familiarity with securing API-first and Event-Driven Architectures.
  • Incident Response and Operations: Participate in the team’s on-call rotation, including out-of-hours coverage to support platform availability and security. We strive to keep our rotation sustainable and low-noise to respect your work-life balance. You will assist in troubleshooting critical issues, lead the response for security-specific incidents. Crucially, we believe in a blameless culture, so you will drive post-mortems focused on learning and preventing recurrence.
  • Ambiguity: You thrive in ambiguous and fast-changing environments, and know how to make progress even when requirements are evolving.

Bonus points if you have:

  • Experience with automated policy enforcement.
  • Familiarity with functional programming concepts or Elixir (our core backend language).
  • Familiarity with securing AI/ML pipelines or services.
  • Experience implementing SCA (Software Composition Analysis).
  • A pragmatic approach: You focus on high-impact security wins that support business agility rather than "security for security’s sake."

About Certifications

We value practical experience and a willingness to learn over specific acronyms. While certifications like CISSP, CISM, or AWS Security are a bonus, they are not required to join our team.

Benefits

  • Time off - 27 days holiday, plus 5 additional days off: 1 life event day, 2 volunteer days, 2 company-wide wellbeing days (M-Powered Weekend) and 8 bank holidays per year.
  • Health & Wellness - private medical Insurance with Bupa, a medical cashback scheme, life insurance, gym membership & wellness resources through Wellhub and access to Spill - all in one mental health support.
  • Hybrid work offering - for most roles we collaborate in the office three days per week with the exception of Coaches and Instructors who collaborate in the office once a month.
  • Work-from-anywhere scheme - you’ll have the opportunity to work from anywhere, up to 10 days per year.
  • Space to connect: Beyond the desk, we make time for weekly catch-ups, seasonal celebrations, and have a kitchen that’s always stocked!

Our Commitment to Diversity, Equity and Inclusion

We’re an equal opportunities employer. And proud of it. Every applicant and employee is afforded the same opportunities regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, or veteran status. This will never change.

Our Commitment to Safeguarding

Multiverse is committed to safeguarding and promoting the welfare of our learners. We expect all employees to share this commitment and adhere to our Safeguarding Policy, our Prevent Policy and all other Multiverse company policies. Successful applicants will be required to undertake at least a Basic check via the Disclosure Barring Service (DBS). For roles that will involve a Regulated Activity, successful applicants must also undergo an Enhanced DBS check, including a Children’s Barred List check and a Prohibition Order check. Roles involving Regulated Activity may interact with vulnerable groups, therefore are exempt from the Rehabilitation of Offenders Act 1974 meaning applicants are required to declare any convictions, cautions, reprimands, and final warnings. Providing false information is an offence and could result in the application being rejected or summary dismissal if the applicant has been selected, and possible referral to the police and the DBS.

DevSecOps Architect employer: Multiverse

Multiverse is an exceptional employer that champions a culture of collaboration and innovation, particularly in the dynamic field of AI and tech. With a commitment to employee growth through diverse upskilling opportunities, generous benefits including 27 days of holiday and a hybrid work model, and a strong focus on diversity and inclusion, Multiverse empowers its team to thrive in a supportive environment. Join us in shaping the future of workforce development while enjoying a workplace that values your contributions and well-being.
M

Contact Detail:

Multiverse Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land DevSecOps Architect

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects and contributions. This gives potential employers a taste of what you can do and sets you apart from the crowd.

✨Tip Number 3

Prepare for interviews by practising common questions and scenarios related to DevSecOps. Think about how you would approach security challenges and be ready to discuss your thought process.

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our mission at Multiverse.

We think you need these skills to ace DevSecOps Architect

Cloud Security Architecture
Infrastructure as Code
CI/CD Orchestration
Automation Engineering
Modern Detection Engineering
Architecture Patterns
Incident Response and Operations
Threat Modelling
Security Automation
SAST
DAST
SCA
Python
Typescript
RabbitMQ

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the DevSecOps Architect role. Highlight your relevant experience in cloud security architecture and automation engineering, and don’t forget to mention any specific tools or technologies you’ve worked with that align with our needs.

Show Your Passion: We love seeing candidates who are genuinely excited about security automation and modern engineering practices. Share examples of projects or experiences that showcase your enthusiasm and how you’ve contributed to a 'Security by Design' culture in previous roles.

Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use bullet points where possible to make your skills and experiences easy to read. We appreciate clarity and want to quickly see how you fit into our team!

Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen on joining our awesome team at Multiverse!

How to prepare for a job interview at Multiverse

✨Know Your Tech Inside Out

Make sure you’re well-versed in cloud security architecture, especially with AWS. Brush up on your knowledge of CI/CD pipelines and how to integrate security into them. Being able to discuss specific tools like Terraform or GitHub Actions will show that you’re ready to hit the ground running.

✨Showcase Your Automation Skills

Prepare to talk about your experience with automation engineering. Bring examples of scripts or code you've written, particularly in Python or Typescript, that demonstrate your ability to build integrations and tooling. This will highlight your hands-on experience and problem-solving skills.

✨Emphasise Collaboration

Since this role involves working closely with engineering teams, be ready to discuss how you’ve facilitated collaborative design sessions or threat modelling in the past. Share specific instances where your input helped improve security practices within a team setting.

✨Be Ready for Real-World Scenarios

Expect questions that test your response to security incidents or ambiguous situations. Prepare to share examples of how you’ve handled critical issues or led post-mortems focused on learning. This will demonstrate your pragmatic approach and commitment to a blameless culture.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

M
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>