DevSecOps Security Consultant in Sheffield

DevSecOps Security Consultant in Sheffield

Sheffield Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
PURVIEW

At a Glance

  • Tasks: Shape cybersecurity for engineering platforms and ensure secure software delivery.
  • Company: Global leader in IT Engineering and Talent Solutions with a diverse team.
  • Benefits: Hybrid work, competitive pay, and opportunities for professional growth.
  • Other info: Join a dynamic team driving digital transformation across 21+ countries.
  • Why this job: Make a real impact on cybersecurity in a leading financial institution.
  • Qualifications: Experience in Cybersecurity and DevSecOps practices required.

The predicted salary is between 60000 - 80000 £ per year.

Purview is a global leader in IT Engineering and Talent Solutions, trusted by Fortune 500 and mid-market clients across 21+ countries. Headquartered in Edinburgh, with delivery centres in India, our 1,200+ professionals drive meaningful digital transformation worldwide.

We are currently hiring for the below role with one of our valued clients. If it aligns with your experience and aspirations, we’d love to hear from you!

Location: Sheffield, UK

Job Type: Contract (Hybrid work mode; 2-3 days is required to travel to the Sheffield, UK location)

We are seeking a highly skilled and experienced Senior Cybersecurity SME / Consultant to join the Engineering Excellence and Enablement team. The successful candidate will work across global engineering platforms to benchmark, uplift, and continuously evolve cybersecurity maturity. This role offers a unique opportunity to shape the cybersecurity posture of engineering platforms at one of the world's leading financial institutions, ensuring the bank can deliver digital services securely, reliably, and at scale.

The role will be accountable for the following:

  • Framework and Assessment
    • Develop and maintain an Engineering-Platform Cybersecurity Maturity Framework to standardise assessments across platforms.
    • Conduct comprehensive platform security reviews (build systems, CI/CD pipelines, runtime infrastructure, developer tooling) against defined framework criteria.
    • Perform threat modelling and gap analysis, identifying vulnerabilities and systemic risks impacting source code, artifacts, and workloads.
  • Engineering Platform Security Enablement
    • Establish standardised secure architecture and engineering patterns for build systems, CI/CD pipelines, runtime environments, and developer tooling.
    • Define and enforce platform security baselines using policy-as-code and automated controls.
    • Partner with platform owners to remediate critical gaps and implement scalable solutions for artifact integrity, access control, and configuration security.
    • Integrate vulnerability management, SBOM, provenance, and code-signing practices within engineering workflows.
  • Roadmap Development & Execution
    • Prioritise identified gaps based on business risk, regulatory impact, and operational criticality.
    • Collaborate with platform owners and engineering leads to build actionable security roadmaps, balancing quick wins with long-term strategic improvements.
    • Partner with engineering teams to design, develop, and embed security patterns and best practices into engineering platforms.
  • Stakeholder Engagement & Governance
    • Serve as a trusted advisor to platform owners, senior technology stakeholders, and Cybersecurity leadership, translating technical risks into business impact.
    • Represent the function in key governance forums, providing updates on maturity progress, roadmap delivery, and risk posture.
    • Influence and align stakeholders across federated engineering teams to ensure consistent adoption of cybersecurity best practices.
  • Continuous Improvement
    • Track and report maturity scores, ensuring measurable improvement across platforms.
    • Continuously evolve the maturity framework in response to emerging threats, technology evolution, and regulatory expectations.
    • Drive a culture of secure-by-design engineering through engagement, advocacy, and knowledge sharing.

To be successful in this role you should have proven experience within the Technology sector with knowledge of the following skills:

  • Proven expertise in Cybersecurity within large-scale, regulated financial institutions or similarly complex environments.
  • Deep technical knowledge of engineering platforms, including CI/CD systems, build tools, artifact repositories, runtime environments, and developer tooling.
  • Strong experience with DevSecOps practices, including secure pipeline design, integration of security scanning tools, and automation of security controls.
  • Strong knowledge and understanding of service mesh, cryptography, network security, application security, vulnerability management, and risk management.
  • Demonstrable ability to conduct threat modelling, platform security assessments, and gap analysis.
  • Experience building and implementing maturity models, frameworks, or roadmaps in complex enterprise environments.
  • Strong stakeholder management skills, with the ability to influence senior leadership and drive change across federated technology teams.
  • Excellent communication skills, with the ability to translate technical risk into business impact.

Good to have:

  • Professional certifications such as CISSP, CISM, CCSK, CCSP, or equivalent.
  • Hands-on knowledge of cloud security (AWS, Azure, GCP) and container orchestration platforms (e.g., Kubernetes).
  • Experience in international and diverse environments, with exposure to regulatory engagement.
  • Familiarity with engineering excellence practices such as SLSA, supply chain security, SBOM, or secure developer tooling initiatives.

DevSecOps Security Consultant in Sheffield employer: PURVIEW

Purview is an exceptional employer, offering a dynamic work environment in Sheffield that fosters innovation and collaboration. With a strong commitment to diversity and employee growth, we provide our team members with opportunities to enhance their skills while working on impactful projects for leading financial institutions. Our hybrid work model promotes flexibility, allowing you to balance professional and personal commitments effectively.

PURVIEW

Contact Details:

PURVIEW Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land DevSecOps Security Consultant in Sheffield

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including PURVIEW, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through PURVIEW

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at PURVIEW. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace DevSecOps Security Consultant in Sheffield

Cybersecurity Expertise
CI/CD Systems Knowledge
DevSecOps Practices
Secure Pipeline Design
Security Scanning Tools Integration
Automation of Security Controls
Threat Modelling

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at PURVIEW insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to PURVIEW that you’re committed to staying ahead in the game.

How to prepare for a job interview at PURVIEW

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at PURVIEW to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at PURVIEW.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.