At a Glance
- Tasks: Lead and scale DevSecOps capabilities for fast, secure software delivery.
- Company: Join the fourth largest building society in the UK, owned by its members.
- Benefits: Enjoy competitive pay, flexible working, and generous leave policies.
- Other info: Be part of a supportive culture focused on growth and innovation.
- Why this job: Make a real impact on software security and delivery processes.
- Qualifications: Strong leadership and expertise in CI/CD, automation, and security integration.
The predicted salary is between 70000 - 90000 € per year.
As our DevSecOps Capability Manager, you’ll lead and scale Skipton’s DevSecOps capability to enable fast, safe and compliant software delivery across our product and platform teams. You will be accountable for embedding secure‑by‑design principles, modern automation practices, and policy‑as‑code into our CI/CD ecosystem, ensuring that our engineering teams can deliver high‑quality change with confidence. You will drive improvements in lead time, deployment frequency, change failure rate and system reliability, all measured through our Engineering Scorecard. This role blends technical strategy, leadership, governance and hands‑on capability development to strengthen our engineering foundations and support delivery of the Society’s Corporate Plan.
Responsibilities
- Owning lead time for changes and deployment frequency outcomes across shared pipelines and platforms.
- Publishing DORA and flow metrics monthly, using them to drive targeted improvements.
- Removing delivery bottlenecks through automation and policy‑as‑code, including trunk‑based development, automated approvals for low‑risk changes, canary/blue‑green deployment and auto‑rollback.
- Triggering “scorecard → investment” actions when performance thresholds are breached to restore flow, quality and reliability.
- Leading, coaching and developing a team of 3–5 DevSecOps Engineers.
- Defining and maintaining DevSecOps standards, patterns and best practices across engineering teams.
- Building a high‑performing engineering culture focused on security, automation and continuous improvement.
- Setting the strategy for DevSecOps capabilities, including pipeline standardisation and security automation.
- Establishing governance for secure CI/CD, infrastructure‑as‑code and cloud delivery.
- Defining and enforcing Observability Minimum Standards including tracing, SLOs, release‑linked annotations and dashboards.
- Mandating security in the pipeline, including secrets protection, SAST/SCA/DAST, IaC scanning and WAF coverage for external apps.
- Governance of Golden Path (Prod‑OS) templates, patterns and adoption levels.
- Overseeing the reliability, performance and security posture of pipelines, platforms and engineering tooling.
- Ensuring effective vulnerability management, including remediation tracking and escalation.
- Providing leadership during incidents and post‑incident reviews, improving MTTR and root‑cause clarity.
- Integrating telemetry across Azure, Defender, Entra and WAF to unify our security posture.
- Using SLO/error‑budget signals and observability insights to inform go/no‑go and rollback decisions.
- Acting as a senior advisor to Engineering Managers, Product Owners and Cyber Security teams, ensuring strong alignment on security requirements, delivery processes and adoption of modern practices.
- Representing DevSecOps across governance forums and contributing to technology‑wide decisions.
- Leading decisions on DevSecOps tooling, including evaluation and lifecycle management.
- Driving automation across testing, security scanning, deployment, monitoring and compliance.
- Partnering with Cloud and Platform Engineering to ensure scalable, resilient and consistent DevSecOps ecosystems.
- Owning the Golden Path service catalogue, including pipelines, IaC modules and secure defaults.
- Embedding BCP and operational resilience controls directly as policy‑as‑code.
- Ensuring pipelines produce audit‑ready evidence for regulated environments.
- Running periodic gamedays with Release & Environments teams to validate recoverability.
Qualifications
- Strong leadership and people‑management experience, particularly coaching senior engineers.
- Deep expertise in CI/CD design, automation and security integration.
- Strong understanding of cloud platforms, containerisation, infrastructure‑as‑code and modern delivery patterns.
- Demonstrated ability to address and remediate security risks at scale.
- Excellent communication and influencing skills across technical and non‑technical audiences.
- Proven track record of improving DORA and flow metrics through automation and modern engineering practices.
- Experience defining observability standards and implementing unified dashboards.
- Extensive experience in DevOps, security engineering or platform engineering within complex or regulated environments.
- Strong working knowledge of automated security tooling (SAST, SCA, DAST, secrets scanning, container scanning).
- Experience in cloud security, identity and access management, zero‑trust principles and platform guardrails.
- Practical involvement in incident management and post‑incident review processes.
- Demonstrable delivery of policy‑as‑code and compliance‑as‑code in regulated environments.
Behaviours
- Strategic thinker with the ability to influence and shape technology decisions.
- Empowers and develops others, creating a supportive, growth‑focused team environment.
- Outcome‑oriented, maintaining balance between security, speed and reliability.
- Collaborative and influential, building trust across diverse teams.
- Continuous‑improvement mindset, simplifying and enhancing engineering practices.
- Calm under pressure, particularly during incidents or complex challenges.
- Visible champion for modern engineering ways of working and DevSecOps adoption.
Company
We’re not just another building society. We’re the fourth biggest building society in the UK and what makes us a bit different is that we’re a mutual organisation. We don’t have shareholders; we’re owned by our members. Our colleagues say Skipton’s a great place to work, and you could be one of them, bringing with you new ideas on how we can keep customers at the heart of what we do. Whatever your background, and whatever your goals, we’ll help you take the next step towards a better future.
Benefits
- Annual discretionary bonus scheme
- 25 days standard annual leave + bank holidays + rising 1 day per year of service to a maximum of 30 days
- Holiday trading scheme allowing the ability to buy and sell additional annual leave days
- Matching employer pension contribution (up to 10% per annum)
- Colleague mortgage (conditions apply)
- Salary sacrifice scheme for hybrid & electric car
- Commitment to training and development
- Private medical insurance for all our colleagues
- 3 paid volunteering days per annum
- Diverse and inclusive colleague networks available for you to join including our Carers and Pride Alliance groups
- Cycle to work initiative and discounted gym membership
Skipton values work/life balance and we are proud to support hybrid and flexible working, where possible. We have a newly refurbished head office which offers a vibrant and collaborative working space.
DevSecOps Capability Manager in Skipton employer: Skipton Building Society
At Skipton, we pride ourselves on being a supportive and inclusive employer that values the contributions of every team member. As a DevSecOps Capability Manager, you will thrive in a vibrant work culture that prioritises continuous improvement and professional growth, with access to extensive training opportunities and a commitment to work/life balance through flexible working arrangements. Our newly refurbished head office fosters collaboration, while our comprehensive benefits package, including generous annual leave and private medical insurance, ensures that you are well taken care of as you help shape the future of secure software delivery.
StudySmarter Expert Advice🤫
We think this is how you could land DevSecOps Capability Manager in Skipton
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects and contributions. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by practising common questions and scenarios related to DevSecOps. Think about how you can demonstrate your leadership and technical skills through real-life examples.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Skipton.
We think you need these skills to ace DevSecOps Capability Manager in Skipton
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the DevSecOps Capability Manager role. Highlight your experience with CI/CD, automation, and security integration, as these are key aspects of the job.
Showcase Your Leadership Skills:Since this role involves leading a team, don’t forget to mention your leadership experience. Share examples of how you've coached engineers or improved team performance in past roles.
Use Metrics to Your Advantage:Quantify your achievements! If you've improved DORA metrics or deployment frequency in previous positions, make sure to include those figures. It shows you understand the importance of measurable outcomes.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets the attention it deserves. Plus, it’s super easy to do!
How to prepare for a job interview at Skipton Building Society
✨Know Your DevSecOps Inside Out
Make sure you’re well-versed in the principles of DevSecOps, especially around secure-by-design practices and automation. Brush up on your knowledge of CI/CD pipelines, policy-as-code, and how to embed security into every stage of software delivery.
✨Showcase Your Leadership Skills
As a DevSecOps Capability Manager, you'll be leading a team. Prepare examples of how you've successfully coached and developed engineers in the past. Highlight your ability to create a supportive environment that fosters growth and collaboration.
✨Be Metrics-Driven
Familiarise yourself with DORA metrics and flow metrics, as these will be crucial in your role. Be ready to discuss how you've used these metrics to drive improvements in lead time, deployment frequency, and system reliability in previous positions.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills during incidents or complex challenges. Think of specific situations where you’ve improved MTTR or clarified root causes, and be prepared to explain your thought process and actions taken.