DevSecOps Capability Manager in Skipton

DevSecOps Capability Manager in Skipton

Skipton Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Skipton International Ltd

At a Glance

  • Tasks: Lead and scale DevSecOps capabilities for fast, secure software delivery.
  • Company: Join Skipton, the UK's fourth largest building society with a unique mutual ownership.
  • Benefits: Enjoy flexible working, competitive salary, bonus scheme, and 30 days annual leave.
  • Other info: Diverse and inclusive workplace with excellent career growth opportunities.
  • Why this job: Make a real impact on software delivery while developing your leadership skills.
  • Qualifications: Strong leadership, CI/CD expertise, and experience in cloud security required.

The predicted salary is between 60000 - 80000 £ per year.

As our DevSecOps Capability Manager, you’ll lead and scale Skipton’s DevSecOps capability to enable fast, safe and compliant software delivery across our product and platform teams. You will be accountable for embedding secure by design principles, modern automation practices, and policy as code into our CI/CD ecosystem, ensuring that our engineering teams can deliver high quality change with confidence. You will drive improvements in lead time, deployment frequency, change failure rate and system reliability, all measured through our Engineering Scorecard. This role blends technical strategy, leadership, governance and hands-on capability development to strengthen our engineering foundations and support delivery of the Society’s Corporate Plan.

What will you be doing?

  • Value, Flow & Quality
    • Owning lead time for changes and deployment frequency outcomes across shared pipelines and platforms.
    • Publishing DORA and flow metrics monthly, using them to drive targeted improvements.
    • Removing delivery bottlenecks through automation and policy as code, including trunk based development, automated approvals for low risk changes, canary/blue green deployment and auto rollback.
    • Triggering “scorecard → investment” actions when performance thresholds are breached to restore flow, quality and reliability.
  • Leadership & Capability Development
    • Leading, coaching and developing a team of 3–5 DevSecOps Engineers.
    • Defining and maintaining DevSecOps standards, patterns and best practices across engineering teams.
    • Building a high performing engineering culture focused on security, automation and continuous improvement.
  • Strategy, Governance & Technical Direction
    • Setting the strategy for DevSecOps capabilities, including pipeline standardisation and security automation.
    • Establishing governance for secure CI/CD, infrastructure as code and cloud delivery.
    • Defining and enforcing Observability Minimum Standards including tracing, SLOs, release linked annotations and dashboards.
    • Mandating security in the pipeline, including secrets protection, SAST/SCA/DAST, IaC scanning and WAF coverage for external apps.
    • Governing Golden Path (ProdOS) templates, patterns and adoption levels.
  • Operational Oversight & Risk Management
    • Overseeing the reliability, performance and security posture of pipelines, platforms and engineering tooling.
    • Ensuring effective vulnerability management, including remediation tracking and escalation.
    • Providing leadership during incidents and post-incident reviews, improving MTTR and root cause clarity.
    • Integrating telemetry across Azure, Defender, Entra and WAF to unify our security posture.
    • Using SLO/error budget signals and observability insights to inform go/nogo and rollback decisions.
  • Collaboration Across Technology & Business
    • Acting as a senior advisor to Engineering Managers, Product Owners and Cyber Security teams.
    • Ensuring strong alignment on security requirements, delivery processes and adoption of modern practices.
    • Representing DevSecOps across governance forums and contributing to technology-wide decisions.
    • Acting as a visible advocate for safe, rapid delivery and sharing best practice internally and externally.
  • Tooling, Automation & Platform Optimisation
    • Leading decisions on DevSecOps tooling, including evaluation and lifecycle management.
    • Driving automation across testing, security scanning, deployment, monitoring and compliance.
    • Partnering with Cloud and Platform Engineering to ensure scalable, resilient and consistent DevSecOps ecosystems.
    • Owning the Golden Path service catalogue, including pipelines, IaC modules and secure defaults.
  • Business Continuity & Operational Resilience
    • Embedding BCP and operational resilience controls directly as policy as code.
    • Ensuring pipelines produce audit-ready evidence for regulated environments.
    • Running periodic game days with Release & Environments teams to validate recoverability.

What do we need from you?

  • Knowledge, skills & experience
    • Strong leadership and people management experience, particularly coaching senior engineers.
    • Deep expertise in CI/CD design, automation and security integration.
    • Strong understanding of cloud platforms, containerisation, infrastructure as code and modern delivery patterns.
    • Demonstrated ability to address and remediate security risks at scale.
    • Excellent communication and influencing skills across technical and non-technical audiences.
    • Proven track record of improving DORA and flow metrics through automation and modern engineering practices.
    • Experience defining observability standards and implementing unified dashboards.
    • Extensive experience in DevOps, security engineering or platform engineering within complex or regulated environments.
    • Strong working knowledge of automated security tooling (SAST, SCA, DAST, secrets scanning, container scanning).
    • Experience in cloud security, identity and access management, zero trust principles and platform guardrails.
    • Practical involvement in incident management and post-incident review processes.
    • Demonstrable delivery of policy as code and compliance as code in regulated environments.
  • Behaviours
    • Strategic thinker with the ability to influence and shape technology decisions.
    • Empowers and develops others, creating a supportive, growth-focused team environment.
    • Outcome-oriented, maintaining balance between security, speed and reliability.
    • Collaborative and influential, building trust across diverse teams.
    • Continuous improvement mindset, simplifying and enhancing engineering practices.
    • Calm under pressure, particularly during incidents or complex challenges.
    • Visible champion for modern engineering ways of working and DevSecOps adoption.

Who are we?

Not just another building society. Not just another job. We’re the fourth biggest building society in the UK and what makes us a bit different is that we're a mutual organisation. We don't have shareholders; we're owned by our members. Our colleagues say Skipton's a great place to work, and you could be one of them, bringing with you new ideas on how we can keep customers at the heart of what we do. Whatever your background, and whatever your goals, we'll help you take the next step towards a better future.

What’s in it for you?

Skipton values work/life balance and we are proud to support hybrid and flexible working, where possible. We have a newly refurbished head office which offers a vibrant and collaborative working space. We have a range of other benefits available to you including:

  • Annual discretionary bonus scheme
  • 25 days standard annual leave + bank holidays + rising 1 day per year of service to a maximum of 30 days
  • Holiday trading scheme allowing the ability to buy and sell additional annual leave days
  • Matching employer pension contribution (up to 10% per annum)
  • Colleague mortgage (conditions apply)
  • Salary sacrifice scheme for hybrid & electric car
  • A commitment to training and development
  • Private medical insurance for all our colleagues
  • 3 paid volunteering days per annum
  • Diverse and inclusive colleague networks available for you to join including our Carers and Pride Alliance groups
  • We care about your health and wellbeing – we provide a range of benefits that support this including cycle to work initiative and discounted gym membership

Diversity and inclusion are a priority for us as we continue to support our members and represent the communities we serve. We encourage applications from individuals of all backgrounds, ethnicity, gender identity, sexual orientation, disability, neurodiversity, age, family or parental status, beliefs, nationalities and religions - supporting an inclusive environment for all our colleagues to bring their true selves to Skipton.

If you have a disability, or if you have a condition that you believe may affect your performance during our selection process, we’ll be happy to discuss making reasonable adjustments to our processes for you. Please contact our Talent Acquisition team at talentacquisition@skipton.co.uk.

DevSecOps Capability Manager in Skipton employer: Skipton International Ltd

Skipton is an exceptional employer that prioritises work-life balance and offers a vibrant, collaborative working environment in its newly refurbished head office. With a strong commitment to employee development, generous benefits including flexible working options, annual leave that increases with service, and a focus on diversity and inclusion, Skipton empowers its employees to thrive both personally and professionally while contributing to a member-owned organisation that values community and customer-centricity.

Skipton International Ltd

Contact Details:

Skipton International Ltd Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land DevSecOps Capability Manager in Skipton

Tip Number 1

Network like a pro! Reach out to your connections in the industry, attend meetups, and engage in online forums. The more people you know, the better your chances of landing that DevSecOps role.

Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects related to CI/CD, automation, and security integration. This gives potential employers a taste of what you can bring to the table.

Tip Number 3

Prepare for interviews by brushing up on your technical knowledge and soft skills. Practice common interview questions and scenarios related to DevSecOps, and be ready to discuss how you've tackled challenges in the past.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you're genuinely interested in joining our team at Skipton.

We think you need these skills to ace DevSecOps Capability Manager in Skipton

Leadership
People Management
CI/CD Design
Automation
Security Integration
Cloud Platforms
Containerisation

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the DevSecOps Capability Manager role. Highlight your experience with CI/CD, automation, and security integration. We want to see how your skills align with our needs!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about DevSecOps and how you can contribute to our team. Keep it engaging and relevant to the job description.

Showcase Your Achievements:Don’t just list your responsibilities; showcase your achievements! Use metrics to demonstrate how you've improved lead times, deployment frequency, or system reliability in previous roles. We love numbers!

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you get all the updates directly from us. Plus, it’s super easy!

How to prepare for a job interview at Skipton International Ltd

Know Your DevSecOps Inside Out

Make sure you’re well-versed in the principles of DevSecOps, especially around CI/CD design and security integration. Brush up on your knowledge of cloud platforms and automation practices, as these will be key topics during your interview.

Showcase Your Leadership Skills

As a DevSecOps Capability Manager, you'll need to demonstrate strong leadership abilities. Prepare examples of how you've coached and developed teams in the past, focusing on creating a supportive and growth-oriented environment.

Prepare for Technical Questions

Expect technical questions that assess your understanding of security risks, automated security tooling, and observability standards. Be ready to discuss specific metrics you've improved, like DORA metrics, and how you’ve implemented best practices in previous roles.

Emphasise Collaboration and Communication

Highlight your ability to work across diverse teams and communicate effectively with both technical and non-technical audiences. Prepare examples of how you've influenced technology decisions and built trust within teams, as this will be crucial for the role.