At a Glance
- Tasks: Secure and enhance software development processes in a dynamic DevSecOps environment.
- Company: Join a leading financial institution in Sheffield, UK, with a focus on innovation.
- Benefits: Hybrid work model, competitive pay, and opportunities for professional growth.
- Other info: Collaborate with diverse teams and influence senior leadership in a fast-paced setting.
- Why this job: Make a real impact on security practices in a complex, regulated environment.
- Qualifications: Experience in cybersecurity, DevSecOps, and strong communication skills required.
The predicted salary is between 63000 - 77000 Β£ per year.
We have one open position of DevSecOps Security Engineer with one of our clients based in Sheffield, UK. This is a contract and hybrid position.
Role: DevSecOps Security Engineer
Mode: Contract Inside IR35
Location: Sheffield, UK (3 Days per week work from office)
Job Description:
- Proven expertise in Cybersecurity within large-scale regulated financial institutions or similarly complex environments.
- Deep technical knowledge of engineering platforms including CICD systems, build tools, artifact repositories, runtime environments, and developer tooling.
- Strong experience with DevSecOps practices including secure pipeline design, integration of security scanning tools, and automation of security controls.
- Strong knowledge and understanding of service mesh, cryptography, network security, application security, vulnerability management, and risk management.
- Demonstrable ability to conduct threat modelling, platform security assessments, and gap analysis.
- Experience building and implementing maturity models, frameworks, or roadmaps in complex enterprise environments.
- Strong stakeholder management skills with the ability to influence senior leadership and drive change across federated technology teams.
- Excellent communication skills with the ability to translate technical risk into business impact.
- Good to have professional certifications such as CISSP, CISM, CCSK, CCSP, or equivalent.
- Hands-on knowledge of cloud security (AWS, Azure, GCP) and container orchestration platforms (e.g., Kubernetes).
- Experience in international and diverse environments with exposure to regulatory engagement.
- Familiarity with engineering excellence practices such as SLSA, supply chain security, SBOM, or secure developer tooling initiatives.
Skills:
- Mandatory Skills: Application Security (application security framework/threat modelling/Secure SDLC/DevSecOps/Application Security Architecture Review), CI/CD Architecture, Network Security Architecture, Risk Management (Credit/Market/IT/Ops).
DevSecOps Security Engineer in Sheffield employer: Thrive IT Systems
Thrive IT Systems is an exceptional employer that fosters a collaborative and innovative work culture, where your contributions directly impact the development of cutting-edge software solutions. Located in the vibrant tech hub of the United Kingdom, we offer competitive benefits, continuous learning opportunities, and a supportive environment that encourages professional growth and creativity, making it an ideal place for passionate Software Engineers to thrive.