Senior DevSecOps - Cyber Security (Consulting) in London

Senior DevSecOps - Cyber Security (Consulting) in London

London Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
United States Digital Space LLC

At a Glance

  • Tasks: Lead security practices in software delivery and coach engineering teams for secure development.
  • Company: Join a top-tier tech consulting firm with a global impact.
  • Benefits: Enjoy hybrid working, competitive pay, and opportunities for professional growth.
  • Other info: Dynamic role with excellent career advancement potential.
  • Why this job: Make a real difference in cybersecurity while collaborating with innovative teams.
  • Qualifications: Cybersecurity expertise and experience in DevSecOps assessments required.

The predicted salary is between 60000 - 80000 £ per year.

Company Overview

CTSH is a leading provider of information technology, consulting, and business process outsourcing services, dedicated to helping the world's leading companies build stronger businesses. Headquartered in Teaneck, New Jersey, the company has over 340,000 employees as of January 2025. CTSH is a member of the NASDAQ-100, the S&P 500, the Forbes Global 1000, and the Fortune 500, and is ranked among the top performing and fastest growing companies in the world.

Role Summary

We are seeking a Senior DevSecOps / Security Consultant to assess, embed and uplift security practices across our client’s software delivery lifecycle. This is a security-first role. The candidate comes from a cyber security background, not a developer who has pivoted into security, and will spend time advising and coaching engineering squads to help them design, build and operate platforms securely by default.

The role is not about deploying a new security toolchain from scratch. The client already has tooling in flight; the job is to make it land. That means running a structured maturity assessment, prioritising what matters, embedding existing tools properly into developer workflows, and coaching teams to use them well. The candidate will be the bridge between Information Security and Engineering, moving the client beyond point-in-time audits toward a continuous, automated, shift-left model.

Responsibilities

  • Run the DevSecOps Maturity Assessment – Conduct a comprehensive, evidence-based audit of the client’s current DevSecOps capabilities against recognised industry frameworks.
  • Assess the adoption, configuration and effectiveness of existing controls across SAST, SCA, DAST, IaC scanning, container security and secrets management.
  • Engage stakeholders across engineering, platform, InfoSec and product to gather both qualitative inputs and quantitative evidence.
  • Score each product line against SAMM business functions and produce a clear maturity scorecard.
  • Produce a prioritised 12-month roadmap, sequenced by risk reduction, delivery effort and developer impact.
  • Re-baseline maturity periodically so progress is measurable and defensible to senior stakeholders.
  • Embed Existing Security Tooling into Developer Workflows – Take the tools the client has already invested in and make them genuinely useful.
  • Tune signal-to-noise ratio aggressively.
  • Refine CI/CD security gates.
  • Improve the developer experience of existing controls.
  • Curate and maintain a library of secure CI/CD reference patterns.
  • Coach and Enable Engineering Teams – Embed with developer squads as their trusted security partner.
  • Run secure-coding clinics, brown-bag sessions and pairing sessions.
  • Translate vulnerability findings into clear, contextualised remediation guidance.
  • Champion a security as an enabler culture.
  • Develop enablement materials such as playbooks, cheat sheets and onboarding guides.
  • Lead Threat Modelling and Secure Design – Facilitate threat-modelling sessions at the design phase of new services.
  • Produce lightweight, developer-friendly threat models and secure design patterns.
  • Identify abuse cases, trust boundaries and data-flow risks early.
  • Advise on secure-by-default choices for cloud-native workloads.
  • Track Metrics, Governance and Progress – Define and track meaningful KPIs.
  • Use metrics to evidence movement against the maturity roadmap.
  • Ensure controls remain aligned with internal security standards.

Qualifications

  • Background and Mindset – A security professional first.
  • Comfortable in code – you read pipelines, IaC and application code fluently.
  • Pragmatic, collaborative and delivery-minded.
  • Essential Skills and Experience – Demonstrable experience running DevSecOps or AppSec maturity assessments.
  • A track record of embedding security tooling into existing developer workflows.
  • Working knowledge of CI/CD security tooling and platforms.
  • Solid grounding in container and cloud workload security.
  • Experience facilitating threat-modelling and secure design workshops.
  • Familiarity with OWASP, NIST and MITRE ATT&CK.
  • Strong communication skills.

Desirable

  • Industry certifications such as CISSP, CCSP, CSSLP, CCSK or equivalent.
  • Exposure to policy-as-code and supply-chain tooling.
  • Awareness of AI / LLM application security concerns.
  • Prior consulting experience.

Expected Deliverables

  • A formal DevSecOps Maturity Assessment Report.
  • A prioritised 12-month Shift-Left Implementation Roadmap.
  • A library of Secure CI/CD Reference Patterns.
  • Developer enablement materials.
  • A live Security Metrics view evidencing progress against the maturity roadmap.

Engagement Details

Hybrid working, with on-site presence at the client location as required by the engagement.

Senior DevSecOps - Cyber Security (Consulting) in London employer: United States Digital Space LLC

At CTSH, we pride ourselves on fostering a dynamic and inclusive work culture that prioritises employee growth and development. As a Senior DevSecOps Consultant, you will have the opportunity to work alongside industry leaders in a hybrid environment, where your expertise will directly influence our clients' security practices and software delivery lifecycle. With access to cutting-edge tools and a commitment to continuous learning, CTSH is an exceptional employer for those seeking meaningful and rewarding careers in cyber security.

United States Digital Space LLC

Contact Details:

United States Digital Space LLC Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior DevSecOps - Cyber Security (Consulting) in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including United States Digital Space LLC, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through United States Digital Space LLC

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at United States Digital Space LLC. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior DevSecOps - Cyber Security (Consulting) in London

DevSecOps Maturity Assessment
OWASP SAMM
NIST SSDF
SAST
SCA
DAST
IaC Scanning

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at United States Digital Space LLC insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to United States Digital Space LLC that you’re committed to staying ahead in the game.

How to prepare for a job interview at United States Digital Space LLC

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at United States Digital Space LLC to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at United States Digital Space LLC.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.