YT Technologies are on the lookout for a skilled Software Engineer to help build cutting-edge DevSecOps software. Due to the nature of the work, only candidates eligible for eDV clearance will be considered Key Skills; High level experience with Java and additional languages such as Python Development experience in Linux environments Solid understanding of JUnit 5.x, unit testing, and mocking framework
20/11/2025
Full time
YT Technologies are on the lookout for a skilled Software Engineer to help build cutting-edge DevSecOps software. Due to the nature of the work, only candidates eligible for eDV clearance will be considered Key Skills; High level experience with Java and additional languages such as Python Development experience in Linux environments Solid understanding of JUnit 5.x, unit testing, and mocking framework
Contract GCP DevOps Engineer (SC Cleared) - Outside IR35 - £450-£550/day Duration: Until March 2026 (likely extensions) 4-6 months Clearance: Active SC required IR35: Outside Location : Largely remote with the expectation to be onsite in London or Corsham when needed My client is looking to build out a new GCP Cloud engineering team. So I am on the look for multiple GCP DevOps/Cloud Engineers to join a fast-moving engineering team building mission-critical, secure GCP platforms with real-world impact. This is a high-autonomy, high-influence role where you'll shape cloud architecture, tooling, and DevSecOps practices while working on the future of trusted, deployable AI infrastructure . What You'll Do Deliver hands-on GCP engineering with a focus on GKE Build and automate infrastructure using Terraform, CI/CD, and cloud-native tooling Deploy secure, reliable, production-grade cloud systems Help drive architectural and tooling decisions in a modern DevSecOps environment What You Need Active SC clearance Strong, practical GCP + GKE experience Terraform, CI/CD, and cloud automation expertise Comfort in a fast-paced SME/mission-focused engineering culture If this is of interest. Drop me your updated CV and availability for a call and we can discuss the role further!
20/11/2025
Contractor
Contract GCP DevOps Engineer (SC Cleared) - Outside IR35 - £450-£550/day Duration: Until March 2026 (likely extensions) 4-6 months Clearance: Active SC required IR35: Outside Location : Largely remote with the expectation to be onsite in London or Corsham when needed My client is looking to build out a new GCP Cloud engineering team. So I am on the look for multiple GCP DevOps/Cloud Engineers to join a fast-moving engineering team building mission-critical, secure GCP platforms with real-world impact. This is a high-autonomy, high-influence role where you'll shape cloud architecture, tooling, and DevSecOps practices while working on the future of trusted, deployable AI infrastructure . What You'll Do Deliver hands-on GCP engineering with a focus on GKE Build and automate infrastructure using Terraform, CI/CD, and cloud-native tooling Deploy secure, reliable, production-grade cloud systems Help drive architectural and tooling decisions in a modern DevSecOps environment What You Need Active SC clearance Strong, practical GCP + GKE experience Terraform, CI/CD, and cloud automation expertise Comfort in a fast-paced SME/mission-focused engineering culture If this is of interest. Drop me your updated CV and availability for a call and we can discuss the role further!
CBSbutler Holdings Limited trading as CBSbutler
Romsey, Hampshire
DevSecOps Engineer 6 months+ 780 per day inside ir35 Romsey/hybrid (3 days per week in the office) SC or DV Security clearance is required for this role Job Description DevSecOps Engineer required to join my clients Defence Information Advantage team to drive best practice in end-to-end SDLC and deployment automation. The Defence domain represents many unique and cutting-edge challenges in DevSecOps, MLOps and utilisation of cloud for example updating deployed equipment in a safe and secure manner. My client seek an innovative thought-leader who can set technical direction and coach others to push the envelope on the art of the possible. The DevSecOps Engineer will exploit the best of cloud and DevSecOps technologies to drive increased rapidity in deployment automation whilst applying SRE principles to the continual operation of live systems to increase up-time. Areas of Responsibility: Join and contribute to agile ceremonies following Scrum, Kanban or SAFe Agile. Coach team members in DevSecOps. Work with product owners and software developers to schedule releases and implement CI/CD pipelines. Work with security architects to ensure the products and services are secure by design. Knowledge and Experience Required: As a DevSecOps Engineer, you will have a degree level qualification in a STEM subject, or an equivalent level of practical experience. Depending on your level of ability/experience, you will have familiarity, competence or expertise in a subset of these areas: Cloud technologies: AWS primarily Azure and GCP beneficial Cyber security Vulnerability management (e.g. tenable) IDAM (e.g Azure AD, Keycloak) Virtualisation and Containerisation Containerisation (e.g. Docker, Podman) Container management (e.g. Kubernetes) Architectural styles Microservices Serverless DevSecOps tooling Version control (e.g. Git) Continuous Integration/Deployment (e.g. Gitlab CI/CD) Infrastructure as code (e.g. Terraform, Puppet, Ansible) If you are interested in this role or wish to apply please feel free to submit your CV.
20/11/2025
Contractor
DevSecOps Engineer 6 months+ 780 per day inside ir35 Romsey/hybrid (3 days per week in the office) SC or DV Security clearance is required for this role Job Description DevSecOps Engineer required to join my clients Defence Information Advantage team to drive best practice in end-to-end SDLC and deployment automation. The Defence domain represents many unique and cutting-edge challenges in DevSecOps, MLOps and utilisation of cloud for example updating deployed equipment in a safe and secure manner. My client seek an innovative thought-leader who can set technical direction and coach others to push the envelope on the art of the possible. The DevSecOps Engineer will exploit the best of cloud and DevSecOps technologies to drive increased rapidity in deployment automation whilst applying SRE principles to the continual operation of live systems to increase up-time. Areas of Responsibility: Join and contribute to agile ceremonies following Scrum, Kanban or SAFe Agile. Coach team members in DevSecOps. Work with product owners and software developers to schedule releases and implement CI/CD pipelines. Work with security architects to ensure the products and services are secure by design. Knowledge and Experience Required: As a DevSecOps Engineer, you will have a degree level qualification in a STEM subject, or an equivalent level of practical experience. Depending on your level of ability/experience, you will have familiarity, competence or expertise in a subset of these areas: Cloud technologies: AWS primarily Azure and GCP beneficial Cyber security Vulnerability management (e.g. tenable) IDAM (e.g Azure AD, Keycloak) Virtualisation and Containerisation Containerisation (e.g. Docker, Podman) Container management (e.g. Kubernetes) Architectural styles Microservices Serverless DevSecOps tooling Version control (e.g. Git) Continuous Integration/Deployment (e.g. Gitlab CI/CD) Infrastructure as code (e.g. Terraform, Puppet, Ansible) If you are interested in this role or wish to apply please feel free to submit your CV.
Location Birmingham, Cardiff, Edinburgh, Exeter, Ipswich, Leeds, London (Croydon & Stratford) Manchester, Newcastle, and Nottingham. About the job Job summary The Insolvency Service is a leading Government agency which plays a crucial role in providing essential services to the public and to business. The work we do is important to the proper functioning of markets, the economy in general and support for thousands of people each year who are in financial difficulty. We have an exciting opportunity for a talented, enthusiastic Lead DevSecOps Engineer within our Digital Services team. We are responsible for developing, maintaining and supporting the agency's line of business applications. Inclusive and diverse teams are important to us. We welcome and encourage applications from everyone, including groups underrepresented in our workforce. The Insolvency Service strives to ensure that the agency is a safe, inclusive, and welcoming place for everybody to bring their true self to work and to help the agency to achieve its diversity objectives. We have 10 active employee network groups available to join or become an ally, these include, Carers Network, Disability & Health, FACES Network Group, Grass Roots, LGBT+, Mind Matters, No Limits, Part Time Workers, The Shed, and Women's Network Group. We offer full-time, part-time, job share and flexible ways of working. We value capability, technical skills and experience and we place great emphasis on lifetime development to support our people. We encourage our employees to become more involved in areas they feel strongly about, whether it be for the benefit of the agency, though our Engagement network or in their own local communities via volunteering opportunities. The Insolvency Service is a great place to work, learn and grow your career! Job description Digital Services is an in-house team, which has recently moved from using a 3rd party DevOps function to bringing it in-house. We are also consolidating our technology stack and moving away from legacy services, so this is a fantastic opportunity to help shape our digital services and the way we work for a sustainable, user-centric future. We would love for you to be part of that team. Digital services is part of Change and Technology Services (CTS), who support and improve applications and systems across the Agency's IT landscape. CTS provide key services including digital services, cyber security and information governance, service architecture and governance and digital programme delivery. DevSecOps look after the deployment and infrastructure of the applications and products we deliver. They keep the lights on and are first to identify and resolve any issues with the live services. They work closely with developers and QAT to ensure the products meet the demands of the users, whilst also ensuring it meets cyber-security demands. As a lead DevSecOps engineer you will lead the DevSecOps team and contribute to the development of the strategic direction of Digital Services. At this role level, you will: Act as a subject matter expert for all DevSecOps responsibilities Provide technical leadership and guidance through coaching and mentoring Work with the Principal Technical Architect to develop technical strategy, define standards and help shape Digital Services knowledge and good practice Responsibilities As a Lead DevSecOps Engineer you will be responsible for: Keeping the applications running in production and non-production environments Ensuring that applications are deployed in a timely and secure manner Defining standards for the successful operation of a DevSecOps function within the Insolvency Service Contributing to priority incident bridge calls and root cause analysis Providing estimates to upcoming DevSecOps activities that are related to the delivery roadmap Working with and providing support to development and operations teams Updating and building deployment pipelines in line with the build and deployment model Raising changes to go through and attending CAB to represent those changes Contributing to the overall improvement of the application technology stack Ensuring that documentation conforms to documentation standards and is up-to-date and reflective of any changes Person specification To be successful in this role you will have: An inquisitive mind, and be able to constructively challenge at all levels to achieve the right results The ability to keep your own and the team's efforts focused on Digital Services goals to help the delivery of our roadmap and value to the business A keen eye for detail and a tenacious approach to work The ability to ask difficult and unpopular questions and make decisions that are evidence based and for the benefit of Digital Services and the wider Insolvency Service Strong analytical and problem-solving skills to be able to identify patterns, draw conclusions and resolve repeatable incidents The ability to build and establish relationships with key stakeholders to support the delivery of business outcomes in a secure and stable manner Good interpersonal and communication skills, both written and verbal
20/11/2025
Full time
Location Birmingham, Cardiff, Edinburgh, Exeter, Ipswich, Leeds, London (Croydon & Stratford) Manchester, Newcastle, and Nottingham. About the job Job summary The Insolvency Service is a leading Government agency which plays a crucial role in providing essential services to the public and to business. The work we do is important to the proper functioning of markets, the economy in general and support for thousands of people each year who are in financial difficulty. We have an exciting opportunity for a talented, enthusiastic Lead DevSecOps Engineer within our Digital Services team. We are responsible for developing, maintaining and supporting the agency's line of business applications. Inclusive and diverse teams are important to us. We welcome and encourage applications from everyone, including groups underrepresented in our workforce. The Insolvency Service strives to ensure that the agency is a safe, inclusive, and welcoming place for everybody to bring their true self to work and to help the agency to achieve its diversity objectives. We have 10 active employee network groups available to join or become an ally, these include, Carers Network, Disability & Health, FACES Network Group, Grass Roots, LGBT+, Mind Matters, No Limits, Part Time Workers, The Shed, and Women's Network Group. We offer full-time, part-time, job share and flexible ways of working. We value capability, technical skills and experience and we place great emphasis on lifetime development to support our people. We encourage our employees to become more involved in areas they feel strongly about, whether it be for the benefit of the agency, though our Engagement network or in their own local communities via volunteering opportunities. The Insolvency Service is a great place to work, learn and grow your career! Job description Digital Services is an in-house team, which has recently moved from using a 3rd party DevOps function to bringing it in-house. We are also consolidating our technology stack and moving away from legacy services, so this is a fantastic opportunity to help shape our digital services and the way we work for a sustainable, user-centric future. We would love for you to be part of that team. Digital services is part of Change and Technology Services (CTS), who support and improve applications and systems across the Agency's IT landscape. CTS provide key services including digital services, cyber security and information governance, service architecture and governance and digital programme delivery. DevSecOps look after the deployment and infrastructure of the applications and products we deliver. They keep the lights on and are first to identify and resolve any issues with the live services. They work closely with developers and QAT to ensure the products meet the demands of the users, whilst also ensuring it meets cyber-security demands. As a lead DevSecOps engineer you will lead the DevSecOps team and contribute to the development of the strategic direction of Digital Services. At this role level, you will: Act as a subject matter expert for all DevSecOps responsibilities Provide technical leadership and guidance through coaching and mentoring Work with the Principal Technical Architect to develop technical strategy, define standards and help shape Digital Services knowledge and good practice Responsibilities As a Lead DevSecOps Engineer you will be responsible for: Keeping the applications running in production and non-production environments Ensuring that applications are deployed in a timely and secure manner Defining standards for the successful operation of a DevSecOps function within the Insolvency Service Contributing to priority incident bridge calls and root cause analysis Providing estimates to upcoming DevSecOps activities that are related to the delivery roadmap Working with and providing support to development and operations teams Updating and building deployment pipelines in line with the build and deployment model Raising changes to go through and attending CAB to represent those changes Contributing to the overall improvement of the application technology stack Ensuring that documentation conforms to documentation standards and is up-to-date and reflective of any changes Person specification To be successful in this role you will have: An inquisitive mind, and be able to constructively challenge at all levels to achieve the right results The ability to keep your own and the team's efforts focused on Digital Services goals to help the delivery of our roadmap and value to the business A keen eye for detail and a tenacious approach to work The ability to ask difficult and unpopular questions and make decisions that are evidence based and for the benefit of Digital Services and the wider Insolvency Service Strong analytical and problem-solving skills to be able to identify patterns, draw conclusions and resolve repeatable incidents The ability to build and establish relationships with key stakeholders to support the delivery of business outcomes in a secure and stable manner Good interpersonal and communication skills, both written and verbal
Infrastructure Engineer (DV Security Clearance) Position Description Secure Innovation is part of CGI's Space, Defence and Intelligence business unit, focused primarily on the delivery of contemporary and innovative technical solutions for the our client's most challenging problems. Our teams work alongside our clients to help them understand how to exploit technologies to maintain competitive advantage. We require a Infrastructure Engineer / Architect to work as part of the Consulting Unit, on a diverse set of projects delivering on prem, cloud and niche solutions. Your future duties and responsibilities They will be working on a highly secure hyprid on-prem / cloud projects. The role is on an established fast-moving DevSecOps team, on on-prem, remote and multi-cloud infrastructure, using a multitude of technologies including CloudFormation, Ansible and Terraform, Ubuntu and Windows, VPNs, firewalls, VMs, laptops, MFA, AD, monitoring, network performance, resilience and security design, plus some integration scripting and application configuration and management. We are heavily committed to developing our staff and will provide excellent learning and development opportunities to ensure that your knowledge and skills keep pace with the evolving technology landscape. We engender a culture of innovation, collaboration and ownership; highly motivated self-starters thrive within our organisation. Although we would like candidates to have all of the mandatory requirements, we would consider high quality individuals who meet most of the criteria. Required qualifications to be successful in this role • Ideally 3 years of experience of Infrastructure engineering - design, build, deploy, test and support • Deployment across on prem and cloud infra • Kubernetes, Containerisation, Platform Engineering • Kubernetes architecture - pods, services, deployments and networking, software defined networking • Scripting, e.g. Python/Shell • Experience of Docker, including image creation, container management (including security patching) and orchestration • Infrastructure as Code using Terraform, Ansible or CloudFormation • Experience of cloud compute - AWS, GCP or Azure (primarily AWS) • GitOps tooling such as Argo CD • Infra security, compliance and governance • Familiarity with CNCF ecosystem and building platforms on top of Kubernetes • Container orchestration tools, e.g. Docker Swarm / Apache Mesos • Knowledge of Service Mesh technologies, e.g. Istio / Linkerd • Experience of monitoring tools, e.g. Prometheus, Grafana, ELK • Rounded problem-solving skills - troubleshoot and resolve complex infrastructure related issues • Strong communication and collaboration skills • Ability to work across a diverse set of stakeholders, across multiple sites • Experience with agile development methodologies and tooling such as Git Together, as owners, let's turn meaningful insights into action. Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you'll reach your full potential because You are invited to be an owner from day 1 as we work together to bring our Dream to life. That's why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company's strategy and direction. Your work creates value. You'll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise. You'll shape your career by joining a company built to grow and last. You'll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons. Come join our team-one of the largest IT and business consulting services firms in the world.
20/11/2025
Full time
Infrastructure Engineer (DV Security Clearance) Position Description Secure Innovation is part of CGI's Space, Defence and Intelligence business unit, focused primarily on the delivery of contemporary and innovative technical solutions for the our client's most challenging problems. Our teams work alongside our clients to help them understand how to exploit technologies to maintain competitive advantage. We require a Infrastructure Engineer / Architect to work as part of the Consulting Unit, on a diverse set of projects delivering on prem, cloud and niche solutions. Your future duties and responsibilities They will be working on a highly secure hyprid on-prem / cloud projects. The role is on an established fast-moving DevSecOps team, on on-prem, remote and multi-cloud infrastructure, using a multitude of technologies including CloudFormation, Ansible and Terraform, Ubuntu and Windows, VPNs, firewalls, VMs, laptops, MFA, AD, monitoring, network performance, resilience and security design, plus some integration scripting and application configuration and management. We are heavily committed to developing our staff and will provide excellent learning and development opportunities to ensure that your knowledge and skills keep pace with the evolving technology landscape. We engender a culture of innovation, collaboration and ownership; highly motivated self-starters thrive within our organisation. Although we would like candidates to have all of the mandatory requirements, we would consider high quality individuals who meet most of the criteria. Required qualifications to be successful in this role • Ideally 3 years of experience of Infrastructure engineering - design, build, deploy, test and support • Deployment across on prem and cloud infra • Kubernetes, Containerisation, Platform Engineering • Kubernetes architecture - pods, services, deployments and networking, software defined networking • Scripting, e.g. Python/Shell • Experience of Docker, including image creation, container management (including security patching) and orchestration • Infrastructure as Code using Terraform, Ansible or CloudFormation • Experience of cloud compute - AWS, GCP or Azure (primarily AWS) • GitOps tooling such as Argo CD • Infra security, compliance and governance • Familiarity with CNCF ecosystem and building platforms on top of Kubernetes • Container orchestration tools, e.g. Docker Swarm / Apache Mesos • Knowledge of Service Mesh technologies, e.g. Istio / Linkerd • Experience of monitoring tools, e.g. Prometheus, Grafana, ELK • Rounded problem-solving skills - troubleshoot and resolve complex infrastructure related issues • Strong communication and collaboration skills • Ability to work across a diverse set of stakeholders, across multiple sites • Experience with agile development methodologies and tooling such as Git Together, as owners, let's turn meaningful insights into action. Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you'll reach your full potential because You are invited to be an owner from day 1 as we work together to bring our Dream to life. That's why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company's strategy and direction. Your work creates value. You'll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise. You'll shape your career by joining a company built to grow and last. You'll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons. Come join our team-one of the largest IT and business consulting services firms in the world.
Cloud Security Architects Position Description At CGI, we empower our clients to secure the future of their digital enterprises and we're trusted to do so at scale. As a Cloud Security Architect, you'll play a pivotal role in designing and delivering robust AWS cloud environments that safeguard critical data and services across industries. You'll help shape innovative security strategies, enhance cloud resilience, and drive transformation across hybrid architectures. In this role, you'll be part of a collaborative global community where your expertise is valued, your ideas are encouraged, and your impact is measurable enabling you to build a career that's both secure and rewarding. CGI was recognised in the Sunday Times Best Places to Work List 2025 and has been named a UK 'Best Employer' by the Financial Times. We offer a competitive salary, excellent pension, private healthcare, plus a share scheme (3.5% + 3.5% matching) which makes you a CGI Partner not just an employee. We are committed to inclusivity, building a genuinely diverse community of tech talent and inspiring everyone to pursue careers in our sector, including our Armed Forces, and are proud to hold a Gold Award in recognition of our support of the Armed Forces Corporate Covenant. Join us and you'll be part of an open, friendly community of experts. We'll train and support you in taking your career wherever you want it to go. Due to the secure nature of the programme, you will need to hold UK Security Clearance or be eligible to go through this clearance. This is a hybrid position. Your future duties and responsibilities In this role, you will design and implement secure cloud architectures that protect mission-critical systems and data. You'll collaborate with clients and technical teams to shape security frameworks, embed governance, and deliver secure-by-design solutions that align with business and regulatory requirements. Working within CGI's large and trusted cyber community, you'll take ownership of complex challenges, innovate with new technologies, and be supported by peers who share your drive for excellence. Your day-to-day responsibilities will include: Shape & Lead: Design secure architectures across enterprise and hybrid environments. Advise & Influence: Define and embed cloud security principles aligned with best practices and compliance standards. Develop & Deliver: Collaborate on cloud migration and transformation projects, ensuring security remains at the core. Automate & Optimise: Integrate security controls through DevSecOps practices and infrastructure automation. Guide & Mentor: Support delivery teams and junior specialists in developing CGI's cloud security capabilities. Innovate & Evolve: Contribute to continuous improvement of CGI's cloud security frameworks and client offerings. Required qualifications to be successful in this role You should bring strong technical expertise in cloud security, coupled with the communication and collaboration skills to influence across teams and client environments. Whether you're a hands-on specialist or a strategic design authority, your experience will help strengthen CGI's trusted reputation for cloud security excellence. Essential qualifications and experience include: Proven experience architecting secure cloud environments (multi-account, landing zones, SCPs, GuardDuty, CloudTrail, IAM). Familiarity with cloud security frameworks (NIST, ISO 27017/27018, MoD/HMG standards). Experience with container and serverless security (EKS, ECS, Lambda). Knowledge of SIEM, logging, and monitoring using AWS-native or integrated tools. Proficiency in secure CI/CD and DevSecOps practices (IaC, security scanning pipelines). Understanding of cloud governance, compliance, and risk management in regulated sectors. AWS Certified Security - Specialty (or equivalent) is highly advantageous. Together, as owners, let's turn meaningful insights into action. Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you'll reach your full potential because You are invited to be an owner from day 1 as we work together to bring our Dream to life. That's why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company's strategy and direction. Your work creates value. You'll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise. You'll shape your career by joining a company built to grow and last. You'll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons. Come join our team-one of the largest IT and business consulting services firms in the world.
20/11/2025
Full time
Cloud Security Architects Position Description At CGI, we empower our clients to secure the future of their digital enterprises and we're trusted to do so at scale. As a Cloud Security Architect, you'll play a pivotal role in designing and delivering robust AWS cloud environments that safeguard critical data and services across industries. You'll help shape innovative security strategies, enhance cloud resilience, and drive transformation across hybrid architectures. In this role, you'll be part of a collaborative global community where your expertise is valued, your ideas are encouraged, and your impact is measurable enabling you to build a career that's both secure and rewarding. CGI was recognised in the Sunday Times Best Places to Work List 2025 and has been named a UK 'Best Employer' by the Financial Times. We offer a competitive salary, excellent pension, private healthcare, plus a share scheme (3.5% + 3.5% matching) which makes you a CGI Partner not just an employee. We are committed to inclusivity, building a genuinely diverse community of tech talent and inspiring everyone to pursue careers in our sector, including our Armed Forces, and are proud to hold a Gold Award in recognition of our support of the Armed Forces Corporate Covenant. Join us and you'll be part of an open, friendly community of experts. We'll train and support you in taking your career wherever you want it to go. Due to the secure nature of the programme, you will need to hold UK Security Clearance or be eligible to go through this clearance. This is a hybrid position. Your future duties and responsibilities In this role, you will design and implement secure cloud architectures that protect mission-critical systems and data. You'll collaborate with clients and technical teams to shape security frameworks, embed governance, and deliver secure-by-design solutions that align with business and regulatory requirements. Working within CGI's large and trusted cyber community, you'll take ownership of complex challenges, innovate with new technologies, and be supported by peers who share your drive for excellence. Your day-to-day responsibilities will include: Shape & Lead: Design secure architectures across enterprise and hybrid environments. Advise & Influence: Define and embed cloud security principles aligned with best practices and compliance standards. Develop & Deliver: Collaborate on cloud migration and transformation projects, ensuring security remains at the core. Automate & Optimise: Integrate security controls through DevSecOps practices and infrastructure automation. Guide & Mentor: Support delivery teams and junior specialists in developing CGI's cloud security capabilities. Innovate & Evolve: Contribute to continuous improvement of CGI's cloud security frameworks and client offerings. Required qualifications to be successful in this role You should bring strong technical expertise in cloud security, coupled with the communication and collaboration skills to influence across teams and client environments. Whether you're a hands-on specialist or a strategic design authority, your experience will help strengthen CGI's trusted reputation for cloud security excellence. Essential qualifications and experience include: Proven experience architecting secure cloud environments (multi-account, landing zones, SCPs, GuardDuty, CloudTrail, IAM). Familiarity with cloud security frameworks (NIST, ISO 27017/27018, MoD/HMG standards). Experience with container and serverless security (EKS, ECS, Lambda). Knowledge of SIEM, logging, and monitoring using AWS-native or integrated tools. Proficiency in secure CI/CD and DevSecOps practices (IaC, security scanning pipelines). Understanding of cloud governance, compliance, and risk management in regulated sectors. AWS Certified Security - Specialty (or equivalent) is highly advantageous. Together, as owners, let's turn meaningful insights into action. Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you'll reach your full potential because You are invited to be an owner from day 1 as we work together to bring our Dream to life. That's why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company's strategy and direction. Your work creates value. You'll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise. You'll shape your career by joining a company built to grow and last. You'll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons. Come join our team-one of the largest IT and business consulting services firms in the world.
Location Croydon CR0 2WF, Manchester M5 3LZ, Sheffield S3 8NU (All QAT roles require flexibility of location, including working from supplier sites and other business locations across the UK and occasionally abroad). About the job Job summary The Home Office Quality Assurance and Testing Team (QAT) is seeking individuals passionate about quality and engineering excellence to join their well-established, award-winning team. QAT delivers a large-scale shared service through 750 QA professionals, supporting essential UK services and fostering a strong culture of continuous improvement, particularly in DevOps and cloud environments. Recently recognised as Testing Team of the Year at the 2024 European Software Testing Awards and re-certified at TMMi level 5 with a global best score, the team prides itself on industry-leading quality standards. The Core Cloud team, a key part of Test Engineering, is building a new strategic hosting platform using Amazon Web Services, focusing on a product-centric approach and enhancing the developer experience at the Home Office. This Lead Test Engineer role is central to the Core Cloud platform, contributing to advancements in quality assurance and testing within a dynamic, collaborative, and innovative environment. Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of 60% of their working time in the office. Applicants can raise any queries to the email address at the bottom of the advert. Watch this video to hear from members of the team talking about the projects they work on and their experience of working here. Job description This role will particularly excite you if you are a quality engineering expert with a keen interest and experience in platform engineering, or equally if you are an experienced platform engineer with a keen interest in quality approaches in the field. You will deliver modern, effective test engineering and assurance, whilst maturing the quality of our cloud platform engineering practice. You will be responsible for solving interesting engineering challenges, including building, adopting, and improving automated test frameworks to deliver effective feedback at scale and pace for complex platform capabilities covering both functional and non-functional aspects. It is essential to ensure these are aligned to the overall platform-level test approaches and QAT principles. Collaboration is key in this role. You will work with engineering and delivery teams to make sure QAT is embedded by default into the development approach. Building healthy relationships with your team, the wider team, other Home Office Digital professions, and communicating effectively with senior business stakeholders will be crucial. To help the QAT practice thrive, you will also keep up to date with emerging tools and innovative quality approaches, applying them to improve engineering practice within the QAT Test Engineering community and the wider organisation, promoting quality outcomes and value. QAT/Engineering Tools and Technologies we use: We have a wide portfolio of tools across the programme including: Cloud: AWS (primary) and Azure Test Frameworks: Terrattest, Pytest, Serenity BDD (Selenium + RestAssured), Playwright, and several bespoke frameworks. DevOps: AWS LZA, GitHub and GitHub Actions, Jenkins, Docker, Kubernetes, Terraform Performance testing - Locust, JMeter Other tools - AWS FIS, Checkov, ZAP, SonarQube Observability and Monitoring - ELK, Grafana, Prometheus, Dynatrace. What you will do Your main day to day responsibilities will be: Setting the direction for QAT Strategy and Test Engineering within the AWS-focused strategic cloud platform. Developing and implementing innovative tooling and DevSecOps best practices. Guiding, mentoring, and supporting engineers at all levels, including junior QAT engineers. Providing technical advice to improve engineering processes and practices. Embedding Infrastructure as Code test frameworks and implementing a modern test pyramid aligned with CI/CD pipelines. Building scalable, efficient, and cost-effective quality engineering solutions, while measuring code quality and using risk-based decision-making to help the QAT practice thrive through innovation. Person specification Essential Criteria As a Lead Test Engineer, you will have experience of: Collaborating with a wide variety of stakeholders to implement effective quality measures and mechanisms. Strong technical automation skills with the ability to write well-structured reusable maintainable tests and test utilities (Java, Python, TS/JS preferred). Leading a technical team of test engineers, this includes experience with DevSecOps, Cloud Platforms, Containers, Networking, Infrastructure as Code (IaC), SCM e.g. GitHub / Bitbucket. Design and deliver platform test approaches involving test automation environments, utilising virtualisation and containerisation. Experienced with DevSecOps environment including IaC testing, Unit testing, Contract testing, API testing, E2E testing, Resilience testing. Develop and enhance platform test engineering tools to support QA, Testing and Software Development in complex environments, with experience in AWS, Linux, AWS SDK, Pytest and TerraTest, CI/CD tools. eg. Jenkins/ GitHub Actions/ArgoCD.
20/11/2025
Full time
Location Croydon CR0 2WF, Manchester M5 3LZ, Sheffield S3 8NU (All QAT roles require flexibility of location, including working from supplier sites and other business locations across the UK and occasionally abroad). About the job Job summary The Home Office Quality Assurance and Testing Team (QAT) is seeking individuals passionate about quality and engineering excellence to join their well-established, award-winning team. QAT delivers a large-scale shared service through 750 QA professionals, supporting essential UK services and fostering a strong culture of continuous improvement, particularly in DevOps and cloud environments. Recently recognised as Testing Team of the Year at the 2024 European Software Testing Awards and re-certified at TMMi level 5 with a global best score, the team prides itself on industry-leading quality standards. The Core Cloud team, a key part of Test Engineering, is building a new strategic hosting platform using Amazon Web Services, focusing on a product-centric approach and enhancing the developer experience at the Home Office. This Lead Test Engineer role is central to the Core Cloud platform, contributing to advancements in quality assurance and testing within a dynamic, collaborative, and innovative environment. Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of 60% of their working time in the office. Applicants can raise any queries to the email address at the bottom of the advert. Watch this video to hear from members of the team talking about the projects they work on and their experience of working here. Job description This role will particularly excite you if you are a quality engineering expert with a keen interest and experience in platform engineering, or equally if you are an experienced platform engineer with a keen interest in quality approaches in the field. You will deliver modern, effective test engineering and assurance, whilst maturing the quality of our cloud platform engineering practice. You will be responsible for solving interesting engineering challenges, including building, adopting, and improving automated test frameworks to deliver effective feedback at scale and pace for complex platform capabilities covering both functional and non-functional aspects. It is essential to ensure these are aligned to the overall platform-level test approaches and QAT principles. Collaboration is key in this role. You will work with engineering and delivery teams to make sure QAT is embedded by default into the development approach. Building healthy relationships with your team, the wider team, other Home Office Digital professions, and communicating effectively with senior business stakeholders will be crucial. To help the QAT practice thrive, you will also keep up to date with emerging tools and innovative quality approaches, applying them to improve engineering practice within the QAT Test Engineering community and the wider organisation, promoting quality outcomes and value. QAT/Engineering Tools and Technologies we use: We have a wide portfolio of tools across the programme including: Cloud: AWS (primary) and Azure Test Frameworks: Terrattest, Pytest, Serenity BDD (Selenium + RestAssured), Playwright, and several bespoke frameworks. DevOps: AWS LZA, GitHub and GitHub Actions, Jenkins, Docker, Kubernetes, Terraform Performance testing - Locust, JMeter Other tools - AWS FIS, Checkov, ZAP, SonarQube Observability and Monitoring - ELK, Grafana, Prometheus, Dynatrace. What you will do Your main day to day responsibilities will be: Setting the direction for QAT Strategy and Test Engineering within the AWS-focused strategic cloud platform. Developing and implementing innovative tooling and DevSecOps best practices. Guiding, mentoring, and supporting engineers at all levels, including junior QAT engineers. Providing technical advice to improve engineering processes and practices. Embedding Infrastructure as Code test frameworks and implementing a modern test pyramid aligned with CI/CD pipelines. Building scalable, efficient, and cost-effective quality engineering solutions, while measuring code quality and using risk-based decision-making to help the QAT practice thrive through innovation. Person specification Essential Criteria As a Lead Test Engineer, you will have experience of: Collaborating with a wide variety of stakeholders to implement effective quality measures and mechanisms. Strong technical automation skills with the ability to write well-structured reusable maintainable tests and test utilities (Java, Python, TS/JS preferred). Leading a technical team of test engineers, this includes experience with DevSecOps, Cloud Platforms, Containers, Networking, Infrastructure as Code (IaC), SCM e.g. GitHub / Bitbucket. Design and deliver platform test approaches involving test automation environments, utilising virtualisation and containerisation. Experienced with DevSecOps environment including IaC testing, Unit testing, Contract testing, API testing, E2E testing, Resilience testing. Develop and enhance platform test engineering tools to support QA, Testing and Software Development in complex environments, with experience in AWS, Linux, AWS SDK, Pytest and TerraTest, CI/CD tools. eg. Jenkins/ GitHub Actions/ArgoCD.
Senior DevOps Consultant (GitHub SME) Microsoft Gold Partner £70 75K - (RL8011) Job Title: Senior DevOps Consultant (GitHub SME) Reference: RL8011 Location: UK Salary: £70,000 £75,000 per annum Benefits: Flexible hybrid working, professional development support, well-being initiatives Start: ASAP The Client: A Microsoft Gold Partner and leading Digital Consultancy, helping organisations embrace Cloud transformation and unlock the potential of Digital, Data, and AI solutions. Their projects span multiple industries including Financial Services, Insurance, Public Services, Media & Telecommunications, Manufacturing, Health, Pharmaceuticals, Business Services, Ecology, and Logistics. They foster a collaborative, people-first culture where innovation, flexibility, and growth are actively encouraged, and they re trusted by some of the worlds most forward-thinking businesses to deliver outstanding results. The Candidate: you'll be an experienced DevOps professional with deep expertise in GitHub Enterprise administration, comfortable advising on governance, security, and best practice across large-scale environments. you'll thrive in collaborative settings, be confident assessing technical landscapes, and have the ability to recommend and implement effective improvements. The Role: As a Senior DevOps Consultant (GitHub SME), you'll take ownership of GitHub Enterprise governance and security, ensuring that development teams across the organisation follow best practices. you'll design and implement scalable structures, optimise automation workflows, and help shape secure and efficient CI/CD processes. This is a strategic, hands-on role suited to someone who enjoys working across teams to improve the way engineering is delivered at scale. Responsibilities: Administer GitHub Enterprise across large and complex organisational environments. Define and implement repository governance, access control, and change management processes. Enable and manage GitHub Advanced Security (GHAS) features including code scanning, secret scanning, and dependency management. Integrate GitHub with enterprise identity systems such as Azure AD/Entra ID for secure SSO. Support and optimise CI/CD pipelines and automation workflows (GitHub Actions). Assess current environments, identify gaps, and propose effective, scalable improvements. Essential Requirements: Proven experience managing GitHub Enterprise in enterprise-scale or multi-team environments. Strong understanding of governance, security, and repository structure best practices. Practical experience with GHAS, SSO integration, and DevOps automation (CI/CD). Strong analytical, problem-solving, and stakeholder communication skills. Desirable (Not Essential): Experience migrating from Bitbucket, GitLab, or SVN. Familiarity with Atlassian tools (Jira, Confluence). Broader knowledge of DevSecOps or cloud environments (Azure, AWS, or GCP). To apply for this Senior DevOps Consultant permanent job, please click the button below and submit your latest CV. Curo Services endeavours to respond to all applications, however this may not always be possible during periods of high volume. Thank you for your patience. Curo Services is a trading name of Curo Resourcing Ltd and acts as an Employment Business for contract and temporary recruitment as well as an Employment Agency in relation to permanent vacancies.
20/11/2025
Full time
Senior DevOps Consultant (GitHub SME) Microsoft Gold Partner £70 75K - (RL8011) Job Title: Senior DevOps Consultant (GitHub SME) Reference: RL8011 Location: UK Salary: £70,000 £75,000 per annum Benefits: Flexible hybrid working, professional development support, well-being initiatives Start: ASAP The Client: A Microsoft Gold Partner and leading Digital Consultancy, helping organisations embrace Cloud transformation and unlock the potential of Digital, Data, and AI solutions. Their projects span multiple industries including Financial Services, Insurance, Public Services, Media & Telecommunications, Manufacturing, Health, Pharmaceuticals, Business Services, Ecology, and Logistics. They foster a collaborative, people-first culture where innovation, flexibility, and growth are actively encouraged, and they re trusted by some of the worlds most forward-thinking businesses to deliver outstanding results. The Candidate: you'll be an experienced DevOps professional with deep expertise in GitHub Enterprise administration, comfortable advising on governance, security, and best practice across large-scale environments. you'll thrive in collaborative settings, be confident assessing technical landscapes, and have the ability to recommend and implement effective improvements. The Role: As a Senior DevOps Consultant (GitHub SME), you'll take ownership of GitHub Enterprise governance and security, ensuring that development teams across the organisation follow best practices. you'll design and implement scalable structures, optimise automation workflows, and help shape secure and efficient CI/CD processes. This is a strategic, hands-on role suited to someone who enjoys working across teams to improve the way engineering is delivered at scale. Responsibilities: Administer GitHub Enterprise across large and complex organisational environments. Define and implement repository governance, access control, and change management processes. Enable and manage GitHub Advanced Security (GHAS) features including code scanning, secret scanning, and dependency management. Integrate GitHub with enterprise identity systems such as Azure AD/Entra ID for secure SSO. Support and optimise CI/CD pipelines and automation workflows (GitHub Actions). Assess current environments, identify gaps, and propose effective, scalable improvements. Essential Requirements: Proven experience managing GitHub Enterprise in enterprise-scale or multi-team environments. Strong understanding of governance, security, and repository structure best practices. Practical experience with GHAS, SSO integration, and DevOps automation (CI/CD). Strong analytical, problem-solving, and stakeholder communication skills. Desirable (Not Essential): Experience migrating from Bitbucket, GitLab, or SVN. Familiarity with Atlassian tools (Jira, Confluence). Broader knowledge of DevSecOps or cloud environments (Azure, AWS, or GCP). To apply for this Senior DevOps Consultant permanent job, please click the button below and submit your latest CV. Curo Services endeavours to respond to all applications, however this may not always be possible during periods of high volume. Thank you for your patience. Curo Services is a trading name of Curo Resourcing Ltd and acts as an Employment Business for contract and temporary recruitment as well as an Employment Agency in relation to permanent vacancies.
Cloud Consulting have an urgent requirement for an experienced Software Factory Administrator to work on a high-profile project for a leading government agency. The role is a hybrid one - 2 days p/week on-site in Bristol and 3 days remote, and is Outside of IR35. We are seeking a Software Factory Administrator to support the creation, maturation, and operation of the Defence Digital Software Factory - a secure, scalable, and collaborative platform enabling continuous integration, testing, and deployment of digital capabilities. This role combines hands-on system administration, automation, and technical governance with coordination and oversight of innovation workstreams. The successful candidate will ensure the Software Factory and its toolchain (including GitLab and associated DevSecOps platforms) operate efficiently, securely, and in alignment with Defence standards and mission outcomes. Scope of role: Software Factory Development and Administration: Lead the creation and maturation of the Software Factory and its supporting toolchain, including GitLab and associated CI/CD environments. Undertake associated management activities, including user training, administration, onboarding, and ongoing operational support. Manage and maintain Software Factory environments, ensuring security, performance, and availability across multiple projects. Oversee configuration, access control, and repository management across GitLab, Nexus, Jenkins, or similar systems. Monitor systems, manage infrastructure, automate routine tasks, and collaborate with software teams to ensure the smooth operation of software development and deployment pipelines. Maintain integration with monitoring and logging tools (eg Prometheus, Grafana, ELK stack) and ensure end-to-end visibility of software pipelines. Administer and monitor containerised environments using Kubernetes (eg Red Hat OpenShift). Innovation and Continuous Development: Lead and manage innovation work packages within the Software Factory, outside of the prototype bridging contract, supporting exploration of emerging technologies and approaches. Support the identification and evaluation of innovative tools, automation methods, and frameworks that enhance efficiency and capability delivery. Contribute to the creation of a Software Factory roadmap Promote best practice and continuous improvement across software engineering and DevSecOps disciplines. Technical Support and Assurance: Act as the primary point of contact for Software Factory-related technical and access issues. Support development teams with environment setup, build and deployment troubleshooting, and configuration guidance. Maintain up-to-date documentation of configuration, system changes, and operational processes for governance and audit. Ensure alignment engineering, security, and accreditation standards. Governance and Compliance: Maintain governance documentation, access logs, and audit trails in line with programme standards. Ensure adherence to accreditation, and data management requirements. Implement configuration management, patching, and vulnerability remediation processes for all factory systems. Support compliance activities associated with DevSecOps and secure software delivery principles. Collaboration and Stakeholder Engagement: Work collaboratively with software developers, project managers, architects, cyber security specialists, and wider stakeholder. Provide technical advice and administrative guidance to ensure efficient and compliant use of the Software Factory. If you are interested, then please forward a copy of your C.V in the first instance.
19/11/2025
Contractor
Cloud Consulting have an urgent requirement for an experienced Software Factory Administrator to work on a high-profile project for a leading government agency. The role is a hybrid one - 2 days p/week on-site in Bristol and 3 days remote, and is Outside of IR35. We are seeking a Software Factory Administrator to support the creation, maturation, and operation of the Defence Digital Software Factory - a secure, scalable, and collaborative platform enabling continuous integration, testing, and deployment of digital capabilities. This role combines hands-on system administration, automation, and technical governance with coordination and oversight of innovation workstreams. The successful candidate will ensure the Software Factory and its toolchain (including GitLab and associated DevSecOps platforms) operate efficiently, securely, and in alignment with Defence standards and mission outcomes. Scope of role: Software Factory Development and Administration: Lead the creation and maturation of the Software Factory and its supporting toolchain, including GitLab and associated CI/CD environments. Undertake associated management activities, including user training, administration, onboarding, and ongoing operational support. Manage and maintain Software Factory environments, ensuring security, performance, and availability across multiple projects. Oversee configuration, access control, and repository management across GitLab, Nexus, Jenkins, or similar systems. Monitor systems, manage infrastructure, automate routine tasks, and collaborate with software teams to ensure the smooth operation of software development and deployment pipelines. Maintain integration with monitoring and logging tools (eg Prometheus, Grafana, ELK stack) and ensure end-to-end visibility of software pipelines. Administer and monitor containerised environments using Kubernetes (eg Red Hat OpenShift). Innovation and Continuous Development: Lead and manage innovation work packages within the Software Factory, outside of the prototype bridging contract, supporting exploration of emerging technologies and approaches. Support the identification and evaluation of innovative tools, automation methods, and frameworks that enhance efficiency and capability delivery. Contribute to the creation of a Software Factory roadmap Promote best practice and continuous improvement across software engineering and DevSecOps disciplines. Technical Support and Assurance: Act as the primary point of contact for Software Factory-related technical and access issues. Support development teams with environment setup, build and deployment troubleshooting, and configuration guidance. Maintain up-to-date documentation of configuration, system changes, and operational processes for governance and audit. Ensure alignment engineering, security, and accreditation standards. Governance and Compliance: Maintain governance documentation, access logs, and audit trails in line with programme standards. Ensure adherence to accreditation, and data management requirements. Implement configuration management, patching, and vulnerability remediation processes for all factory systems. Support compliance activities associated with DevSecOps and secure software delivery principles. Collaboration and Stakeholder Engagement: Work collaboratively with software developers, project managers, architects, cyber security specialists, and wider stakeholder. Provide technical advice and administrative guidance to ensure efficient and compliant use of the Software Factory. If you are interested, then please forward a copy of your C.V in the first instance.
Principal Security Engineer The Role: Synoptix are expanding their Cyber Security capability by applying it to Systems Thinking, allowing for delivery of Cyber Security Solutions to both defence and commercial clients. We re looking for a technically strong, client-focused Principal Security Engineer to support the development, implementation, and assurance of secure system architectures and solutions. This role sits within our Secure by Design capability and supports both internal development projects and external client engagements. Working alongside the existing team, contributing to security requirements definition, risk assessments, technical security design, and security documentation for both internal platforms and client systems. Dynamic Working: A blend of home and office-based working is encouraged Key Responsibilities: Lead and Deliver Cyber Security work packages to clients, this includes applying Systems Engineering methodologies into Cyber solutions. Risk identification and management Requirements Capture Validation Verification Be responsible for the technical content of client deliverables, for example. Security Management Plans Security Case Report following Secure by Design through life principals Verification Plans Validation Test Schedules and Reporting Penetration Test Remedial Action Plans Managing Risk Appetite and Risk Analysis Assessments Support the Sales and Business Development team in winning work through the generation of proposals and support to client meetings. Represent Synoptix at conferences, symposia, and trade shows. Lead Cyber security related research programmes with Academia. Represent the client and Synoptix at both internal and external customer facing security working groups. Delivering Key Management in accordance with agreed management plans. Assist in the further development of the Synoptix Cyber security capability. Skills Required: Essential: Knowledge of Secure by Design principles Experience in system security engineering, ideally in defence, space, or critical infrastructure Familiarity with MOD, NCSC, and ISO standards (e.g. ISO 27001/2, NIST 800-series, JSP 604) Competence in requirements engineering and systems thinking Practical experience with security in software and/or system development environments Effective communication and report-writing skills Ability to work independently as well as collaboratively within multidisciplinary teams Desirable: CISSP, CISM, or relevant NCSC-certified qualifications Experience with model-based systems engineering (MBSE) Experience supporting formal security assurance processes Understanding of space system architectures or satellite communications DevSecOps awareness or experience with security automation Benefits: Annual Company Bonus 25 Days holiday not including bank holidays with the option to buy/sell up to 5 days Competitive pension contribution Continuous professional development including incentives Access to online Udemy training facility Flexible working arrangements Bike to work scheme Electric car scheme Private health care Job well done scheme Please note that due to the nature of our projects we can only accept Sole UK National candidates who will need to be eligible to obtain UK Security Clearance. By applying for this position, you are confirming that you consent to the retention of your personal data. Your data is held securely on our own premises and under the terms of the Data Protection Act (2018). It will be treated as confidential, and will not be transferred to any third party, or to any other jurisdiction without your consent. We will not hold any data for any longer than is necessary for us to fulfil our obligations and will remove any data at your written request.
19/11/2025
Full time
Principal Security Engineer The Role: Synoptix are expanding their Cyber Security capability by applying it to Systems Thinking, allowing for delivery of Cyber Security Solutions to both defence and commercial clients. We re looking for a technically strong, client-focused Principal Security Engineer to support the development, implementation, and assurance of secure system architectures and solutions. This role sits within our Secure by Design capability and supports both internal development projects and external client engagements. Working alongside the existing team, contributing to security requirements definition, risk assessments, technical security design, and security documentation for both internal platforms and client systems. Dynamic Working: A blend of home and office-based working is encouraged Key Responsibilities: Lead and Deliver Cyber Security work packages to clients, this includes applying Systems Engineering methodologies into Cyber solutions. Risk identification and management Requirements Capture Validation Verification Be responsible for the technical content of client deliverables, for example. Security Management Plans Security Case Report following Secure by Design through life principals Verification Plans Validation Test Schedules and Reporting Penetration Test Remedial Action Plans Managing Risk Appetite and Risk Analysis Assessments Support the Sales and Business Development team in winning work through the generation of proposals and support to client meetings. Represent Synoptix at conferences, symposia, and trade shows. Lead Cyber security related research programmes with Academia. Represent the client and Synoptix at both internal and external customer facing security working groups. Delivering Key Management in accordance with agreed management plans. Assist in the further development of the Synoptix Cyber security capability. Skills Required: Essential: Knowledge of Secure by Design principles Experience in system security engineering, ideally in defence, space, or critical infrastructure Familiarity with MOD, NCSC, and ISO standards (e.g. ISO 27001/2, NIST 800-series, JSP 604) Competence in requirements engineering and systems thinking Practical experience with security in software and/or system development environments Effective communication and report-writing skills Ability to work independently as well as collaboratively within multidisciplinary teams Desirable: CISSP, CISM, or relevant NCSC-certified qualifications Experience with model-based systems engineering (MBSE) Experience supporting formal security assurance processes Understanding of space system architectures or satellite communications DevSecOps awareness or experience with security automation Benefits: Annual Company Bonus 25 Days holiday not including bank holidays with the option to buy/sell up to 5 days Competitive pension contribution Continuous professional development including incentives Access to online Udemy training facility Flexible working arrangements Bike to work scheme Electric car scheme Private health care Job well done scheme Please note that due to the nature of our projects we can only accept Sole UK National candidates who will need to be eligible to obtain UK Security Clearance. By applying for this position, you are confirming that you consent to the retention of your personal data. Your data is held securely on our own premises and under the terms of the Data Protection Act (2018). It will be treated as confidential, and will not be transferred to any third party, or to any other jurisdiction without your consent. We will not hold any data for any longer than is necessary for us to fulfil our obligations and will remove any data at your written request.
Summer-Browning Associates
City Of Westminster, London
Summer-Browning Associates are currently supporting a Central Government client, who have a requirement for a Google Cloud Architect on an initial 12 month contract. What You'll Be Doing Designing and delivering secure, scalable, and resilient architectures in Google Cloud Platform (GCP) and Google Distributed Cloud (GDC) environments. Working within disconnected environments on data-severing solutions. Collaborating closely with engineering, DevOps, and security teams to ensure seamless integration from design through delivery. Implementing automation and Infrastructure as Code (IaC) for repeatable, auditable deployments. Providing technical leadership and mentorship, helping teams adopt best practice across cloud engineering and DevSecOps. Aligning designs with government security frameworks and enterprise architecture principles. Supporting ongoing system optimisation and capability development over the lifespan of the programme. What You'll Bring Proven hands-on experience as a Cloud Architect or Senior Cloud Engineer specialising in Google Cloud Platform. Practical knowledge of Google Distributed Cloud (GDC), Experience working in environments without direct internet connectivity. Strong engineering background with deep understanding of IaC (Terraform, Deployment Manager), automation, and CI/CD pipelines. Expertise in networking, IAM, containerisation (GKE/Kubernetes), and secure systems design. Confident working within highly regulated or classified environments where reliability and compliance are paramount. Strong communicator - able to bridge technical and non-technical stakeholders effectively. Desirables Prior experience working on government classified systems or within secure data centre environments. Experience of configuring and using AI technologies within cloud environments, including GCP AI technologies. Familiarity with NCSC guidance, UK Government cloud policies, or cross-domain architectures. Knowledge of multi-cloud integrations, edge computing, and data sovereignty requirements. NB: The ideal applicant will hold a minimum of SC level vetting and be willing to undertake DV level vetting.
19/11/2025
Contractor
Summer-Browning Associates are currently supporting a Central Government client, who have a requirement for a Google Cloud Architect on an initial 12 month contract. What You'll Be Doing Designing and delivering secure, scalable, and resilient architectures in Google Cloud Platform (GCP) and Google Distributed Cloud (GDC) environments. Working within disconnected environments on data-severing solutions. Collaborating closely with engineering, DevOps, and security teams to ensure seamless integration from design through delivery. Implementing automation and Infrastructure as Code (IaC) for repeatable, auditable deployments. Providing technical leadership and mentorship, helping teams adopt best practice across cloud engineering and DevSecOps. Aligning designs with government security frameworks and enterprise architecture principles. Supporting ongoing system optimisation and capability development over the lifespan of the programme. What You'll Bring Proven hands-on experience as a Cloud Architect or Senior Cloud Engineer specialising in Google Cloud Platform. Practical knowledge of Google Distributed Cloud (GDC), Experience working in environments without direct internet connectivity. Strong engineering background with deep understanding of IaC (Terraform, Deployment Manager), automation, and CI/CD pipelines. Expertise in networking, IAM, containerisation (GKE/Kubernetes), and secure systems design. Confident working within highly regulated or classified environments where reliability and compliance are paramount. Strong communicator - able to bridge technical and non-technical stakeholders effectively. Desirables Prior experience working on government classified systems or within secure data centre environments. Experience of configuring and using AI technologies within cloud environments, including GCP AI technologies. Familiarity with NCSC guidance, UK Government cloud policies, or cross-domain architectures. Knowledge of multi-cloud integrations, edge computing, and data sovereignty requirements. NB: The ideal applicant will hold a minimum of SC level vetting and be willing to undertake DV level vetting.
We're Atom bank The bank that's leading the fintech charge! We're not like the rest. We're true innovators, and we're redefining what a bank should be. Ours is a bank for today and the future, a mobile-first bank. Forget the stuffy branches, with Atom you can bank whenever, wherever, faster, and simpler. Could you be the next innovator to join us? What will your 'typical' day look like? Different that's for sure : The Security Architect at Atom Bank is a critical leadership role responsible for driving the evolution of the bank's security architecture. This role acts as the primary security subject matter expert, partnering with technology and product teams to design, build, and govern highly secure, resilient, and compliant solutions that protect customers and accelerate Atom's safe adoption of new services and technologies. The ideal candidate is a proactive leader who embeds a culture of security by design across the estate, balancing speed and innovation with the stringent requirements of a financial services regulator. You will: Lead the design of solutions for new products and features, ensuring they are scalable, reliable, and secure. Develop and maintain aspirational architectural roadmaps and current/future state architectures that clearly link product strategy to Tech strategy. Actively cultivate relationships with product and delivery leadership and gain Value Stream commitment for initiatives. Foster a culture of continuous conversational governance by engaging in ongoing conversations with teams, coaching them, communicating strategy and standards, providing guidance on designs, and capturing architectural decisions. Contribute to the development of the Architecture capability and maintain knowledge of industry best practices and emerging technologies. Engage in the bank's governance and change frameworks. Identify and mitigate architectural risks to improve system resilience and reduce long-term technology debt. Inspire and motivate others to deliver excellent technical solutions and outcomes. What do we need from you? Proven design, implementation, or consulting experience within a security context. Security Domain Expertise: Proven practitioner experience in one or more of the following: Cloud Security Application Security Data Security Identity and Access Management (IAM) Network Security Modern Architecture: Understanding of securing modern architectural patterns such as microservices, event-driven architecture, and serverless computing. Experience with DevSecOps practices, including embedding security into CI/CD pipelines. Security Principles: Knowledge of security principles like Zero Trust, secure-by-design, and defence-in-depth. Problem Solving: Shows a systematic, disciplined, and analytical approach to problem-solving. Governance: Experience constructively navigating and contributing to technology governance processes. Understanding of architectural and security best practice, frameworks, and standards. Self-managing, proactive, and a strong communicator. Professional security certifications such as CISSP, CISM, or CCSP. Experience with cybersecurity frameworks, e.g., NIST and ISO/IEC 27001. Inspire and motivate others to deliver excellent technical solutions and outcomes. What you'll get from us? Flexible Hybrid 4-day work week Incredibly generous company pension scheme (maximum of 13% of Atom input - you can put in more) 'All About Me' fund: £200 per year to spend on personal development. 22.5 days annual leave plus public holidays Private Medical Insurance, Health Cash Plan & Life Insurance Enhanced Parental Leave Electric Vehicle Scheme PLEASE NOTE: You must have the legal right to work in the UK to apply for this role as Atom is unable to support Visa Applications/Sponsorship Atom is an equal opportunities employer. We value you as an individual and therefore disregard race, religion/belief, gender, sexual orientation, maternity/pregnancy, age, gender reassignment, marriage/civil partnership and disability in any hiring decisions we make. Atom will always adhere to the Equality Act 2010. All roles within Atom must adhere to the Conduct Rules as set out by the Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) As part of Atom bank's commitment to the FCA's Consumer Duty, Atom will, take all reasonable steps to avoid causing foreseeable harm to customers, take all reasonable steps to enable customers to pursue their financial objectives and act in good faith.
19/11/2025
Full time
We're Atom bank The bank that's leading the fintech charge! We're not like the rest. We're true innovators, and we're redefining what a bank should be. Ours is a bank for today and the future, a mobile-first bank. Forget the stuffy branches, with Atom you can bank whenever, wherever, faster, and simpler. Could you be the next innovator to join us? What will your 'typical' day look like? Different that's for sure : The Security Architect at Atom Bank is a critical leadership role responsible for driving the evolution of the bank's security architecture. This role acts as the primary security subject matter expert, partnering with technology and product teams to design, build, and govern highly secure, resilient, and compliant solutions that protect customers and accelerate Atom's safe adoption of new services and technologies. The ideal candidate is a proactive leader who embeds a culture of security by design across the estate, balancing speed and innovation with the stringent requirements of a financial services regulator. You will: Lead the design of solutions for new products and features, ensuring they are scalable, reliable, and secure. Develop and maintain aspirational architectural roadmaps and current/future state architectures that clearly link product strategy to Tech strategy. Actively cultivate relationships with product and delivery leadership and gain Value Stream commitment for initiatives. Foster a culture of continuous conversational governance by engaging in ongoing conversations with teams, coaching them, communicating strategy and standards, providing guidance on designs, and capturing architectural decisions. Contribute to the development of the Architecture capability and maintain knowledge of industry best practices and emerging technologies. Engage in the bank's governance and change frameworks. Identify and mitigate architectural risks to improve system resilience and reduce long-term technology debt. Inspire and motivate others to deliver excellent technical solutions and outcomes. What do we need from you? Proven design, implementation, or consulting experience within a security context. Security Domain Expertise: Proven practitioner experience in one or more of the following: Cloud Security Application Security Data Security Identity and Access Management (IAM) Network Security Modern Architecture: Understanding of securing modern architectural patterns such as microservices, event-driven architecture, and serverless computing. Experience with DevSecOps practices, including embedding security into CI/CD pipelines. Security Principles: Knowledge of security principles like Zero Trust, secure-by-design, and defence-in-depth. Problem Solving: Shows a systematic, disciplined, and analytical approach to problem-solving. Governance: Experience constructively navigating and contributing to technology governance processes. Understanding of architectural and security best practice, frameworks, and standards. Self-managing, proactive, and a strong communicator. Professional security certifications such as CISSP, CISM, or CCSP. Experience with cybersecurity frameworks, e.g., NIST and ISO/IEC 27001. Inspire and motivate others to deliver excellent technical solutions and outcomes. What you'll get from us? Flexible Hybrid 4-day work week Incredibly generous company pension scheme (maximum of 13% of Atom input - you can put in more) 'All About Me' fund: £200 per year to spend on personal development. 22.5 days annual leave plus public holidays Private Medical Insurance, Health Cash Plan & Life Insurance Enhanced Parental Leave Electric Vehicle Scheme PLEASE NOTE: You must have the legal right to work in the UK to apply for this role as Atom is unable to support Visa Applications/Sponsorship Atom is an equal opportunities employer. We value you as an individual and therefore disregard race, religion/belief, gender, sexual orientation, maternity/pregnancy, age, gender reassignment, marriage/civil partnership and disability in any hiring decisions we make. Atom will always adhere to the Equality Act 2010. All roles within Atom must adhere to the Conduct Rules as set out by the Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) As part of Atom bank's commitment to the FCA's Consumer Duty, Atom will, take all reasonable steps to avoid causing foreseeable harm to customers, take all reasonable steps to enable customers to pursue their financial objectives and act in good faith.
Our hosting team delivers InterSystems' solutions as hosted or managed services, anywhere in the world. As more and more clients change to hosted solutions, we are looking for a new DevSecOps engineer. This is a hands-on role for someone who thrives in complex hosting environments. As a DevSecOps Engineer, you'll work across infrastructure and application layers to identify and remediate vulnerabilities, coordinate with engineering teams, and ensure our systems meet the highest standards of security and compliance. Experience in a hosting provider or managed service provider (MSP) is essential, as you'll be navigating multi-tenant architectures, uptime SLAs, and regulatory frameworks that demand precision and accountability. The role offers a fantastic opportunity to gain experience across a range of technologies, to solve interesting problems, to be allowed to make improvements, and to be recognized for making a difference. Benefits Include Lucrative Bonus Scheme Private Healthcare incl Dental Plan Enhanced Pension Wellbeing programmes Volunteering Days Perk & Saving Discounts Gym Reimbursements 25 days Annual Leave Free lunch and more! Responsibilities Lead departmental security compliance initiatives and external audits Identify, triage, and remediate vulnerabilities across infrastructure and applications Assess and contextualize vulnerabilities by evaluating exploit difficulty, existing controls, and potential impact Produce clear, actionable management-level reports that translate technical findings into business risk language Collaborate with external CREST-accredited assessors and deliver customer-facing vulnerability summaries Coordinate secure changes and maintenance windows with engineering teams Respond to security incidents and support root cause analysis and reporting Participate in the deployment of new applications and/or changes, ensuring that all service components are documented and monitored and integrated into the company's operational processes. Work with stakeholders across the solutions lifecycle to ensure that pre-operational sign-offs are obtained, so as to ensure that solutions can be operated in a way that meets or exceeds performance targets e.g. security, availability and response times. Assist with the troubleshooting of integration issues. Consulting with technical stakeholders (including customers) on the delivery of hosted solutions. Experience & Qualifications Good experience in a hosting provider or managed service provider environment Strong working knowledge of ISO 27001, ISO 27017, ISO 27018, and ISO 22301 Hands-on experience with scanning and vulnerability detection applications Hands-on experience of Real time threat detection software Ability to analyze and explain exploitability of vulnerabilities, including attack vectors, prerequisites, and mitigations Skilled in producing executive-level reporting that aligns technical risk with business impact Familiarity with healthcare data protection regulations and audit readiness Strong communication skills for cross-functional collaboration and customer engagement Strong experience in AD GPO development and maintenance, particularly around security Good experience of security in both Linux and Windows environments Experience of public and private cloud environments Hands-on Windows domain and AD management experience Strong troubleshooting skills Strong scripting skills Enthusiasm and talent for acquiring complex technical skills Good customer service attitude Knowledge of configuration management (Puppet and/or Red Hat Satellite preferred) Scripting for automation using technologies (e.g. Powershell, Puppet, Ansible, Python) ITIL knowledge - principles and application Ability to support and develop junior colleagues
18/11/2025
Full time
Our hosting team delivers InterSystems' solutions as hosted or managed services, anywhere in the world. As more and more clients change to hosted solutions, we are looking for a new DevSecOps engineer. This is a hands-on role for someone who thrives in complex hosting environments. As a DevSecOps Engineer, you'll work across infrastructure and application layers to identify and remediate vulnerabilities, coordinate with engineering teams, and ensure our systems meet the highest standards of security and compliance. Experience in a hosting provider or managed service provider (MSP) is essential, as you'll be navigating multi-tenant architectures, uptime SLAs, and regulatory frameworks that demand precision and accountability. The role offers a fantastic opportunity to gain experience across a range of technologies, to solve interesting problems, to be allowed to make improvements, and to be recognized for making a difference. Benefits Include Lucrative Bonus Scheme Private Healthcare incl Dental Plan Enhanced Pension Wellbeing programmes Volunteering Days Perk & Saving Discounts Gym Reimbursements 25 days Annual Leave Free lunch and more! Responsibilities Lead departmental security compliance initiatives and external audits Identify, triage, and remediate vulnerabilities across infrastructure and applications Assess and contextualize vulnerabilities by evaluating exploit difficulty, existing controls, and potential impact Produce clear, actionable management-level reports that translate technical findings into business risk language Collaborate with external CREST-accredited assessors and deliver customer-facing vulnerability summaries Coordinate secure changes and maintenance windows with engineering teams Respond to security incidents and support root cause analysis and reporting Participate in the deployment of new applications and/or changes, ensuring that all service components are documented and monitored and integrated into the company's operational processes. Work with stakeholders across the solutions lifecycle to ensure that pre-operational sign-offs are obtained, so as to ensure that solutions can be operated in a way that meets or exceeds performance targets e.g. security, availability and response times. Assist with the troubleshooting of integration issues. Consulting with technical stakeholders (including customers) on the delivery of hosted solutions. Experience & Qualifications Good experience in a hosting provider or managed service provider environment Strong working knowledge of ISO 27001, ISO 27017, ISO 27018, and ISO 22301 Hands-on experience with scanning and vulnerability detection applications Hands-on experience of Real time threat detection software Ability to analyze and explain exploitability of vulnerabilities, including attack vectors, prerequisites, and mitigations Skilled in producing executive-level reporting that aligns technical risk with business impact Familiarity with healthcare data protection regulations and audit readiness Strong communication skills for cross-functional collaboration and customer engagement Strong experience in AD GPO development and maintenance, particularly around security Good experience of security in both Linux and Windows environments Experience of public and private cloud environments Hands-on Windows domain and AD management experience Strong troubleshooting skills Strong scripting skills Enthusiasm and talent for acquiring complex technical skills Good customer service attitude Knowledge of configuration management (Puppet and/or Red Hat Satellite preferred) Scripting for automation using technologies (e.g. Powershell, Puppet, Ansible, Python) ITIL knowledge - principles and application Ability to support and develop junior colleagues
Security Platform Engineer / DevSecOps Engineer - 3 months+ (Apply online only)pd Outside IR35 - Hampshire ( Full time on site - 5 days per week) IMPORTANT: Candidates must hold an existing & transferrable high level clearance in order to be considered for the role. Successful applicants will be required to be security cleared prior to appointment. Looking for a DV Cleared Security Platfrom Engineer / DevSecOps Engineer to build a security platform. Essential Skills: Strong experience with Kubernetes Linux (Bash scripting) Strong knowledge of DevSecOps Kubernetes deployments Infrastructure as Code Splunk platform Ideal to have: Windows - (Windows admin) Familiarity with SeOps tooling, log aggregators, edr's etc Security Platform Engineer / DevSecOps Engineer - 3 months+ (Apply online only)pd Outside IR35 - Hampshire ( Full time on site - 5 days per week) Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job. Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.
18/11/2025
Contractor
Security Platform Engineer / DevSecOps Engineer - 3 months+ (Apply online only)pd Outside IR35 - Hampshire ( Full time on site - 5 days per week) IMPORTANT: Candidates must hold an existing & transferrable high level clearance in order to be considered for the role. Successful applicants will be required to be security cleared prior to appointment. Looking for a DV Cleared Security Platfrom Engineer / DevSecOps Engineer to build a security platform. Essential Skills: Strong experience with Kubernetes Linux (Bash scripting) Strong knowledge of DevSecOps Kubernetes deployments Infrastructure as Code Splunk platform Ideal to have: Windows - (Windows admin) Familiarity with SeOps tooling, log aggregators, edr's etc Security Platform Engineer / DevSecOps Engineer - 3 months+ (Apply online only)pd Outside IR35 - Hampshire ( Full time on site - 5 days per week) Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job. Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.
Role: Mobile Security Engineer Location: Bristol, UK Contract (Inside IR35) Your Profile Essential skills/knowledge/experience: Experience of Mobile platform security, threat modelling and mitigation techniques Capable of conducting regular reviews of our mobile application security posture using your hands-on experience. Develop and maintain pen-testing security tools, scripts, policies and procedures In depth knowledge of mobile app security standards (Android/iOS) Desirable skills/knowledge/experience: Familiarity with mobile development, DevSecOps tooling, testing and automation frameworks. Have deep knowledge and experience using the mobile security tools. Good understanding of authentication, authorisation, encryption, and cryptography patterns. Experience in proactive researching of new technologies emerging in the security landscape.
18/11/2025
Contractor
Role: Mobile Security Engineer Location: Bristol, UK Contract (Inside IR35) Your Profile Essential skills/knowledge/experience: Experience of Mobile platform security, threat modelling and mitigation techniques Capable of conducting regular reviews of our mobile application security posture using your hands-on experience. Develop and maintain pen-testing security tools, scripts, policies and procedures In depth knowledge of mobile app security standards (Android/iOS) Desirable skills/knowledge/experience: Familiarity with mobile development, DevSecOps tooling, testing and automation frameworks. Have deep knowledge and experience using the mobile security tools. Good understanding of authentication, authorisation, encryption, and cryptography patterns. Experience in proactive researching of new technologies emerging in the security landscape.
YT Technologies are on the lookout for a skilled Software Engineer to help build cutting-edge DevSecOps software. Due to the nature of the work, only candidates eligible for eDV clearance will be considered Key Skills; High level experience with Java and additional languages such as Python Development experience in Linux environments Solid understanding of JUnit 5.x, unit testing, and mocking frameworks Confident using Git and working within Agile/SCRUM teams Experience mentoring junior developers Knowledge of Oracle/relational databases, MongoDB, and GitLab CI/CD Familiarity with Apache NiFi, JavaScript/TypeScript, and React Experience with Elasticsearch, Kibana, Hibernate, and the Atlassian suite (Bitbucket, Jira, Confluence) Desirable; Experience with JSF (PrimeFaces) Knowledge of AWS and cloud-ready developmen Exposure to microservices or serverless architecture Understanding of cloud migration challenges and maturing CI/CD pipeline Hands-on experience with AWS services such as EC2, EKS, Fargate, IAM, S3, Lambda Due to the nature of the work, only candidates eligible for eDV clearance will be considered If interested, and you match the above requirements, please apply with your most recent CV and I will be in touch to discuss further.
14/11/2025
Full time
YT Technologies are on the lookout for a skilled Software Engineer to help build cutting-edge DevSecOps software. Due to the nature of the work, only candidates eligible for eDV clearance will be considered Key Skills; High level experience with Java and additional languages such as Python Development experience in Linux environments Solid understanding of JUnit 5.x, unit testing, and mocking frameworks Confident using Git and working within Agile/SCRUM teams Experience mentoring junior developers Knowledge of Oracle/relational databases, MongoDB, and GitLab CI/CD Familiarity with Apache NiFi, JavaScript/TypeScript, and React Experience with Elasticsearch, Kibana, Hibernate, and the Atlassian suite (Bitbucket, Jira, Confluence) Desirable; Experience with JSF (PrimeFaces) Knowledge of AWS and cloud-ready developmen Exposure to microservices or serverless architecture Understanding of cloud migration challenges and maturing CI/CD pipeline Hands-on experience with AWS services such as EC2, EKS, Fargate, IAM, S3, Lambda Due to the nature of the work, only candidates eligible for eDV clearance will be considered If interested, and you match the above requirements, please apply with your most recent CV and I will be in touch to discuss further.
Are you a seasoned solution lead or enterprise architect with a depth of experience in highly secure environments? Do you have the highest levels of security clearance, a consistent track record in defence or national security, and an innovative approach? If you're ready to work with prestigious clients to define and deliver robust, growth-focused solutions, we want to hear from you. The Defence & National Security Innovation Architect will play a meaningful role in defining and delivering enterprise solutions for high-profile defence and national security clients. Working with the CTO, the role encompasses two key areas of responsibility. Innovation and Future Solutions (50%) - Lead the identification, design, and development of advanced IT-enabled solutions, fostering innovation to address the evolving requirements of clients and the wider sector. Short-Term Customer Initiatives (50%) - Provide enterprise and solution leadership for rapid assessments and remediation programmes, working in close collaboration with client teams to resolve complex challenges and make sure successful project outcomes. This is a permanent role, mostly working on-site at locations across the South of England including, Hemel Hempstead, Salisbury, Portsmouth, Farnborough and Cheltenham. The role requires candidates to be holding a live DV clearance or previously held DV clearance. What you will be doing: Make sure the integrity and successful delivery of assigned solution areas within agreed scope, time, cost, and quality parameters. Maintain strong client and partner engagement, including coordination with subcontractors and partners. Represent and promote Sopra Steria's capabilities within client engagements and the wider industry. Monitor market and competitor trends to advise ongoing service and solution development. Share expertise through mentoring, workshops, and professional knowledge-sharing. Proactively identify, manage, and report risks in a timely and clear manner. Define enterprise and solution architectures for large-scale, sophisticated, or highly niche assignments. Lead pre-sales initiatives with potential for significant downstream revenue. Influence business and technology strategy across your area of responsibility. Develop and implement functional policies and procedures. Advise senior management on architecture, strategy, and market trends. Maintain a deep understanding of customer needs and evolving market dynamics. What you will bring: Define solution scope and deliverables to meet client (internal or external) requirements. Extensive experience as a Solution Lead or Enterprise Architect in highly secure defence or national security environments. Validated leadership in delivering innovative solutions to complex security and technology challenges. Confident in engaging with high-profile clients and partners to define strategy and make sure delivery excellence. Ability to balance forward-looking solution design with hands-on support for ongoing engagements. Deep knowledge of defence markets, suppliers, MOD, and UKIC delivery. Proven ownership and design of complex COTS and custom solutions. Expertise in IT architecture (TOGAF) and modelling (ArchiMate, C4). Solid understanding of standards, industry trends, and secure-by-design principles. Agile delivery experience and modern DevSecOps practices. Track record in delivery, bid, and pre-sales activities. High-level cyber awareness and security enforcement experience. Benefits: Car Allowance, Bonus, 25 days annual leave with the option to buy additional days, private health care, life assurance, pension, and generous flexible benefits fund (3% of base salary). Although this role is advertised as full-time, we believe that flexibility at work can promote work/life balance, increase your motivation, reduce stress and improves performance and productivity. We support different ways of working and can offer a range of flexible working arrangements. So, if you're interested and need to work flexibly, we encourage you to apply and talk to us about what might be possible. Loved reading about this job and want to know more about ADS? Sopra Steria's Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We cultivate a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most sophisticated safety- and security-critical markets. We embrace difference as a source of creativity, innovation and competitive advantage and are striving to become a more diverse organisation. We welcome applications from people with a diverse variety of backgrounds and identities. We are committed to equality of opportunity for all and do not discriminate on the basis of race, religion, colour, gender, age, disability, sexual orientation or marital status. We have partnered with Vercida, the UK's largest diversity and inclusion focused careers site, where all our vacancies are available in an accessible format. If you require any adjustments to the recruitment process, to enable you to perform to the best of your ability, please let us know when completing your application. We participate in the Disability Confident scheme and are committed to offering an interview to any candidate with a disability, who meets the minimum criteria for the role. If you believe this could apply to you, please let us know when completing your application.
13/11/2025
Full time
Are you a seasoned solution lead or enterprise architect with a depth of experience in highly secure environments? Do you have the highest levels of security clearance, a consistent track record in defence or national security, and an innovative approach? If you're ready to work with prestigious clients to define and deliver robust, growth-focused solutions, we want to hear from you. The Defence & National Security Innovation Architect will play a meaningful role in defining and delivering enterprise solutions for high-profile defence and national security clients. Working with the CTO, the role encompasses two key areas of responsibility. Innovation and Future Solutions (50%) - Lead the identification, design, and development of advanced IT-enabled solutions, fostering innovation to address the evolving requirements of clients and the wider sector. Short-Term Customer Initiatives (50%) - Provide enterprise and solution leadership for rapid assessments and remediation programmes, working in close collaboration with client teams to resolve complex challenges and make sure successful project outcomes. This is a permanent role, mostly working on-site at locations across the South of England including, Hemel Hempstead, Salisbury, Portsmouth, Farnborough and Cheltenham. The role requires candidates to be holding a live DV clearance or previously held DV clearance. What you will be doing: Make sure the integrity and successful delivery of assigned solution areas within agreed scope, time, cost, and quality parameters. Maintain strong client and partner engagement, including coordination with subcontractors and partners. Represent and promote Sopra Steria's capabilities within client engagements and the wider industry. Monitor market and competitor trends to advise ongoing service and solution development. Share expertise through mentoring, workshops, and professional knowledge-sharing. Proactively identify, manage, and report risks in a timely and clear manner. Define enterprise and solution architectures for large-scale, sophisticated, or highly niche assignments. Lead pre-sales initiatives with potential for significant downstream revenue. Influence business and technology strategy across your area of responsibility. Develop and implement functional policies and procedures. Advise senior management on architecture, strategy, and market trends. Maintain a deep understanding of customer needs and evolving market dynamics. What you will bring: Define solution scope and deliverables to meet client (internal or external) requirements. Extensive experience as a Solution Lead or Enterprise Architect in highly secure defence or national security environments. Validated leadership in delivering innovative solutions to complex security and technology challenges. Confident in engaging with high-profile clients and partners to define strategy and make sure delivery excellence. Ability to balance forward-looking solution design with hands-on support for ongoing engagements. Deep knowledge of defence markets, suppliers, MOD, and UKIC delivery. Proven ownership and design of complex COTS and custom solutions. Expertise in IT architecture (TOGAF) and modelling (ArchiMate, C4). Solid understanding of standards, industry trends, and secure-by-design principles. Agile delivery experience and modern DevSecOps practices. Track record in delivery, bid, and pre-sales activities. High-level cyber awareness and security enforcement experience. Benefits: Car Allowance, Bonus, 25 days annual leave with the option to buy additional days, private health care, life assurance, pension, and generous flexible benefits fund (3% of base salary). Although this role is advertised as full-time, we believe that flexibility at work can promote work/life balance, increase your motivation, reduce stress and improves performance and productivity. We support different ways of working and can offer a range of flexible working arrangements. So, if you're interested and need to work flexibly, we encourage you to apply and talk to us about what might be possible. Loved reading about this job and want to know more about ADS? Sopra Steria's Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We cultivate a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most sophisticated safety- and security-critical markets. We embrace difference as a source of creativity, innovation and competitive advantage and are striving to become a more diverse organisation. We welcome applications from people with a diverse variety of backgrounds and identities. We are committed to equality of opportunity for all and do not discriminate on the basis of race, religion, colour, gender, age, disability, sexual orientation or marital status. We have partnered with Vercida, the UK's largest diversity and inclusion focused careers site, where all our vacancies are available in an accessible format. If you require any adjustments to the recruitment process, to enable you to perform to the best of your ability, please let us know when completing your application. We participate in the Disability Confident scheme and are committed to offering an interview to any candidate with a disability, who meets the minimum criteria for the role. If you believe this could apply to you, please let us know when completing your application.
Principal Technical Architect - Secure Cloud / Defence - Farnborough / Hybrid - 120k - 140k A rare opportunity to join in a senior capacity for a proven technical leader to define and deliver secure cloud architectures across high-assurance environments within the defence industry. You'll set the technical direction, lead a team of architects, and shape complex cloud strategies that underpin national security programmes. This is a hands-on leadership role for someone who can combine deep cloud expertise with architectural vision, stakeholder influence, and real delivery impact. The Role Lead the design and direction of secure cloud and infrastructure solutions, ensuring alignment with strategic objectives and compliance standards. Develop and maintain architectural patterns, governance, and technical roadmaps for large-scale, high-security environments. Mentor and guide technical teams, promoting consistent standards, innovation, and knowledge sharing. Act as subject matter expert across AWS, Azure, and GCP, including restricted and government offerings. Provide technical authority through full solution lifecycles, from design through to delivery and assurance. You'll Bring 10+ years in architecture or infrastructure leadership, with 5+ in secure cloud environments (defence, government, or critical national systems). Proven experience in shaping technical strategy and leading architecture teams. Deep understanding of secure cloud design, zero-trust models, and compliance frameworks such as NIST, DISA STIGs, and NCSC best practice. Expertise in Infrastructure-as-Code, containerisation (Kubernetes, OpenShift), and automation for secure cloud deployments. Strong knowledge of networking, encryption, IAM, and DevSecOps principles. Excellent stakeholder management, communication, and bid support experience. Desirable Cloud certifications (AWS / Azure / GCP Architect-level). Security credentials (CISSP or equivalent). Agile / DevOps / DevSecOps Prior experience in MOD, UKIC, or other defence domains. Contributions to thought leadership in cloud security or architecture. Clearance Applicants must have current Security Clearance (SC) and interested in becoming DV Cleared.
13/11/2025
Full time
Principal Technical Architect - Secure Cloud / Defence - Farnborough / Hybrid - 120k - 140k A rare opportunity to join in a senior capacity for a proven technical leader to define and deliver secure cloud architectures across high-assurance environments within the defence industry. You'll set the technical direction, lead a team of architects, and shape complex cloud strategies that underpin national security programmes. This is a hands-on leadership role for someone who can combine deep cloud expertise with architectural vision, stakeholder influence, and real delivery impact. The Role Lead the design and direction of secure cloud and infrastructure solutions, ensuring alignment with strategic objectives and compliance standards. Develop and maintain architectural patterns, governance, and technical roadmaps for large-scale, high-security environments. Mentor and guide technical teams, promoting consistent standards, innovation, and knowledge sharing. Act as subject matter expert across AWS, Azure, and GCP, including restricted and government offerings. Provide technical authority through full solution lifecycles, from design through to delivery and assurance. You'll Bring 10+ years in architecture or infrastructure leadership, with 5+ in secure cloud environments (defence, government, or critical national systems). Proven experience in shaping technical strategy and leading architecture teams. Deep understanding of secure cloud design, zero-trust models, and compliance frameworks such as NIST, DISA STIGs, and NCSC best practice. Expertise in Infrastructure-as-Code, containerisation (Kubernetes, OpenShift), and automation for secure cloud deployments. Strong knowledge of networking, encryption, IAM, and DevSecOps principles. Excellent stakeholder management, communication, and bid support experience. Desirable Cloud certifications (AWS / Azure / GCP Architect-level). Security credentials (CISSP or equivalent). Agile / DevOps / DevSecOps Prior experience in MOD, UKIC, or other defence domains. Contributions to thought leadership in cloud security or architecture. Clearance Applicants must have current Security Clearance (SC) and interested in becoming DV Cleared.
We are seeking a highly experienced and strategic senior leader to oversee our Cyber Engineering, Identity & Access Management (IAM), and Data Loss Prevention (DLP) functions. This role will be responsible for driving the design, delivery, and governance of enterprise-wide security engineering solutions, while ensuring secure, scalable, and resilient identity and data protection services. The ideal candidate will combine deep technical expertise with strong leadership skills to shape the future of cybersecurity, identity, and data protection within the organization. This position is designated as a Senior Management Function (SMF) under the Financial Conduct Authority regime, carrying personal accountability for compliance, operational resilience, and security effectiveness. The Role: Strategic Leadership Define and execute the global strategy for Cyber Engineering, IAM, and DLP in alignment with the enterprise security and technology roadmap. Serve as a trusted advisor to the CISO, CIO, and executive leadership on emerging threats, secure architecture, identity, and data protection. Establish metrics and reporting to demonstrate effectiveness, risk reduction, and compliance with regulatory requirements (e.g., National Institute of Standards Cyber Security Framework (NIST CSF), Digital Operations Resilience Act (DORA), New Tork State Department of Financial Services (NYDFS), Sarbanes-Oxyley (SOX), and the Financia Conduct Authority(FCA). Cyber Engineering Oversight Lead engineering teams responsible for core security platforms, including endpoint protection, cloud security, network defense, vulnerability management, and DevSecOps integrations. Build and mature a comprehensive vulnerability management program, including continuous scanning, risk-based prioritization, remediation tracking, and Board-level reporting. Drive innovation by embedding security into cloud, hybrid, and modern application architectures ("Secure by Design" principles). Ensure the adoption of automation, orchestration, and advanced analytics to improve detection, response, and resiliency. Identity & Access Management Own enterprise-wide IAM strategy, including workforce and customer identity, privileged access management (PAM), identity governance and administration (IGA), and multi-factor authentication (MFA). Lead initiatives to modernize and integrate IAM platforms to support cloud adoption, Zero Trust, and frictionless user experiences. Partner with business and technology leaders to enable secure digital transformation through robust identity services. Data Loss Prevention (DLP) Advance a comprehensive Data Loss Prevention program to safeguard sensitive information across endpoints, cloud, email, and collaboration platforms. Establish enterprise-wide policies and controls to prevent unauthorized data exfiltration, insider threats, and regulatory breaches. Implement monitoring, classification, and enforcement mechanisms that balance data protection with business enablement. Partner with business, compliance, and data governance teams to align DLP strategy with General Data Protection Regulation, Financial Conduct Authority, Prudential Regulation Authority, Sarbanes-Oxley, and other global data protection requirements. Provide executive and Board-level reporting on data protection risks, incidents, and mitigation efforts. Governance, Risk & Compliance Ensure IAM, DLP, and security engineering practices meet regulatory, audit, and policy requirements. Define and maintain standards for identity lifecycle, access controls, data handling, and information protection. Oversee risk assessments and remediation programs tied to IAM, DLP, and security engineering platforms. Senior Management Function (FCA Responsibilities) As an FCA-designated Senior Management Function (SMF) role, the position carries individual accountability under the Senior Managers & Certification Regime (SM&CR). Specific responsibilities include: Personal accountability for ensuring cyber, IAM, and DLP controls are effective, proportionate, and aligned with FCA expectations for operational resilience and financial sector stability. Maintaining robust governance, oversight, and risk management frameworks for engineering, identity, and data protection, ensuring risks are identified, escalated, and remediated in line with FCA and PRA requirements. Demonstrating reasonable steps have been taken to oversee outsourced arrangements, third-party providers, and cloud services related to IAM, DLP, and cyber platforms. Ensuring Board and regulators receive timely, accurate, and complete information on cyber, identity, and data protection risks, vulnerabilities, and remediation activities. Acting as the point of accountability for operational resilience in cyber engineering, IAM, and DLP, supporting FCA requirements around impact tolerance, scenario testing, and response planning. Requirements: Progressive experience in cybersecurity, with extensive experience in leadership roles across IAM, cyber engineering, and/or data protection. Proven track record of leading global security programs at scale in complex, regulated environments (financial services strongly preferred). Expertise in IAM technologies (SailPoint, Okta, Azure AD, CyberArk, Ping Identity), DLP platforms (Symantec, Microsoft Purview, Forcepoint, Digital Guardian), and security engineering tools (EDR, CSPM, SIEM, SOAR, vulnerability management). Strong knowledge of Zero Trust, data protection regulations (GDPR, FCA, PRA), cloud-native security, and DevSecOps practices. Exceptional leadership, communication, and stakeholder engagement skills, with the ability to influence at Board and executive levels. Relevant certifications (CISSP, CISM, CCSP, CIPP/E, SABSA, or equivalent) preferred. We're committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email your recruiter.
12/11/2025
Full time
We are seeking a highly experienced and strategic senior leader to oversee our Cyber Engineering, Identity & Access Management (IAM), and Data Loss Prevention (DLP) functions. This role will be responsible for driving the design, delivery, and governance of enterprise-wide security engineering solutions, while ensuring secure, scalable, and resilient identity and data protection services. The ideal candidate will combine deep technical expertise with strong leadership skills to shape the future of cybersecurity, identity, and data protection within the organization. This position is designated as a Senior Management Function (SMF) under the Financial Conduct Authority regime, carrying personal accountability for compliance, operational resilience, and security effectiveness. The Role: Strategic Leadership Define and execute the global strategy for Cyber Engineering, IAM, and DLP in alignment with the enterprise security and technology roadmap. Serve as a trusted advisor to the CISO, CIO, and executive leadership on emerging threats, secure architecture, identity, and data protection. Establish metrics and reporting to demonstrate effectiveness, risk reduction, and compliance with regulatory requirements (e.g., National Institute of Standards Cyber Security Framework (NIST CSF), Digital Operations Resilience Act (DORA), New Tork State Department of Financial Services (NYDFS), Sarbanes-Oxyley (SOX), and the Financia Conduct Authority(FCA). Cyber Engineering Oversight Lead engineering teams responsible for core security platforms, including endpoint protection, cloud security, network defense, vulnerability management, and DevSecOps integrations. Build and mature a comprehensive vulnerability management program, including continuous scanning, risk-based prioritization, remediation tracking, and Board-level reporting. Drive innovation by embedding security into cloud, hybrid, and modern application architectures ("Secure by Design" principles). Ensure the adoption of automation, orchestration, and advanced analytics to improve detection, response, and resiliency. Identity & Access Management Own enterprise-wide IAM strategy, including workforce and customer identity, privileged access management (PAM), identity governance and administration (IGA), and multi-factor authentication (MFA). Lead initiatives to modernize and integrate IAM platforms to support cloud adoption, Zero Trust, and frictionless user experiences. Partner with business and technology leaders to enable secure digital transformation through robust identity services. Data Loss Prevention (DLP) Advance a comprehensive Data Loss Prevention program to safeguard sensitive information across endpoints, cloud, email, and collaboration platforms. Establish enterprise-wide policies and controls to prevent unauthorized data exfiltration, insider threats, and regulatory breaches. Implement monitoring, classification, and enforcement mechanisms that balance data protection with business enablement. Partner with business, compliance, and data governance teams to align DLP strategy with General Data Protection Regulation, Financial Conduct Authority, Prudential Regulation Authority, Sarbanes-Oxley, and other global data protection requirements. Provide executive and Board-level reporting on data protection risks, incidents, and mitigation efforts. Governance, Risk & Compliance Ensure IAM, DLP, and security engineering practices meet regulatory, audit, and policy requirements. Define and maintain standards for identity lifecycle, access controls, data handling, and information protection. Oversee risk assessments and remediation programs tied to IAM, DLP, and security engineering platforms. Senior Management Function (FCA Responsibilities) As an FCA-designated Senior Management Function (SMF) role, the position carries individual accountability under the Senior Managers & Certification Regime (SM&CR). Specific responsibilities include: Personal accountability for ensuring cyber, IAM, and DLP controls are effective, proportionate, and aligned with FCA expectations for operational resilience and financial sector stability. Maintaining robust governance, oversight, and risk management frameworks for engineering, identity, and data protection, ensuring risks are identified, escalated, and remediated in line with FCA and PRA requirements. Demonstrating reasonable steps have been taken to oversee outsourced arrangements, third-party providers, and cloud services related to IAM, DLP, and cyber platforms. Ensuring Board and regulators receive timely, accurate, and complete information on cyber, identity, and data protection risks, vulnerabilities, and remediation activities. Acting as the point of accountability for operational resilience in cyber engineering, IAM, and DLP, supporting FCA requirements around impact tolerance, scenario testing, and response planning. Requirements: Progressive experience in cybersecurity, with extensive experience in leadership roles across IAM, cyber engineering, and/or data protection. Proven track record of leading global security programs at scale in complex, regulated environments (financial services strongly preferred). Expertise in IAM technologies (SailPoint, Okta, Azure AD, CyberArk, Ping Identity), DLP platforms (Symantec, Microsoft Purview, Forcepoint, Digital Guardian), and security engineering tools (EDR, CSPM, SIEM, SOAR, vulnerability management). Strong knowledge of Zero Trust, data protection regulations (GDPR, FCA, PRA), cloud-native security, and DevSecOps practices. Exceptional leadership, communication, and stakeholder engagement skills, with the ability to influence at Board and executive levels. Relevant certifications (CISSP, CISM, CCSP, CIPP/E, SABSA, or equivalent) preferred. We're committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email your recruiter.
CBSbutler Holdings Limited trading as CBSbutler
Reading, Oxfordshire
Technical Architects x 3 + Contracts initially to end March 26 - but extensions expected + SC Cleared role + Hybrid working from Berkshire + 80 to 100 per hour - Inside IR35 Key Skills: + System & Service Architecture + Architectural Frameworks - TOGAF, MODAF, etc Technical Architect - Defence Systems As a Technical Architect , you'll define, assure, and evolve secure, mission-critical architectures across complex defence programmes. You'll act as the technical design authority, ensuring interoperability, resilience, and compliance with MOD and security standards. Key Responsibilities Define and govern system and service architectures for C4ISR, mission systems, and secure communications solutions. Lead architecture design, decomposition, and interface definition , ensuring traceability from requirements through to delivery. Apply and adapt architecture frameworks (MODAF, NAF, TOGAF) and secure-by-design principles . Conduct technical reviews and trade studies , balancing capability, risk, and through-life cost. Support bids, solution development, and stakeholder engagement at senior technical forums. Provide technical assurance and mentor engineers in architecture best practice and model-based design. What You'll Bring Proven experience in defence or mission system architecture , ideally spanning multiple domains (sensors, comms, data, or platform integration). Strong understanding of secure systems design , information assurance , and Defence Digital / JSP standards . Hands-on familiarity with cloud, networking, and cross-domain architectures . Experience applying Agile or SAFe methods within highly regulated environments. Excellent communication and influencing skills, with the ability to engage MOD and industry stakeholders. Desirable Certifications: TOGAF, ArchiMate, CISSP, AWS/Azure . Experience with DevSecOps , Infrastructure-as-Code , or automation in secure environments. Knowledge of Def Stan 00-055/056 , JSP 604 , or similar defence standards. Experience contributing to technology roadmaps and enterprise architecture strategies.
12/11/2025
Contractor
Technical Architects x 3 + Contracts initially to end March 26 - but extensions expected + SC Cleared role + Hybrid working from Berkshire + 80 to 100 per hour - Inside IR35 Key Skills: + System & Service Architecture + Architectural Frameworks - TOGAF, MODAF, etc Technical Architect - Defence Systems As a Technical Architect , you'll define, assure, and evolve secure, mission-critical architectures across complex defence programmes. You'll act as the technical design authority, ensuring interoperability, resilience, and compliance with MOD and security standards. Key Responsibilities Define and govern system and service architectures for C4ISR, mission systems, and secure communications solutions. Lead architecture design, decomposition, and interface definition , ensuring traceability from requirements through to delivery. Apply and adapt architecture frameworks (MODAF, NAF, TOGAF) and secure-by-design principles . Conduct technical reviews and trade studies , balancing capability, risk, and through-life cost. Support bids, solution development, and stakeholder engagement at senior technical forums. Provide technical assurance and mentor engineers in architecture best practice and model-based design. What You'll Bring Proven experience in defence or mission system architecture , ideally spanning multiple domains (sensors, comms, data, or platform integration). Strong understanding of secure systems design , information assurance , and Defence Digital / JSP standards . Hands-on familiarity with cloud, networking, and cross-domain architectures . Experience applying Agile or SAFe methods within highly regulated environments. Excellent communication and influencing skills, with the ability to engage MOD and industry stakeholders. Desirable Certifications: TOGAF, ArchiMate, CISSP, AWS/Azure . Experience with DevSecOps , Infrastructure-as-Code , or automation in secure environments. Knowledge of Def Stan 00-055/056 , JSP 604 , or similar defence standards. Experience contributing to technology roadmaps and enterprise architecture strategies.