DevSecOps Consultant - 12 Month Contract - Hybrid in Sheffield - Inside IR35
Role Overview
We are looking for a DevSecOps Consultant to join on a 12-month hybrid contract based in Sheffield, starting September 2026. The role sits within an Engineering Excellence and Enablement team, working across global engineering platforms to benchmark, uplift, and continuously evolve cybersecurity maturity - ensuring build systems, CI/CD pipelines, runtime infrastructure, and developer tooling are secure by design within a leading financial services institution.
Key Responsibilities
- Develop and maintain an Engineering-Platform Cybersecurity Maturity Framework, conducting comprehensive platform security reviews across CI/CD pipelines, build systems, runtime infrastructure, and developer tooling
- Perform threat modelling and gap analysis, identifying vulnerabilities and systemic risks across source code, artefacts, and workloads, and establishing standardised secure architecture and engineering patterns
- Define and enforce platform security baselines using policy-as-code and automated controls, integrating vulnerability management, SBOM, provenance, and code-signing practices within engineering workflows
- Partner with platform owners to remediate critical gaps and build actionable security roadmaps, balancing quick wins with long-term strategic improvements aligned to business risk and regulatory impact
- Serve as a trusted advisor to senior technology stakeholders and Cyber leadership, representing the function in key governance forums and influencing adoption of cybersecurity best practices across federated engineering teams
Top 5 Skills
- Proven cybersecurity expertise within large-scale regulated financial institutions, with deep technical knowledge of engineering platforms including CI/CD systems, build tools, artifact repositories, and runtime environments
- Strong DevSecOps experience including secure pipeline design, integration of security scanning tools, and automation of security controls across enterprise environments
- Demonstrable experience conducting threat modelling, platform security assessments, and gap analysis, with experience building and implementing maturity models, frameworks, or roadmaps
- Strong knowledge of service mesh, cryptography, network security, application security, vulnerability management, and risk management in complex enterprise environments
- Strong stakeholder management and communication skills, with the ability to translate technical risk into business impact and drive change across federated teams - desirable: CISSP, CISM, CCSK, or CCSP, and hands-on cloud security experience across AWS, Azure, or GCP
Contract Details:
- Rate: £575 per day Inside IR35
- Location: Hybrid (2x a week) in Sheffield
- Contract Length: 12 - Month Initial Contract