> Markdown version of [/jobs/ext/3101894-principal-security-architect-devsecops](https://www.wearedevelopers.com/jobs/ext/3101894-principal-security-architect-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Architect - DevSecOps - **Company:** UST Global - **Location:** Nottingham, UK - **Experience:** Expert - **Salary:** £39,000.0 - £79,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Access, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Audit Trail, Automation of Tests, Software as a Service, Cloud Computing, Cloud Computing Security, Static Program Analysis, Computer Networks, Continuous Integration, DevOps, Programming Tools, Identity and Access Management, Information Systems Security Architecture Professional, Key Management, Network Segmentation, OAuth, OpenID, Systems Development Life Cycle, Role-Based Access Control, Cloud Services, Prometheus, Zero Trust Network Access, Security Software, Security Information and Event Management, Software Deployment, Software Engineering, Systems Integration, Policy as Code, Data Logging, Cloud Platform System, Istio, Grafana, Software Security, Backend, Rate Limiting, Cloudformation, Event Driven Architecture, Kubernetes, Infrastructure Automation Frameworks, Production Code, Enterprise Integration, ArcSight Event Correlation, Cloudwatch, Terraform, Devsecops, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** September 27, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5899595470 ## About the Role * 8+ years of experience in software, security, cloud security, DevSecOps, or platform engineering; 10-15 years is ideal, with production platform ownership. * Strong software engineering background, including the ability to review application code, system designs, CI/CD workflows, infrastructure automation, and runtime behavior. * Proven experience securing cloud-native platforms in production. * Deep knowledge of secure SDLC practices, including secure design and coding, threat modeling, automated testing, vulnerability and dependency management, release controls, and production readiness. * Practical experience integrating SAST, DAST, and SCA into CI/CD workflows. * Experience with container security, including image scanning, base-image strategy, registry controls, remediation, runtime configuration, and secure workload deployment. * Kubernetes security experience, including cluster hardening, namespace isolation, RBAC, admission control, network policies, workload identity, pod security, secrets, ingress, and runtime protection. * Experience with policy-as-code tools such as OPA, Gatekeeper, or Kyverno, or equivalent tools. * Knowledge of IAM, least privilege, zero trust, workload identity, service-to-service authentication, and identity-driven security models. * Experience with secrets management, including secure storage, rotation, access control, pipeline integration, runtime injection, and governance. * Experience securing SaaS integrations and platform architectures, including identity, access, data protection, tenant boundaries, and auditability. * Experience with CI/CD security automation, including pipeline hardening, artifact integrity, dependency controls, environment promotion, deployment approvals, rollback safety, and supply-chain security. * Production security experience, including reliability, auditability, scalability, incident response, monitoring, and remediation. * Strong communication skills, including the ability to explain architecture, risks, and trade-offs to globally distributed teams. * Technical leadership and mentoring skills to raise engineering standards without formal authority. * Comfort working in a global, distributed organization across multiple teams, stakeholders, and time zones. * Preferred: AWS security experience, including IAM, Organizations, networking, KMS, CloudTrail, GuardDuty, Security Hub, workload identity, private connectivity, and multi-account patterns. * Preferred: Production experience with Amazon EKS or equivalent Kubernetes platforms. * Preferred: IaC security experience with AWS CDK, Terraform, or CloudFormation, including static analysis, policy enforcement, and secure module design. * Preferred: GitOps security experience, including repository controls, signed artifacts, environment promotion, drift detection, and deployment guardrails. * Preferred: Software supply-chain security experience, including SBOMs, artifact signing, provenance, dependency controls, and build integrity. * Preferred: Observability and security monitoring experience with tools such as Prometheus, Grafana, CloudWatch, OpenTelemetry, SIEM, tracing, logging, and event correlation. * Preferred: API security experience, including OAuth2/OIDC, mTLS, service mesh, gateway security, rate limiting, token validation, and service-to-service authorization. * Preferred: Experience in financial services, banking, or regulated environments where auditability and operational control are critical. * Preferred: Experience building reusable security platforms, guardrails, templates, policy libraries, and paved-road patterns for multiple teams. * Preferred: Experience supporting, patching, auditing, scaling, migrating, and evolving secure platforms after adoption. ## Description * Define and evolve the DevSecOps strategy for our cloud-native banking transformation platform. * Embed security across the SDLC, including design, coding, build, test, deployment, runtime, monitoring, and incident response. * Design and implement automated security controls across CI/CD pipelines, infrastructure provisioning, application delivery, container images, Kubernetes, and cloud services. * Integrate and operationalize SAST, DAST, SCA, container scanning, secrets scanning, and policy-as-code. * Define secure engineering standards and reusable guardrails that help teams move quickly within approved boundaries. * Apply cloud-native security patterns for IAM, network segmentation, workload identity, secrets management, least privilege, zero trust, runtime security, and auditability. * Guide secure architecture for APIs, microservices, event-driven systems, SaaS integrations, and developer tooling. * Partner with platform, backend, DevOps, QA, product, and delivery teams to build security into delivery. * Mentor engineers through design reviews, threat modeling, code and pipeline reviews, and pairing. * Ensure production systems are secure, observable, resilient, compliant, and ready for regulated banking. * Work with our CTO to define standards, identify engineering gaps, improve delivery quality, and ensure architecture is reflected in production code, platforms, and operational practices. * Influence multiple teams, establish reusable standards, mentor technical leaders, challenge weak designs, and turn technical direction into production-quality execution. * Use engineering judgment to validate, refine, or reject AI-generated outputs and ensure controls are automated, observable, repeatable, and embedded. Technologies: * AI * API * AWS * Architect * Backend * CI/CD * Cloud * CloudWatch * CTO * DevSecOps * DevOps * Embedded * GitOps * Grafana * IAM * Kubernetes * Network * OpenTelemetry * Prometheus * RBAC * Security * Terraform * microservices * LESS ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)