> Markdown version of [/jobs/ext/3602798-design-engineer](https://www.wearedevelopers.com/jobs/ext/3602798-design-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Design Engineer - **Company:** Insight - **Location:** Sheffield, UK - **Experience:** Experienced - **Salary:** £77,936.0 - **Contract:** Permanent contract - **Skills:** Confluence, JIRA, User Authentication, Cloud Computing, Cyber Security, Computer Literacy, Federated Identity Management, Identity and Access Management, Kerberos (Protocol), OAuth, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Single Sign-On, Software Engineering, Software Vulnerability Management, Technical Debt, Togaf, Information Technology, Hashicorp, Terraform - **Published:** October 7, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5914221116 ## About the Role Significant technical expertise in at least one cybersecurity domain (e.g., security operations, threat/vulnerability management, IAM, cryptography, infrastructure, network, application, data, cloud). - Strong IT background with ability to communicate technical concepts to non-security SMEs. - Deep understanding of cybersecurity practices, operational risk management, incident response, and threat/vulnerability management. - Knowledge of relevant national/international laws, regulations, and ethics, especially in the financial industry. - Experience with enterprise and solution architecture roles and integration. - Background in both operational and transformational cybersecurity roles or a clear understanding of both. - Experience in large-scale IT transformation programs. Identity & Access Management: - 3+ years' experience working with HashiCorp Vault (on-prem preferred). - 3+ years' experience designing and building complex modules using HashiCorp Terraform. - In-depth, hands-on experience with Vault integration, including Secret Engines and Authentication methods. - Ownership of root cause investigations and monitoring of Vault integration. - Experience designing/implementing Workload Identity Frameworks at enterprise scale. - Ability to define and influence secrets management strategy within the organization. - Experience with Federated Identity Management and enabling single sign-on across domains. - Experience implementing Privileged Access Management (PAM) solutions. - Proficiency in secure authentication protocols (Kerberos, OAuth, SAML)., Degree or equivalent experience in cybersecurity, computer science, software engineering, or related field. - Industry certifications such as CISSP/CISM (preferred). - SABSA or TOGAF certification (preferred). Platform & Technology Proficiency: - High proficiency with Jira for project and task management. - Working knowledge of Confluence for documentation and collaboration. ## Description Produce, manage, and update end-to-end solution designs aligned with reference architecture and business requirements. - Document and communicate key design decisions and options. - Manage technical debt and ensure approval of design deviations. - Identify and mitigate technical risks/issues in solution design. - Translate requirements into architecture to meet business outcomes. - Ensure solutions are efficient, timely, and cost-effective. - Maintain strong documentation practices. Governance: - Ensure all architectural artifacts undergo required governance and peer review. - Present solution designs and patterns at technical design authorities for feedback and approval. Risk and Dependency Management: - Manage and escalate technical and project risks/issues. - Articulate solutions and remediation for technical risks. - Map design decisions to technical risks and communicate rationale for decisions. Leadership & Teamwork: - Provide technical thought leadership in cybersecurity domain. - Collaborate across IT as a cybersecurity SME. - Manage project teams of architects, engineers, and analysts. - Take on deputy program management duties when needed.