×
Register Here to Apply for Jobs or Post Jobs. X

DevSecOps Capability Manager

Job in Skipton, North Yorkshire, BD23, England, UK
Listing for: Skipton Building Society
Full Time position
Listed on 2026-05-10
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Cloud Computing: Infrastructure & Operations, IT Project Manager
Salary/Wage Range or Industry Benchmark: 80000 - 100000 GBP Yearly GBP 80000.00 100000.00 YEAR
Job Description & How to Apply Below

Hours:

35 hours per week

Closing Date:
Fri, 10 Apr 2026

Job Overview

As our Dev Sec Ops  Capability Manager, you’ll lead and scale Skipton’s Dev Sec Ops  capability to enable fast, safe and compliant software delivery across our product and platform teams. You will be accountable for embedding secure‑by‑design principles, modern automation practices, and policy‑as‑code into our CI/CD ecosystem, ensuring that our engineering teams can deliver high‑quality change with confidence. You will drive improvements in lead time, deployment frequency, change failure rate and system reliability, all measured through our Engineering Scorecard.

This role blends technical strategy, leadership, governance and hands‑on capability development to strengthen our engineering foundations and support delivery of the Society’s Corporate Plan.

Responsibilities
  • Owning lead time for changes and deployment frequency outcomes across shared pipelines and platforms.
  • Publishing DORA and flow metrics monthly, using them to drive targeted improvements.
  • Removing delivery bottlenecks through automation and policy‑as‑code, including trunk‑based development, automated approvals for low‑risk changes, canary/blue‑green deployment and auto‑rollback.
  • Triggering “scorecard → investment” actions when performance thresholds are breached to restore flow, quality and reliability.
  • Leading, coaching and developing a team of 3–5 Dev Sec Ops  Engineers.
  • Defining and maintaining Dev Sec Ops  standards, patterns and best practices across engineering teams.
  • Building a high‑performing engineering culture focused on security, automation and continuous improvement.
  • Setting the strategy for Dev Sec Ops  capabilities, including pipeline standardisation and security automation.
  • Establishing governance for secure CI/CD, infrastructure‑as‑code and cloud delivery.
  • Defining and enforcing Observability Minimum Standards including tracing, SLOs, release‑linked annotations and dashboards.
  • Mandating security in the pipeline, including secrets protection, SAST/SCA/DAST, IaC scanning and WAF coverage for external apps.
  • Governance of Golden Path (Prod‑OS) templates, patterns and adoption levels.
  • Overseeing the reliability, performance and security posture of pipelines, platforms and engineering tooling.
  • Ensuring effective vulnerability management, including remediation tracking and escalation.
  • Providing leadership during incidents and post‑incident reviews, improving MTTR and root‑cause clarity.
  • Integrating telemetry across Azure, Defender, Entra and WAF to unify our security posture.
  • Using SLO/error‑budget signals and observability insights to inform go/no‑go and rollback decisions.
  • Acting as a senior advisor to Engineering Managers, Product Owners and Cyber Security teams, ensuring strong alignment on security requirements, delivery processes and adoption of modern practices.
  • Representing Dev Sec Ops  across governance forums and contributing to technology‑wide decisions.
  • Leading decisions on Dev Sec Ops  tooling, including evaluation and lifecycle management.
  • Driving automation across testing, security scanning, deployment, monitoring and compliance.
  • Partnering with Cloud and Platform Engineering to ensure scalable, resilient and consistent Dev Sec Ops  ecosystems.
  • Owning the Golden Path service catalogue, including pipelines, IaC modules and secure defaults.
  • Embedding BCP and operational resilience controls directly as policy‑as‑code.
  • Ensuring pipelines produce audit‑ready evidence for regulated environments.
  • Running periodic gamedays with Release & Environments teams to validate recoverability.
Qualifications
  • Strong leadership and people‑management experience, particularly coaching senior engineers.
  • Deep expertise in CI/CD design, automation and security integration.
  • Strong understanding of cloud platforms, containerisation, infrastructure‑as‑code and modern delivery patterns.
  • Demonstrated ability to address and remediate security risks at scale.
  • Excellent communication and influencing skills across technical and non‑technical audiences.
  • Proven track record of improving DORA and flow metrics through automation and modern engineering practices.
  • Experience defining observability standards and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary