Principal Architect, DevSecOps
Listed on 2026-05-30
-
IT/Tech
Systems Engineer, Cybersecurity
Hybrid role requiring 2 days per week in a Wolters Kluwer office
Wolters Kluwer is seeking a hands‑on, technically credible Principal Architect, Dev Sec Ops to co‑lead the Dev Sec Ops Center of Excellence and define the enterprise architecture, standards, and golden paths for secure software delivery.
This role operates at the intersection of a mature engineering organization and established centers of excellence. The Principal Architect partners closely with DXG leadership and the GBS team to own CI/CD pipeline architecture, security integration, Dev Sec Ops tooling strategy, and engineering adoption
, while jointly governing the Dev Sec Ops maturity model across the enterprise.
This is not a coordination or program management role
. The successful candidate actively builds solutions, develops reference implementations, and leads through deep technical expertise. Influence is earned through hands‑on contribution, architectural insight, and the ability to translate security and platform standards into practical, scalable engineering practices.
The ideal candidate combines strong software and platform engineering skills with Dev Sec Ops and security depth
, enabling teams to deliver software that is secure, automated, and production‑ready by design.
The primary accountability from which all other responsibilities derive their authority.
- Support DXE Leadership in Co‑leading the Dev Sec Ops CoE with the GBS Team, jointly setting the Dev Sec Ops strategy, maturity model, capability roadmap, and governance framework for the enterprise.
- Define and implement the CI, security integration, golden path, and engineering enablement dimensions of the CoE.
- Establish and operate effective CoPs: shared decision protocol, clear escalation paths, and a transparent operating rhythm that prevents the CoE from becoming a coordination bottleneck.
- Represent the Dev Sec Ops CoE at Architecture CoE and cross‑functional governance forums, ensuring Dev Sec Ops standards are embedded in enterprise architectural governance, not maintained as a parallel track.
- Operate as peer interface with the App Sec CoE, translating their security requirements and standards into Dev Sec Ops implementation patterns, not redefining them.
Outright ownership of the standards, architecture, and reference implementations
- Define and maintain the enterprise CI pipeline architecture: build, test, security gate, artifact creation, and handoff standards that connect to the Ops team's CD domain.
- Establish the integration seam between CI and CD, the standards and contracts that govern how a build artefact transitions from pipeline to deployment with security posture preserved across the boundary.
- Define policy‑as‑code standards, approved toolchain configurations, and pipeline governance guardrails in collaboration with the App Sec CoE.
- Produce authoritative reference architectures and design patterns for CI pipeline security that engineering teams and the IDP can implement directly.
In Collaboration with the principal architect Developer Platform and the Engineering Enablement Team
- Develop the enablement assets, playbooks, architecture decision records, worked examples, and onboarding guides that allow engineering teams to adopt Dev Sec Ops standards independently and confidently.
- Define and track Dev Sec Ops adoption metrics by engineering domain; report progress against the CoE maturity model with transparency to engineering and technology leadership.
- Provide hands‑on architectural guidance to engineering teams working through complex adoption challenges direct support, not redirection to documentation alone.
- Partner with the Dev Sec Ops CoE to deliver structured enablement programs and community-of-practice activities that build Dev Sec Ops capability across the organization over time.
- 8+ years in software engineering, platform engineering, or security engineering — including at least 4 years in a principal, staff, or lead architect role with demonstrable enterprise‑scale impact.
- P…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).