Jobs
My ads
My job alerts
Sign in
Find a job Career Tips Companies
Find

Devsecops capability manager

Skipton
Skipton
Capability manager
€80,000 a year
Posted: 18 May
Offer description

Hours: 35 hours per week

Closing Date: Sat, 23 May 2026

As our DevSecOps Capability Manager, you'll lead and scale Skipton's DevSecOps capability to enable fast, safe and compliant software delivery across our product and platform teams. You will be accountable for embedding secure‑by‑design principles, modern automation practices, and policy‑as‑code into our CI/CD ecosystem, ensuring that our engineering teams can deliver high‑quality change with confidence.

You will drive improvements in lead time, deployment frequency, change failure rate and system reliability, all measured through our Engineering Scorecard. This role blends technical strategy, leadership, governance and hands‑on capability development to strengthen our engineering foundations and support delivery of the Society's Corporate Plan.


What will you be doing?


Value, Flow & Quality

* Owning lead time for changes and deployment‑frequency outcomes across shared pipelines and platforms.
* Publishing DORA and flow metrics monthly, using them to drive targeted improvements.
* Removing delivery bottlenecks through automation and policy‑as‑code, including trunk‑based development, automated approvals for low‑risk changes, canary/blue‑green deployment and auto‑rollback.
* Triggering "scorecard → investment" actions when performance thresholds are breached to restore flow, quality and reliability.


Leadership & Capability Development

* Leading, coaching and developing a team of 3‑5 DevSecOps Engineers.
* Defining and maintaining DevSecOps standards, patterns and best practices across engineering teams.
* Building a high‑performing engineering culture focused on security, automation and continuous improvement.


Strategy, Governance & Technical Direction

* Setting the strategy for DevSecOps capabilities, including pipeline standardisation and security automation.
* Establishing governance for secure CI/CD, infrastructure‑as‑code and cloud delivery.
* Defining and enforcing Observability Minimum Standards including tracing, SLOs, release‑linked annotations and dashboards.
* Mandating security in the pipeline, including secrets protection, SAST/SCA/DAST, IaC scanning and WAF coverage for external apps.
* Governing Golden Path (ProdOS) templates, patterns and adoption levels.


Operational Oversight & Risk Management

* Overseeing the reliability, performance and security posture of pipelines, platforms and engineering tooling.
* Ensuring effective vulnerability management, including remediation tracking and escalation.
* Providing leadership during incidents and post‑incident reviews, improving MTTR and root‑cause clarity.
* Integrating telemetry across Azure, Defender, Entra and WAF to unify our security posture.
* Using SLO/error‑budget signals and observability insights to inform go/no‑go and rollback decisions.


Collaboration Across Technology & Business

* Acting as a senior advisor to Engineering Managers, Product Owners and Cyber Security teams.
* Ensuring strong alignment on security requirements, delivery processes and adoption of modern practices.
* Representing DevSecOps across governance forums and contributing to technology‑wide decisions.
* Acting as a visible advocate for safe, rapid delivery and sharing best practice internally and externally.


Tooling, Automation & Platform Optimisation

* Leading decisions on DevSecOps tooling, including evaluation and lifecycle management.
* Driving automation across testing, security scanning, deployment, monitoring and compliance.
* Partnering with Cloud and Platform Engineering to ensure scalable, resilient and consistent DevSecOps ecosystems.
* Owning the Golden Path service catalogue, including pipelines, IaC modules and secure defaults.


Business Continuity & Operational Resilience

* Embedding BCP and operational‑resilience controls directly as policy‑as‑code.
* Ensuring pipelines produce audit‑ready evidence for regulated environments.
* Running periodic gamedays with Release & Environments teams to validate recoverability.


What do we need from you?


Knowledge, skills & experience

* Strong leadership and people‑management experience, particularly coaching senior engineers.
* Deep expertise in CI/CD design, automation and security integration.
* Strong understanding of cloud platforms, containerisation, infrastructure‑as‑code and modern delivery patterns.
* Demonstrated ability to address and remediate security risks at scale.
* Excellent communication and influencing skills across technical and non‑technical audiences.
* Proven track record of improving DORA and flow metrics through automation and modern engineering practices.
* Experience defining observability standards and implementing unified dashboards.
* Extensive experience in DevOps, security engineering or platform engineering within complex or regulated environments.
* Strong working knowledge of automated security tooling (SAST, SCA, DAST, secrets scanning, container scanning).
* Experience in cloud security, identity and access management, zero‑trust principles and platform guardrails.
* Practical involvement in incident management and post‑incident review processes.
* Demonstrable delivery of policy‑as‑code and compliance‑as‑code in regulated environments.


Behaviours

* Strategic thinker with the ability to influence and shape technology decisions.
* Empowers and develops others, creating a supportive, growth‑focused team environment.
* Outcome‑oriented, maintaining balance between security, speed and reliability.
* Collaborative and influential, building trust across diverse teams.
* Continuous improvement mindset, simplifying and enhancing engineering practices.
* Calm under pressure, particularly during incidents or complex challenges.
* Visible champion for modern engineering ways of working and DevSecOps adoption.


What's in it for you?

* Annual discretionary bonus scheme
* 25 days standard annual leave + bank holidays + rising 1 day per year of service to a maximum of 30 days
* Holiday trading scheme allowing the ability to buy and sell additional annual leave days
* Matching employer pension contribution (up to 10% per annum)
* Colleague mortgage (conditions apply)
* Salary sacrifice scheme for hybrid & electric car
* A commitment to training and development
* Private medical insurance for all our colleagues
* 3 paid volunteering days per annum
* Diverse and inclusive colleague networks available for you to join including our Carers and Pride Alliance groups
* We care about your health and wellbeing - we provide a range of benefits that support this including cycle to work initiative and discounted gym membership
#J-18808-Ljbffr

Apply
Create E-mail Alert
Job alert activated
Saved
Save
Similar job
Devsecops capability manager
Skipton
Skipton Building Society
Capability manager
Similar job
Devsecops capability manager
Skipton
Skipton Building Society
Capability manager
See more jobs
Similar jobs
It jobs in Skipton
jobs Skipton
jobs North Yorkshire
jobs England
Home > Jobs > It jobs > Capability manager jobs > Capability manager jobs in Skipton > DevSecOps Capability Manager

About Jobijoba

  • Career Advice
  • Company Reviews

Search for jobs

  • Jobs by Job Title
  • Jobs by Industry
  • Jobs by Company
  • Jobs by Location
  • Jobs by Keywords

Contact / Partnership

  • Contact
  • Publish your job offers on Jobijoba

Legal notice - Terms of Service - Privacy Policy - Manage my cookies - Accessibility: Not compliant

© 2026 Jobijoba - All Rights Reserved

Apply
Create E-mail Alert
Job alert activated
Saved
Save