Enable job alerts via email!

Devsecops Architect / Consultant - Outside IR35

Experis

Tyseley

Hybrid

GBP 70,000 - 90,000

Full time

Today
Be an early applicant

Job summary

A leading tech consultancy is seeking a Senior DevSecOps Architect / Consultant to lead cloud security governance and architecture across multiple platforms including Microsoft Azure and AWS. The ideal candidate will define security standards, ensure compliance, and engage with internal teams to improve practices. This is a hybrid role located in Tyseley, UK, requiring a flexible schedule.

Qualifications

  • Experience leading governance, architecture guidance, and assurance for cloud and infrastructure security.
  • Familiarity with Cyber Essentials Plus, ISO 27001, and Zero Trust principles.
  • Excellent written communication and facilitation skills.

Responsibilities

  • Define multi-cloud security standards and reference blueprints.
  • Own security architecture patterns and contribute to various documentation.
  • Chair Cloud & Platform Security design reviews.

Skills

Blueprint catalogues experience
Containers/Kubernetes policy models
Azure Policy/Initiatives knowledge
AWS Control Tower experience
Security & Monitoring with Microsoft Sentinel
Documentation & Governance knowledge
Job description

Outside IR35, Senior DevSecOps Architect / Consultant, hybrid, ISO 27001

My client is looking for a Senior DevSecOps Architect / Consultant to lead governance, architecture guidance, and assurance for cloud and infrastructure security across Microsoft Azure, AWS, and key SaaS platforms. This is a hybrid role, so you need to be flexible to attend meetings and workshops.

This role is pivotal in defining technical blueprints, setting security standards, and ensuring regulatory compliance with Cyber Essentials Plus, ISO 27001, and Zero Trust principles. You will work closely with IT and platform teams to embed best practices, validate implementations, and support audit readiness across IaaS, PaaS, and SaaS environments.

Responsibilities
  • Define and maintain multi-cloud security standards and reference blueprints (e.g. Azure Policy/Initiatives, AWS Control Tower/SCPs)
  • Own security architecture patterns and contribute to HLD/LLD, threat models, and risk assessments
  • Set assurance criteria and control evidence requirements for internal teams and third-party vendors
  • Establish policy-as-code requirements and maintain an exceptions register with expiry and risk ownership
  • Define identity and access control standards (Entra ID Conditional Access, MFA, PIM; AWS IAM federation)
  • Govern SaaS security onboarding (SSO, OAuth governance, DLP controls, vendor assessments)
  • Specify telemetry and logging requirements for Microsoft Sentinel/SOC and review analytics/reporting
  • Lead compliance mapping for ISO 27001 and curate audit-ready evidence packs
  • Chair Cloud & Platform Security design reviews and participate in CAB for risk appraisal
  • Strong regulatory sector experience
  • Educate and influence teams through guidance, clinics, and coaching sessions
  • Familiarity with IaaS, PaaS, SaaS risk models and audit frameworks
  • Excellent written communication and facilitation skills to drive adoption and influence stakeholders
Required Skills
  • Experience with blueprint catalogues and architecture governance processes
  • Working knowledge of containers/Kubernetes (AKS/EKS) policy models
  • Azure: Policy/Initiatives, Defender for Cloud, Entra ID, PIM
  • AWS: Control Tower, SCPs, Security Hub, GuardDuty, IAM
  • Security & Monitoring: Microsoft Sentinel (KQL), Defender XDR, audit dashboards
  • Documentation & Governance: Blueprint repositories, risk registers, ITSM/CAB records

If this role sounds of interest please send me your cv for review ASAP

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.