Principal Security Architect — DevSecOps

UST Global

Nottingham

Hybrid

GBP 39,000 - 79,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

UST Global is hiring a Principal Security Architect - DevSecOps to embed security across our cloud-native banking platform. You will drive security throughout design, build, test, deployment, and operations, shaping guardrails and patterns with global teams.

The role demands leadership in secure engineering, policy-as-code, and production readiness, with emphasis on IAM, zero trust, and SCA/DAST integration across CI/CD pipelines and cloud services.

Qualifications

  • 8+ years in software, security, cloud security, DevSecOps, or platform engineering.
  • Strong software engineering background with code review and CI/CD knowledge.
  • Proven experience securing cloud-native platforms in production.
  • Deep knowledge of secure SDLC, threat modeling, automated testing, and risk controls.
  • Experience integrating SAST/DAST/SCA into CI/CD workflows.
  • Kubernetes security experience including RBAC, policies, network policies, and runtime protection.
  • Knowledge of IAM, least privilege, zero trust, and workload identity.
  • Experience with policy-as-code tools like OPA, Gatekeeper, or Kyverno.
  • Experience with secrets management, data protection, and auditability.
  • Preferred: AWS security, EKS, IaC security, GitOps, software supply-chain security, observability.

Responsibilities

  • Define and evolve the DevSecOps strategy for our cloud-native banking transformation platform.
  • Embed security across the SDLC, including design, coding, build, test, deployment, runtime, monitoring, and incident response.
  • Design and implement automated security controls across CI/CD pipelines, infrastructure provisioning, application delivery, container images, Kubernetes, and cloud services.
  • Integrate and operationalize SAST, DAST, SCA, container scanning, secrets scanning, and policy-as-code.
  • Define secure engineering standards and reusable guardrails that help teams move quickly within approved boundaries.
  • Apply cloud-native security patterns for IAM, network segmentation, workload identity, secrets management, least privilege, zero trust, runtime security, and auditability.
  • Guide secure architecture for APIs, microservices, event-driven systems, SaaS integrations, and developer tooling.
  • Partner with platform, backend, DevOps, QA, product, and delivery teams to build security into delivery.
  • Mentor engineers through design reviews, threat modeling, code and pipeline reviews, and pairing.
  • Ensure production systems are secure, observable, resilient, compliant, and ready for regulated banking.
  • Work with CTO to define standards, identify gaps, improve delivery quality, and reflect architecture in production code and practices.
  • Influence multiple teams, establish reusable standards, mentor leaders, and turn technical direction into production-ready execution.

Skills

Security engineering
Cloud security
DevSecOps
Platform ownership
CI/CD
Threat modeling
SAST/DAST/SCA
Kubernetes security
IAM/zero trust
Secrets management

Tools

AWS
Kubernetes
Terraform
GitOps
OPA
Gatekeeper
Kyverno
OpenTelemetry
Prometheus
CloudWatch
Secrets vault

Job description

Salary: £39,000 - 79,000 per year

Requirements
  • 8+ years of experience in software, security, cloud security, DevSecOps, or platform engineering; 10-15 years is ideal, with production platform ownership.
  • Strong software engineering background, including the ability to review application code, system designs, CI/CD workflows, infrastructure automation, and runtime behavior.
  • Proven experience securing cloud-native platforms in production.
  • Deep knowledge of secure SDLC practices, including secure design and coding, threat modeling, automated testing, vulnerability and dependency management, release controls, and production readiness.
  • Practical experience integrating SAST, DAST, and SCA into CI/CD workflows.
  • Experience with container security, including image scanning, base-image strategy, registry controls, remediation, runtime configuration, and secure workload deployment.
  • Kubernetes security experience, including cluster hardening, namespace isolation, RBAC, admission control, network policies, workload identity, pod security, secrets, ingress, and runtime protection.
  • Experience with policy-as-code tools such as OPA, Gatekeeper, or Kyverno, or equivalent tools.
  • Knowledge of IAM, least privilege, zero trust, workload identity, service-to-service authentication, and identity-driven security models.
  • Experience with secrets management, including secure storage, rotation, access control, pipeline integration, runtime injection, and governance.
  • Experience securing SaaS integrations and platform architectures, including identity, access, data protection, tenant boundaries, and auditability.
  • Experience with CI/CD security automation, including pipeline hardening, artifact integrity, dependency controls, environment promotion, deployment approvals, rollback safety, and supply-chain security.
  • Production security experience, including reliability, auditability, scalability, incident response, monitoring, and remediation.
  • Strong communication skills, including the ability to explain architecture, risks, and trade-offs to globally distributed teams.
  • Technical leadership and mentoring skills to raise engineering standards without formal authority.
  • Comfort working in a global, distributed organization across multiple teams, stakeholders, and time zones.
  • Preferred: AWS security experience, including IAM, Organizations, networking, KMS, CloudTrail, GuardDuty, Security Hub, workload identity, private connectivity, and multi-account patterns.
  • Preferred: Production experience with Amazon EKS or equivalent Kubernetes platforms.
  • Preferred: IaC security experience with AWS CDK, Terraform, or CloudFormation, including static analysis, policy enforcement, and secure module design.
  • Preferred: GitOps security experience, including repository controls, signed artifacts, environment promotion, drift detection, and deployment guardrails.
  • Preferred: Software supply-chain security experience, including SBOMs, artifact signing, provenance, dependency controls, and build integrity.
  • Preferred: Observability and security monitoring experience with tools such as Prometheus, Grafana, CloudWatch, OpenTelemetry, SIEM, tracing, logging, and event correlation.
  • Preferred: API security experience, including OAuth2/OIDC, mTLS, service mesh, gateway security, rate limiting, token validation, and service-to-service authorization.
  • Preferred: Experience in financial services, banking, or regulated environments where auditability and operational control are critical.
  • Preferred: Experience building reusable security platforms, guardrails, templates, policy libraries, and paved-road patterns for multiple teams.
  • Preferred: Experience supporting, patching, auditing, scaling, migrating, and evolving secure platforms after adoption.
Responsibilities
  • Define and evolve the DevSecOps strategy for our cloud-native banking transformation platform.
  • Embed security across the SDLC, including design, coding, build, test, deployment, runtime, monitoring, and incident response.
  • Design and implement automated security controls across CI/CD pipelines, infrastructure provisioning, application delivery, container images, Kubernetes, and cloud services.
  • Integrate and operationalize SAST, DAST, SCA, container scanning, secrets scanning, and policy-as-code.
  • Define secure engineering standards and reusable guardrails that help teams move quickly within approved boundaries.
  • Apply cloud-native security patterns for IAM, network segmentation, workload identity, secrets management, least privilege, zero trust, runtime security, and auditability.
  • Guide secure architecture for APIs, microservices, event-driven systems, SaaS integrations, and developer tooling.
  • Partner with platform, backend, DevOps, QA, product, and delivery teams to build security into delivery.
  • Mentor engineers through design reviews, threat modeling, code and pipeline reviews, and pairing.
  • Ensure production systems are secure, observable, resilient, compliant, and ready for regulated banking.
  • Work with our CTO to define standards, identify engineering gaps, improve delivery quality, and ensure architecture is reflected in production code, platforms, and operational practices.
  • Influence multiple teams, establish reusable standards, mentor technical leaders, challenge weak designs, and turn technical direction into production-quality execution.
  • Use engineering judgment to validate, refine, or reject AI-generated outputs and ensure controls are automated, observable, repeatable, and embedded.
Technologies
  • AI
  • API
  • AWS
  • Architect
  • Backend
  • CI/CD
  • Cloud
  • CloudWatch
  • CTO
  • DevSecOps
  • DevOps
  • Embedded
  • GitOps
  • Grafana
  • IAM
  • Kubernetes
  • Network
  • OpenTelemetry
  • Prometheus
  • RBAC
  • Security
  • Terraform
  • microservices
  • LESS
More

UST has worked alongside leading companies since 1999, partnering from design through operation to deliver technology-driven transformation. Headquartered in the United States, we have more than 30,000 employees in over 30 countries and focus on creating measurable value and lasting change. UST FinX brings together professionals working to help banks move beyond legacy technology constraints. We are hiring a Principal Security Architect - DevSecOps for a senior, hands-on technical leadership role focused on embedding security throughout our engineering lifecycle. The role reports directly to the CTO of UST FinX and provides technical influence across teams; it is neither a passive advisory position nor a traditional people-management role. We value integrity, humility, humanity, innovation, diversity, and inclusion, and we are an equal opportunity employer.

last updated 40 week of 2026

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Security Architect — DevSecOps (Group Manager II - Information Security)
Principal Security Architect — DevSecOps (Group Manager II - Information Security)

UST • Nottingham

On-site
GBP 90,000 - 140,000
Senior DevSecOps Security Architect – Cloud-Native Banking
Senior DevSecOps Security Architect – Cloud-Native Banking

UST Global • Nottingham

Hybrid
GBP 39,000 - 79,000
Senior DevSecOps Architect
Senior DevSecOps Architect

Hackajob Ltd • Leeds

On-site
GBP 61,000 - 101,000
Senior DevSecOps Architect
Senior DevSecOps Architect

Next Frontier Capital • Greater London

On-site
GBP 120,000 - 180,000
Senior DevSecOps Architect
Senior DevSecOps Architect

JPMorgan Chase & Co. • Greater London

On-site
GBP 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Atarus • England

On-site
GBP 70,000 - 90,000
Budget for certifications
Opportunities for continuous learning
Clear progression to Staff / Principal Security Engineer
Senior DevSecOps Engineer
Senior DevSecOps Engineer

PCN Media • Greater London

On-site
GBP 90,000 - 130,000
Principal Architect — Distributed Systems & Event Streaming (Director I - Product Architect)
Principal Architect — Distributed Systems & Event Streaming (Director I - Product Architect)

UST • Nottingham

On-site
GBP 110,000 - 140,000
Lead DevSecOps Architect — Cloud-Native Security
Lead DevSecOps Architect — Cloud-Native Security

UST • Nottingham

On-site
GBP 90,000 - 140,000
Lead Security Engineer
Lead Security Engineer

Winston Fox • Greater London

On-site
GBP 70,000 - 95,000