Haystack
← Back to Jobs
Remote
Temporary/Casual
Technology
XC

DevSecOps Architect

XcedeSouth East London, London🇬🇧United KingdomPosted 5 Sept 2026

Why This Role Stands Out

This remote DevSecOps Architect role offers a significant opportunity to shape enterprise-level security and governance within a major technology transformation. You will thrive here if you possess strong architectural skills and a passion for building secure, scalable software supply chains, and you're encouraged to apply to make a substantial impact.

Quick Overview

Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
Remote
Location
South East London, London, United Kingdom
Posted
13 hours ago
SSOKubernetesStakeholder Management

Job Description

DevSecOps & Governance Architect
Location: London / Manchester Mainly Remote
Contract:4-6 months initial contract, with potential for extension
Clearance: Active SC Clearance required
Start:October 2026

We are looking for an experienced DevSecOps & Governance Architect to support a major enterprise technology transformation programme within a large UK public sector organisation.

This is a senior architecture role focused on helping define and establish an enterprise DevSecOps and platform capability, balancing strong security and governance requirements with developer productivity and practical engineering needs.

You will be responsible for defining target and transitional architectures, establishing governance frameworks and creating reusable technical patterns that can be adopted across multiple teams and domains.

You'll work closely with security, architecture, engineering, delivery and business stakeholders, translating organisational risk and policy into practical DevSecOps solutions.

Key Responsibilities
  • Define target and transitional DevSecOps/platform architectures
  • Design secure software supply-chain capabilities covering SCA, vulnerability scanning, secrets detection, SBOMs, software signing and provenance
  • Develop architecture patterns across CI/CD, artefact repositories, containers and runtime provisioning
  • Define identity, SSO, RBAC, logging and auditable security controls
  • Establish policy-as-code and automated security enforcement
  • Assess and advise on vendor solutions and deployment options
  • Define approved, controlled and unsupported technology usage patterns
  • Design governance, exception handling and risk-acceptance mechanisms
  • Create reusable reference architectures and patterns that can scale across multiple domains
  • Facilitate architecture workshops and technical decision-making
  • Ensure solutions align with enterprise architecture and security obligations
  • Balance security controls with developer experience and engineering productivity
We're looking for someone with strong experience across DevSecOps, Platform Engineering and Security/Enterprise Architecture, ideally within large or highly regulated organisations.

You'll need:
  • Strong enterprise DevSecOps and platform architecture experience
  • Excellent understanding of secure software supply chains
  • Strong knowledge of CI/CD, containers and Kubernetes
  • Experience with SCA, vulnerability management, secrets management and SBOMs
  • Knowledge of policy-as-code and automated security controls
  • Experience with identity, SSO, RBAC and security governance
  • Strong architecture documentation and reference-pattern experience
  • Experience translating security policy and risk into practical engineering solutions
  • Excellent stakeholder management and workshop facilitation skills
  • The ability to influence across Security, Architecture, Engineering and Delivery
  • Knowledge of DSPT, CAF or similar security/assurance frameworks would be highly beneficial
  • Active SC Clearance is essential
The role is predominantly remote, with occasional site visits required in London and/or Manchester.

This is an opportunity to play a key role in shaping an enterprise DevSecOps capability, with a strong combination of architecture, security, governance and platform engineering.

If you're an SC-cleared DevSecOps, Platform, Cloud Security or Enterprise Architect looking for your next contract, we'd be keen to hear from you.

Similar jobs