As our DevSecOps Capability Manager, you’ll lead and scale Skipton’s DevSecOps capability to enable fast, safe and compliant software delivery across our product and platform teams. You will be accountable for embedding securebydesign principles, modern automation practices, and policyascode into our CI/CD ecosystem, ensuring that our engineering teams can deliver highquality change with confidence.
You will drive improvements in lead time, deployment frequency, change failure rate and system reliability, all measured through our Engineering Scorecard. This role blends technical strategy, leadership, governance and handson capability development to strengthen our engineering foundations and support delivery of the Society’s Corporate Plan.
What will you be doing?
Value, Flow & Quality
Owning lead time for changes and deploymentfrequency outcomes across shared pipelines and platforms.
Publishing DORA and flow metrics monthly, using them to drive targeted improvements.
Removing delivery bottlenecks through automation and policyascode, including trunkbased development, automated approvals for lowrisk changes, canary/bluegreen deployment and autorollback.
Triggering “scorecard → investment” actions when performance thresholds are breached to restore flow, quality and reliability.
Leadership & Capability Development
Leading, coaching and developing a team of 3–5 DevSecOps Engineers.
Defining and maintaining DevSecOps standards, patterns and best practices across engineering teams.
Building a highperforming engineering culture focused on security, automation and continuous improvement.
Strategy, Governance & Technical Direction
Setting the strategy for DevSecOps capabilities, including pipeline standardisation and security automation.
Establishing governance for secure CI/CD, infrastructureascode and cloud delivery.
Defining and enforcing Observability Minimum Standards including tracing, SLOs, releaselinked annotations and dashboards.
Mandating securityinthepipeline, including secrets protection, SAST/SCA/DAST, IaC scanning and WAF coverage for external apps.
Governing Golden Path (ProdOS) templates, patterns and adoption levels.
Operational Oversight & Risk Management
Overseeing the reliability, performance and security posture of pipelines, platforms and engineering tooling.
Ensuring effective vulnerability management, including remediation tracking and escalation.
Providing leadership during incidents and postincident reviews, improving MTTR and rootcause clarity.
Integrating telemetry across Azure, Defender, Entra and WAF to unify our security posture.
Using SLO/errorbudget signals and observability insights to inform go/nogo and rollback decisions.
Collaboration Across Technology & Business
Acting as a senior advisor to Engineering Managers, Product Owners and Cyber Security teams.
Ensuring strong alignment on security requirements, delivery processes and adoption of modern practices.
Representing DevSecOps across governance forums and contributing to technologywide decisions.
Acting as a visible advocate for safe, rapid delivery and sharing best practice internally and externally.
Tooling, Automation & Platform Optimisation
Leading decisions on DevSecOps tooling, including evaluation and lifecycle management.
Driving automation across testing, security scanning, deployment, monitoring and compliance.
Partnering with Cloud and Platform Engineering to ensure scalable, resilient and consistent DevSecOps ecosystems.
Owning the Golden Path service catalogue, including pipelines, IaC modules and secure defaults.
Business Continuity & Operational Resilience
Embedding BCP and operationalresilience controls directly as policyascode.
Ensuring pipelines produce auditready evidence for regulated environments.
Running periodic gamedays with Release & Environments teams to validate recoverability.
What do we need from you?
Knowledge, skills & experience
Strong leadership and peoplemanagement experience, particularly coaching senior engineers.
Deep expertise in CI/CD design, automation and security integration.
Strong understanding of cloud platforms, containerisation, infrastructureascode and modern delivery patterns.
Demonstrated ability to address and remediate security risks at scale.
Excellent communication and influencing skills across technical and nontechnical audiences.
Proven track record of improving DORA and flow metrics through automation and modern engineering practices.
Experience defining observability standards and implementing unified dashboards.
Extensive experience in DevOps, security engineering or platform engineering within complex or regulated environments.
Strong working knowledge of automated security tooling (SAST, SCA, DAST, secrets scanning, container scanning).
Experience in cloud security, identity and access management, zerotrust principles and platform guardrails.
Practical involvement in incident management and postincident review processes.
Demonstrable delivery of policyascode and complianceascode in regulated environments.
Behaviours
Strategic thinker with the ability to influence and shape technology decisions.
Empowers and develops others, creating a supportive, growthfocused team environment.
Outcomeoriented, maintaining balance between security, speed and reliability.
Collaborative and influential, building trust across diverse teams.
Continuousimprovement mindset, simplifying and enhancing engineering practices.
Calm under pressure, particularly during incidents or complex challenges.
Visible champion for modern engineering ways of working and DevSecOps adoption.
Who are we?
Not just another building society. Not just another job. We’re the fourth biggest building society in the UK and what makes us a bit different is that we're a mutual organisation. We don't have shareholders; we're owned by our members.
Our colleagues say Skipton's a great place to work, and you could be one of them, bringing with you new ideas on how we can keep customers at the heart of what we do. Whatever your background, and whatever your goals, we'll help you take the next step towards a better future.
What’s in it for you?
Skipton values work/life balance and we are proud to support hybrid and flexible working, where possible. We have a newly refurbished head office which offers a vibrant and collaborative working space.
We have a range of other benefits available to you including:
Annual discretionary bonus scheme
25 days standard annual leave + bank holidays + rising 1 day per year of service to a maximum of 30 days
Holiday trading scheme allowing the ability to buy and sell additional annual leave days
Matching employer pension contribution (up to 10% per annum)
Colleague mortgage (conditions apply)
Salary sacrifice scheme for hybrid & electric car
A commitment to training and development
Private medical insurance for all our colleagues
3 paid volunteering days per annum
Diverse and inclusive colleague networks available for you to join including our Carers and Pride Alliance groups
We care about your health and wellbeing – we provide a range of benefits that support this including cycle to work initiative and discounted gym membership
Because your career is more than just a ladder.
In 2026, we were named as one of the Financial Times Best Employers in the UK. We were also the highest placed building society on the list, too.
Not bad, right? But it’s much more than just another opportunity to blow our own trumpet. It truly reflects how our people experience working here.
Because at Skipton, we’re a mutual. We’re founded on fairness, built on shared effort, and committed to saying it straight. We’re curious, brave and always collaborative. We look out for each other. And we treat everyone like a grown-up - with respect, with understanding, with a level playing field at their feet.
You’ll join a Technology team that’s constantly focused on real challenges. That builds products and solutions which make a genuine difference. And which gets things done for our members - at pace.
And because we’re dead keen on development, it’s a place where you’re encouraged to try out new tech, sharpen your skills, or get hands-on with AI and automation.
Learning is part of the everyday at Skipton. It’s woven into conversations and brought to life through hands-on experiences. You’ll pick up new skills as you go, and get tools and support that flex around your role and life.
Each month in Technology, we give you two days to focus on your own development. And we support certifications, apprenticeships, and training where it’s relevant, too. It’s a journey for all of us, and we’re working hard to build out a fully structured development programme. The investment is real, the intent is genuine, and most of all, we can’t wait to see where it takes you, your career, and your future.
Talent Acquisition Senior Specialist
I joined Skipton in May 2025 to lead recruitment across Tech. I specialise in hiring experts for Infrastructure, Cloud, Data, and Architecture.
At Skipton, the focus is always on people. It’s a collaborative space where you can make a real impact on transformation while being trusted to lead your own professional growth.
Once you’ve sent us your application and CV, we’ll review it using clear criteria. Our decisions are based on the skills, and experience you share with us.
Your interview might be by phone, over Microsoft Teams or in person, depending on the role and the circumstances. For some roles, there may also be more than one stage in the recruitment process - but we’ll always let you know what the plan is.
During your interview, we’ll ask you about your current and previous experience, and we’re very much interested in all of your skills and knowledge. This includes relevant things you might have learned through work, studies and voluntary activities
For some roles we could ask you to complete one or more tasks, or deliver a presentation. But don't worry, we'll support you throughout the process so you can do your best.
At Skipton we always get in touch after your interview to let you know if you’re successful, or if you’re made it through to the next stage. And if you would like feedback on your interview we are always happy to share this. It’s all part of the Skipton experience, we value the time you’ve given us throughout the process.
If you’re successful, we’ll get in touch to discuss your offer. When you accept we’ll send your contract and confirm the pre-employment checks you need to complete to get the ball rolling. You’ll need to successfully complete the checks before starting, so providing information quickly will help keep things on track. We aim to keep things simple and easy to follow.
You’re in - welcome to the team!
We’ll be in touch regularly right up to your first day with lots of exciting info, details of what to expect when you’re here, and hints and tips to help you prepare for a great start.
And when it comes to the big day, there’ll be a warm welcome waiting for you as you begin your journey with us.