Overview
We are seeking an experienced DevSecOps & Governance Architect to shape secure engineering and platform architecture within a complex, security-focused enterprise environment. The successful candidate will collaborate across DevSecOps, platform engineering, cyber security, and enterprise architecture, translating security policies into practical, automated engineering patterns. This remote position requires active SC clearance and a strong understanding of modern software delivery, ensuring that security measures enhance rather than hinder developer productivity.
Responsibilities
- Define target and transitional architectures for enterprise DevSecOps and engineering platforms.
- Design secure software supply-chain approaches, including vulnerability scanning and secrets detection.
- Establish architectural patterns across CI/CD, artefact repositories, and containerised environments.
- Implement identity, SSO, RBAC, logging, and auditing controls.
- Introduce policy-as-code and automated security enforcement into engineering workflows.
- Assess vendor platforms and tooling against architectural and security requirements.
- Develop reusable reference architectures and patterns for scalability across teams.
- Facilitate architecture workshops and support technical decision-making with stakeholders.
Requirements
- Proven experience in enterprise DevSecOps and/or platform architecture.
- Strong understanding of secure software supply chains and modern software delivery practices.
- Experience with CI/CD architecture and engineering tooling.
- Familiarity with SCA, vulnerability management/scanning, and secrets detection.
- Knowledge of SBOMs, software signing, and provenance.
- Understanding of artefact repositories and container platforms.
- Experience with identity management, SSO, and RBAC.
- Ability to translate cyber/security policies into practical engineering controls.