IT & Software

DevSecOps Architect

Xcede Limited

London · England · United Kingdom

DevSecOps & Governance Architect

Location: London / Manchester – Mainly Remote
Contract: 6 months initial Inside IR35
Clearance: Active SC Clearance Required
Start Date: Targeting late September / October 2026

About the Role

We are seeking an experienced DevSecOps & Governance Architect to join a critical enterprise technology transformation programme within a major UK public sector organisation.

The role will focus on helping shape and establish an enterprise DevSecOps platform capability , defining the architecture, governance, security controls and engineering practices required to enable development teams to work securely and consistently at scale.

The programme is currently moving through a discovery and shaping phase , so the successful candidate will have the opportunity to influence the direction of the platform rather than simply implement a fully defined solution.

The customer is particularly looking for someone who has built and shaped DevSecOps platforms before , can demonstrate what good looks like, and can provide practical recommendations around architecture, governance, security and platform adoption.

A key area of focus will be understanding and establishing the right approach to enterprise package and binary management , with technologies such as JFrog Artifactory currently being considered as part of the wider platform capability.

Key Responsibilities

  • Shape and define the target and transitional architecture for an enterprise DevSecOps platform.
  • Lead and contribute to the discovery phase , helping establish the technical scope, architecture and future operating model.
  • Help the customer understand the key DevSecOps platform pillars , capabilities and best practices required within an enterprise environment.
  • Define appropriate approaches to software package, dependency and binary management across the organisation.
  • Assess and provide recommendations on technologies and enterprise solutions, including JFrog Artifactory and comparable platforms.
  • Design secure and scalable approaches across CI/CD, source control, artefact repositories and wider platform integrations .
  • Define appropriate security, governance and control mechanisms that can be embedded into the DevSecOps platform.
  • Establish approaches for identity, access control, RBAC, logging, auditability and security enforcement .
  • Develop reusable architecture patterns, standards and reference architectures that can be adopted by development teams.
  • Work with security, architecture, engineering and delivery stakeholders to understand requirements and translate them into practical technical solutions.
  • Facilitate architecture and discovery workshops and support technical decision-making.
  • Assess existing capabilities and identify gaps, risks and opportunities for improvement.
  • Provide recommendations around platform ownership, governance and operational responsibilities as the future model develops.
  • Ensure DevSecOps governance and security controls support developer productivity while maintaining appropriate enterprise standards.
  • Provide architectural leadership and guidance throughout the wider programme.

Essential Experience

  • Significant experience working as a DevSecOps, Platform, Cloud, Security or Enterprise Architect .
  • Proven experience designing, building or shaping enterprise DevSecOps platforms .
  • Strong understanding of DevSecOps principles, platform engineering and secure software delivery .
  • Experience establishing governance, security controls and best-practice patterns within enterprise DevSecOps environments.
  • Strong understanding of CI/CD, source control, artefact/package management and modern software delivery platforms .
  • Hands‑on experience with enterprise package, dependency or binary management .
  • Experience with JFrog Artifactory or an equivalent enterprise artefact/package management solution .
  • Ability to work effectively through discovery, ambiguity and evolving requirements , helping define the technical direction rather than relying on a fully established specification.
  • Strong understanding of how DevSecOps platforms integrate with wider enterprise technology ecosystems .
  • Ability to assess technology options and provide clear, pragmatic recommendations to technical and non-technical stakeholders.
  • Strong stakeholder management and communication skills, with the ability to work across Architecture, Security, Engineering, Development and Delivery .
  • Experience creating architecture standards, reference patterns and governance frameworks .
  • Strong workshop facilitation and technical decision-making skills.
  • Active SC Clearance is essential.

Desirable Experience

  • Experience working within UK Government, public sector or other highly regulated environments .
  • Experience establishing DevSecOps capabilities within a large-scale enterprise.
  • Experience with JFrog / Artifactory and enterprise software supply-chain management.
  • Knowledge of software supply-chain security, dependency management and vulnerability management.
  • Experience with technologies such as GitHub/GitLab, Kubernetes, cloud platforms, CI/CD tooling and security tooling .
  • Experience defining platform operating models, ownership models and governance structures .
  • Previous experience supporting the transition from developer-level package/dependency management towards a centrally governed enterprise solution .

The Ideal Candidate

The ideal candidate will have genuine experience building or shaping enterprise DevSecOps platforms and be comfortable operating at the intersection of Platform Engineering, Security, Governance and Architecture .

We're not simply looking for someone who can produce architecture diagrams. The customer needs someone who has been through this before , understands the challenges of establishing DevSecOps capabilities within a large enterprise, and can confidently recommend what good looks like.

You'll be comfortable working in an environment where some requirements are still being defined, using your previous experience to guide discovery, challenge assumptions, shape the platform architecture and establish practical governance and engineering patterns .

Experience with enterprise package and binary management, particularly JFrog Artifactory or similar platforms , will be highly relevant as this is expected to be an important area of the discovery and future platform capability.

#J-18808-Ljbffr

Reference: WJ-766_21914589

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.