IT & Software

Principal Security Architect — DevSecOps (Group Manager II - Information Security)

UST Global

Nottingham · Nottinghamshire · United Kingdom

Overview

In this senior, hands-on role you embed security across the engineering lifecycle for UST FinX’s cloud-native banking transformation platform. You design secure patterns, automate controls, and guide developers to build secure platforms by default. You balance security with delivery speed and resilience while collaborating across pods and time zones. You shape the security baseline in a fast-evolving, AI-assisted environment.

Responsibilities
  • Define and evolve the DevSecOps strategy for the cloud-native banking platform
  • Embed security across the SDLC—from design to incident response
  • Design and implement automated security controls across CI/CD, infrastructure provisioning, container workloads, Kubernetes, and cloud services
  • Integrate SAST, DAST, SCA, container and secrets scanning, and policy-as-code
  • Define secure engineering standards and reusable guardrails for rapid yet safe delivery
  • Apply cloud-native security patterns (IAM, least privilege, zero trust, runtime security) and ensure auditability
  • Guide secure architecture for APIs, microservices, event-driven systems, and SaaS integrations
  • Partner with platform, backend, DevOps, QA, product, and delivery teams to bake in security
  • Mentor engineers through design reviews, threat modeling, and code/pipeline reviews
  • Ensure production systems are secure, observable, resilient, and compliant for regulated banking
Key requirements
  • 8+ years in software, security, cloud security, DevSecOps, or platform engineering (10–15 years ideal) with production platform ownership
  • Strong software engineering background capable of reading code and understanding CI/CD, automation, and runtime behavior
  • Proven experience securing cloud-native platforms in production
  • Deep secure-SDLC knowledge (design, coding, threat modeling, automated testing, release controls)
  • Experience integrating SAST, DAST, and SCA into automated CI/CD workflows
  • Container security expertise (image scanning, registry controls, runtime config)
  • Kubernetes security (cluster hardening, RBAC, policies, secrets, pod security)
  • Policy-as-code (OPA, Gatekeeper, Kyverno)
  • IAM, least privilege, zero trust, workload identity, service-to-service authentication
  • Secrets management, SaaS integrations security, and platform architectures
  • CI/CD security automation, artifact integrity, deployment guardrails
  • Production security practices (reliability, auditing, monitoring, incident response)
  • Strong communication and mentoring skills
  • Comfort working in a global, distributed organization
  • strong communication
  • mentoring and technical leadership
  • collaboration across cross-functional teams
  • Cloud security and cloud-native platforms
  • Secure SDLC and threat modeling
  • SAST/DAST/SCA and software supply chain security

Reference: WJ-747_30378252

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.