35 hours per week
Fri, 12 Jun 2026
As ourDevSecOpsCapability Manager,you’lllead and scale Skipton’sDevSecOpscapability to enable fast,safeand compliant software delivery across our product and platform teams. You will be accountable for embeddingsecurebydesignprinciples, modern automation practices, andpolicyascodeinto our CI/CD ecosystem, ensuring that our engineering teams can deliverhighqualitychange with confidence.
You will drive improvements in lead time, deployment frequency, change failure rate and system reliability, all measured through our Engineering Scorecard. This role blends technical strategy, leadership, governance andhandsoncapability development to strengthen our engineering foundations and support delivery of the Society’s Corporate Plan.
What will you be doing?
Value, Flow & Quality
Owning lead time for changes anddeploymentfrequencyoutcomes across shared pipelines and platforms.
Publishing DORA and flow metrics monthly, using them to drive targeted improvements.
Removing delivery bottlenecks through automation andpolicyascode, includingtrunkbaseddevelopment, automated approvals forlowriskchanges, canary/bluegreendeployment andautorollback
Triggering “scorecard → investment” actions when performance thresholds are breached to restore flow,qualityand reliability.
Leadership & Capability Development
Leading, coaching and developing a team of 3–5DevSecOpsEngineers.
Defining and maintainingDevSecOpsstandards,patternsand best practices across engineering teams.
Building ahighperformingengineering culture focused on security,automationand continuous improvement.
Strategy, Governance & Technical Direction
Setting the strategy forDevSecOpscapabilities, including pipeline standardisation and security automation.
Establishing governance for secure CI/CD,infrastructureascodeand cloud delivery.
Defining and enforcing Observability Minimum Standards including tracing, SLOs,releaselinkedannotations and dashboards.
Mandatingsecurityinthepipeline, including secrets protection, SAST/SCA/DAST,IaCscanning and WAF coverage for external apps.
Governing Golden Path (ProdOS) templates,patternsand adoption levels.
Operational Oversight & Risk Management
Overseeing the reliability, performance and security posture of pipelines,platformsand engineering tooling.
Ensuring effective vulnerability management, including remediation tracking and escalation.
Providing leadership during incidents andpostincidentreviews, improving MTTR androotcauseclarity.
Integrating telemetry across Azure, Defender, Entra and WAF to unify our security posture.
Using SLO/errorbudgetsignals and observability insights to inform go/nogoand rollback decisions.
Collaboration Across Technology & Business
Acting as a senior advisor to Engineering Managers, ProductOwnersand Cyber Security teams.
Ensuring strong alignment on security requirements, deliveryprocessesand adoption of modern practices.
RepresentingDevSecOpsacross governance forums and contributing totechnologywidedecisions.
Acting as a visible advocate for safe, rapid delivery and sharing best practice internally and externally.
Tooling, Automation & Platform Optimisation
Leading decisions onDevSecOpstooling, including evaluation and lifecycle management.
Driving automation across testing, security scanning, deployment,monitoringand compliance.
Partnering with Cloud and Platform Engineering to ensure scalable,resilientand consistentDevSecOpsecosystems.
Owning the Golden Path service catalogue, including pipelines,IaCmodules and secure defaults.
Business Continuity & Operational Resilience
Embedding BCP andoperationalresiliencecontrols directly aspolicyascode
Ensuring pipelines produceauditreadyevidence for regulated environments.
Running periodic gamedays with Release & Environments teams tovalidaterecoverability.
What do we need from you?
Knowledge, skills & experience
Strong leadership andpeoplemanagementexperience, particularly coaching senior engineers.
Deepexpertisein CI/CD design,automationand security integration.
Strong understanding of cloud platforms, containerisation,infrastructureascodeand modern delivery patterns.
Demonstrated ability to address and remediate security risks at scale.
Excellent communication and influencing skills across technical and nontechnical audiences.
Proventrack recordof improving DORA and flow metrics through automation and modern engineering practices.
Experience defining observability standards and implementing unified dashboards.
Extensive experience in DevOps, securityengineeringor platform engineering within complex or regulated environments.
Strong working knowledge of automated security tooling (SAST, SCA, DAST, secrets scanning, container scanning).
Experience in cloud security,identityand access management,zerotrustprinciples and platform guardrails.
Practical involvement in incident management andpostincidentreview processes.
Demonstrable delivery ofpolicyascodeandcomplianceascodein regulated environments.
Behaviours
Strategic thinker with the ability to influence and shape technology decisions.
Empowers and develops others, creating a supportive,growthfocusedteam environment.
Outcomeoriented,maintainingbalance between security,speedand reliability.
Collaborative and influential, building trust across diverse teams.
Continuousimprovement mindset, simplifying and enhancing engineering practices.
Calm under pressure, particularly during incidents or complex challenges.
Visible champion for modern engineering ways of working andDevSecOpsadoption.
Who are we?
Not just another building society. Not just another job.We’rethe fourth biggest building society in the UK and what makes us a bit different is thatwe'rea mutual organisation. Wedon'thave shareholders;we'reowned by our members.
Our colleagues say Skipton'sa great placeto work, and you could be one of them, bringing with younew ideason how we can keep customers at the heart of what we do. Whatever your background, and whatever your goals,we'llhelp you take the next step towards a better future.
What’sin it for you?
Skipton values work/life balance and we are proud to support hybrid and flexible working, where possible. We have a newly refurbished head office which offers a vibrant and collaborative working space.
We have a range of other benefits available to you including:
Annual discretionary bonus scheme
25 days standard annual leave + bank holidays + rising 1 day per year of service to a maximum of 30 days
Holiday trading scheme allowing the ability to buy and selladditionalannual leave days
Matching employer pension contribution (up to 10% per annum)
Colleague mortgage (conditions apply)
Salary sacrifice scheme for hybrid & electric car
A commitment to training and development
Private medical insurance for all our colleagues
3 paid volunteering days per annum
Diverse and inclusive colleague networks available for you to join including our Carers and Pride Alliance groups
We care about your health and wellbeing – weprovidea range of benefits that support this including cycle to work initiative and discounted gym membership

Founded on Fairness.
Fairness in what we provide to members, fairness in what we stand for in Society and fairness is what we deliver to our colleagues.
We started 172 years ago with a clear purpose, to build a better society. And that’s what our colleagues work to do every day. We help more people have a home, save for life ahead and support long-term financial wellbeing, whether that’s from our head office at The Bailey in Skipton or our branch network across the country.
And we’re more than just a building society. We head up Skipton Group, a collection of companies stretching from Aberdeen, UK to Auckland, NZ. Together we’re 90 brands. 18,000 people. 1,300 branches. 1.2million building society members. £37bn total assets. All pushing together to help policymakers make better decisions, and help society address the needs of the hardest hit.
So, if you want to become a member of somewhere that’s driving change all while keeping community at its core and fairness in its foundation, get in touch.