Job Title: DevSecOps Security Consultant Location: Sheffield or Birmingham (hybrid - 3 days per week) Salary/Rate: (Apply online only) per day inside IR35 Start Date: May Job Type: Initial contract until 18/05/2027 Company Introduction We have an exciting opportunity now available with one of our sector-leading consultancy clients! They are currently looking for a skilled DevSecOps Security Consultant to join their client at a Tier 1 bank in either Sheffield or Birmingham on a hybrid basis. Job Responsibilities/Objectives We are seeking a highly skilled and experienced Senior Cybersecurity SME / Consultant to join the Engineering Excellence and Enablement team. The successful candidate will work across global engineering platforms to benchmark, uplift, and continuously evolve cybersecurity maturity. The successful candidate will play a critical role in ensuring that build systems, runtime infrastructure, and developer tooling are secure by design, while enabling rapid and resilient software delivery across the bank. This role offers a unique opportunity to shape the cybersecurity posture of engineering platforms at one of the world?s leading financial institutions, ensuring the bank can deliver digital services securely, reliably, and at scale. Framework and Assessment Develop and maintain an Engineering-Platform Cybersecurity Maturity Framework to standardise assessments across platforms. Conduct comprehensive platform security reviews (build systems, CI/CD pipelines, runtime infrastructure, developer tooling) against defined framework criteria. Perform threat modelling and gap analysis, identifying vulnerabilities and systemic risks impacting source code, artifacts, and workloads. Engineering Platform Security Enablement Establish standardised secure architecture and engineering patterns for build systems, CI/CD pipelines, runtime environments, and developer tooling. Define and enforce platform security baselines using policy-as-code and automated controls. Partner with platform owners to remediate critical gaps and implement scalable solutions for artifact integrity, access control, and configuration security. Integrate vulnerability management, SBOM, provenance, and code-signing practices within engineering workflows. Roadmap Development & Execution Prioritise identified gaps based on business risk, regulatory impact, and operational criticality. Collaborate with platform owners and engineering leads to build actionable security roadmaps, balancing quick wins with long-term strategic improvements. Partner with engineering teams to design, develop, and embed security patterns and best practices into engineering platforms. Stakeholder Engagement & Governance Serve as a trusted advisor to platform owners, senior technology stakeholders, and Cybersecurity leadership, translating technical risks into business impact. Represent the function in key governance forums, providing updates on maturity progress, roadmap delivery, and risk posture. Influence and align stakeholders across federated engineering teams to ensure consistent adoption of cybersecurity best practices. Continuous Improvement Track and report maturity scores, ensuring measurable improvement across platforms. Continuously evolve the maturity framework in response to emerging threats, technology evolution, and regulatory expectations. Drive a culture of secure-by-design engineering through engagement, advocacy, and knowledge sharing. Required Skills/Experience The ideal candidate will have the following: Proven expertise in Cybersecurity within large-scale, regulated financial institutions or similarly complex environments. Deep technical knowledge of engineering platforms, including CI/CD systems, build tools, artifact repositories, runtime environments, and developer tooling. Strong experience with DevSecOps practices, including secure pipeline design, integration of security scanning tools, and automation of security controls. Strong knowledge and understanding of service mesh, cryptography, network security, application security, vulnerability management, and risk management. Demonstrable ability to conduct threat modelling, platform security assessments, and gap analysis. Experience building and implementing maturity models, frameworks, or roadmaps in complex enterprise environments. Strong stakeholder management skills, with the ability to influence senior leadership and drive change across federated technology teams. Excellent communication skills, with the ability to translate technical risk into business impact. Desirable Skills/Experience Although not essential, the following skills are desired by the client: Professional certifications such as CISSP, CISM, CCSK, CCSP, or equivalent. Hands-on knowledge of cloud security (AWS, Azure, GCP) and container orchestration platforms (e.g., Kubernetes). Experience in international and diverse environments, with exposure to regulatory engagement. Familiarity with engineering excellence practices such as SLSA, supply chain security, SBOM, or secure developer tooling initiatives. If you are interested in this opportunity, please apply now with your updated CV in Microsoft Word/PDF format. Disclaimer Notwithstanding any guidelines given to level of experience sought, we will consider candidates from outside this range if they can demonstrate the necessary competencies. Square One is acting as both an employment agency and an employment business, and is an equal opportunities recruitment business. Square One embraces diversity and will treat everyone equally. Please see our website for our full diversity statement.
May 21, 2026
Contractor
Job Title: DevSecOps Security Consultant Location: Sheffield or Birmingham (hybrid - 3 days per week) Salary/Rate: (Apply online only) per day inside IR35 Start Date: May Job Type: Initial contract until 18/05/2027 Company Introduction We have an exciting opportunity now available with one of our sector-leading consultancy clients! They are currently looking for a skilled DevSecOps Security Consultant to join their client at a Tier 1 bank in either Sheffield or Birmingham on a hybrid basis. Job Responsibilities/Objectives We are seeking a highly skilled and experienced Senior Cybersecurity SME / Consultant to join the Engineering Excellence and Enablement team. The successful candidate will work across global engineering platforms to benchmark, uplift, and continuously evolve cybersecurity maturity. The successful candidate will play a critical role in ensuring that build systems, runtime infrastructure, and developer tooling are secure by design, while enabling rapid and resilient software delivery across the bank. This role offers a unique opportunity to shape the cybersecurity posture of engineering platforms at one of the world?s leading financial institutions, ensuring the bank can deliver digital services securely, reliably, and at scale. Framework and Assessment Develop and maintain an Engineering-Platform Cybersecurity Maturity Framework to standardise assessments across platforms. Conduct comprehensive platform security reviews (build systems, CI/CD pipelines, runtime infrastructure, developer tooling) against defined framework criteria. Perform threat modelling and gap analysis, identifying vulnerabilities and systemic risks impacting source code, artifacts, and workloads. Engineering Platform Security Enablement Establish standardised secure architecture and engineering patterns for build systems, CI/CD pipelines, runtime environments, and developer tooling. Define and enforce platform security baselines using policy-as-code and automated controls. Partner with platform owners to remediate critical gaps and implement scalable solutions for artifact integrity, access control, and configuration security. Integrate vulnerability management, SBOM, provenance, and code-signing practices within engineering workflows. Roadmap Development & Execution Prioritise identified gaps based on business risk, regulatory impact, and operational criticality. Collaborate with platform owners and engineering leads to build actionable security roadmaps, balancing quick wins with long-term strategic improvements. Partner with engineering teams to design, develop, and embed security patterns and best practices into engineering platforms. Stakeholder Engagement & Governance Serve as a trusted advisor to platform owners, senior technology stakeholders, and Cybersecurity leadership, translating technical risks into business impact. Represent the function in key governance forums, providing updates on maturity progress, roadmap delivery, and risk posture. Influence and align stakeholders across federated engineering teams to ensure consistent adoption of cybersecurity best practices. Continuous Improvement Track and report maturity scores, ensuring measurable improvement across platforms. Continuously evolve the maturity framework in response to emerging threats, technology evolution, and regulatory expectations. Drive a culture of secure-by-design engineering through engagement, advocacy, and knowledge sharing. Required Skills/Experience The ideal candidate will have the following: Proven expertise in Cybersecurity within large-scale, regulated financial institutions or similarly complex environments. Deep technical knowledge of engineering platforms, including CI/CD systems, build tools, artifact repositories, runtime environments, and developer tooling. Strong experience with DevSecOps practices, including secure pipeline design, integration of security scanning tools, and automation of security controls. Strong knowledge and understanding of service mesh, cryptography, network security, application security, vulnerability management, and risk management. Demonstrable ability to conduct threat modelling, platform security assessments, and gap analysis. Experience building and implementing maturity models, frameworks, or roadmaps in complex enterprise environments. Strong stakeholder management skills, with the ability to influence senior leadership and drive change across federated technology teams. Excellent communication skills, with the ability to translate technical risk into business impact. Desirable Skills/Experience Although not essential, the following skills are desired by the client: Professional certifications such as CISSP, CISM, CCSK, CCSP, or equivalent. Hands-on knowledge of cloud security (AWS, Azure, GCP) and container orchestration platforms (e.g., Kubernetes). Experience in international and diverse environments, with exposure to regulatory engagement. Familiarity with engineering excellence practices such as SLSA, supply chain security, SBOM, or secure developer tooling initiatives. If you are interested in this opportunity, please apply now with your updated CV in Microsoft Word/PDF format. Disclaimer Notwithstanding any guidelines given to level of experience sought, we will consider candidates from outside this range if they can demonstrate the necessary competencies. Square One is acting as both an employment agency and an employment business, and is an equal opportunities recruitment business. Square One embraces diversity and will treat everyone equally. Please see our website for our full diversity statement.
Gillespie Recruitment Ltd
Newcastle Upon Tyne, Tyne And Wear
Are you a senior-level Full Stack Developer who thrives on solving complex problems and turning innovative ideas into powerful, real-world applications? Do you enjoy working with Python at scale, shaping user-focused web platforms, and having genuine influence over technical direction and product development? Looking for a permanent opportunity where your expertise is valued, your voice is heard, and you can help build cutting-edge tools within a growing, purpose-driven organisation? Gillespie Recruitment are delighted to be working on behalf of an innovative and rapidly scaling technology business to recruit an experienced Senior Python Full Stack Developer based in Newcastle upon Tyne. This is an exciting opportunity to join a forward-thinking organisation developing world-leading tools, where collaboration, flexibility, and technical excellence sit at the heart of everything they do. The Role As Senior Python Full Stack Developer, you'll be a key member of the Full Stack Development team, working closely with the Lead Full Stack Developer to bring sophisticated engineering tools to life through intuitive, high-performance web applications. You'll be involved across the full software lifecycle - from system architecture and cloud design through to development, deployment, and optimisation. Alongside hands-on development, you'll play an important role in mentoring junior colleagues, shaping future R&D initiatives, and contributing to the organisation's growing presence within the industry. This role is ideal for someone with a proactive, "can-do" mindset who enjoys balancing technical depth with creativity, teamwork, and real ownership. Key Responsibilities Taking initiative on robust software product development, including developing, deploying, and maintaining cloud-based web applications Designing full system structures, including workflows, databases, and cloud architectures Creating an exceptional user experience for advanced engineering tools Developing background daemons and orchestration software to run optimisation algorithms in parallel Identifying and scoping new features and future R&D opportunities Producing technical specifications for external subcontractors and managing those relationships Supporting the development of R&D funding applications and consultancy proposals Coaching and mentoring junior developers Representing the business at conferences, webinars, and industry events About You Essential Skills & Experience Proven experience owning and delivering full stack web applications end-to-end Strong understanding of user-centric design and client experience Solid knowledge of parallel, virtual, cloud computing and Dockerisation Experience developing background services using multiprocessing and multithreading Excellent technical capability across: Python , Flask, MVT architecture SQLAlchemy and ORM principles PostgreSQL and database design Front-end development using HTML, CSS, JavaScript (jQuery, AJAX, DataTables) Jinja2 and Node Package Manager Docker and Docker Python API AWS (ECS, RDS, EFS, EC2, VPC, Firewalls, Boto3 API) Azure DevOps, CI/CD pipelines, repositories Git and source control tools Mapping solutions such as OpenLayers Strong written and verbal communication skills, able to clearly explain technical concepts to non-technical stakeholders Experience delivering complex, uncertain R&D projects Confident conducting high-quality code reviews Desirable Experience with additional languages (e.g. .NET Core) Kubernetes GIS and mapping technologies Background in net-zero or renewable energy engineering environments Model-based engineering knowledge Experience writing successful R&D or consultancy proposals Experience working on international consultancy projects Additional language skills Attributes & Behaviours Professional and confident working with a wide range of stakeholders Collaborative, inquisitive, and solutions-focused Comfortable working independently while contributing fully to a team Discreet, diplomatic, and trustworthy Adaptable, with an understanding that roles evolve in a growing organisation Aligned with strong values around integrity, fairness, trust, and excellence Qualifications Essential Degree in a relevant subject (e.g. Software Development, Computer Science, Mathematics, Engineering) from a reputable institution Right to work in the UK Desirable Relevant CPD or formal certifications (AWS, Python, Front-End Development, Cyber Security, etc.) CPD or qualifications linked to the net-zero or energy transition sector What's on Offer Permanent position Salary between £42,000 - £62,000, depending on experience Newcastle upon Tyne-based role Opportunity to work on truly innovative, world-leading technology Supportive, collaborative team environment Real scope to influence products, processes, and future direction
May 12, 2026
Full time
Are you a senior-level Full Stack Developer who thrives on solving complex problems and turning innovative ideas into powerful, real-world applications? Do you enjoy working with Python at scale, shaping user-focused web platforms, and having genuine influence over technical direction and product development? Looking for a permanent opportunity where your expertise is valued, your voice is heard, and you can help build cutting-edge tools within a growing, purpose-driven organisation? Gillespie Recruitment are delighted to be working on behalf of an innovative and rapidly scaling technology business to recruit an experienced Senior Python Full Stack Developer based in Newcastle upon Tyne. This is an exciting opportunity to join a forward-thinking organisation developing world-leading tools, where collaboration, flexibility, and technical excellence sit at the heart of everything they do. The Role As Senior Python Full Stack Developer, you'll be a key member of the Full Stack Development team, working closely with the Lead Full Stack Developer to bring sophisticated engineering tools to life through intuitive, high-performance web applications. You'll be involved across the full software lifecycle - from system architecture and cloud design through to development, deployment, and optimisation. Alongside hands-on development, you'll play an important role in mentoring junior colleagues, shaping future R&D initiatives, and contributing to the organisation's growing presence within the industry. This role is ideal for someone with a proactive, "can-do" mindset who enjoys balancing technical depth with creativity, teamwork, and real ownership. Key Responsibilities Taking initiative on robust software product development, including developing, deploying, and maintaining cloud-based web applications Designing full system structures, including workflows, databases, and cloud architectures Creating an exceptional user experience for advanced engineering tools Developing background daemons and orchestration software to run optimisation algorithms in parallel Identifying and scoping new features and future R&D opportunities Producing technical specifications for external subcontractors and managing those relationships Supporting the development of R&D funding applications and consultancy proposals Coaching and mentoring junior developers Representing the business at conferences, webinars, and industry events About You Essential Skills & Experience Proven experience owning and delivering full stack web applications end-to-end Strong understanding of user-centric design and client experience Solid knowledge of parallel, virtual, cloud computing and Dockerisation Experience developing background services using multiprocessing and multithreading Excellent technical capability across: Python , Flask, MVT architecture SQLAlchemy and ORM principles PostgreSQL and database design Front-end development using HTML, CSS, JavaScript (jQuery, AJAX, DataTables) Jinja2 and Node Package Manager Docker and Docker Python API AWS (ECS, RDS, EFS, EC2, VPC, Firewalls, Boto3 API) Azure DevOps, CI/CD pipelines, repositories Git and source control tools Mapping solutions such as OpenLayers Strong written and verbal communication skills, able to clearly explain technical concepts to non-technical stakeholders Experience delivering complex, uncertain R&D projects Confident conducting high-quality code reviews Desirable Experience with additional languages (e.g. .NET Core) Kubernetes GIS and mapping technologies Background in net-zero or renewable energy engineering environments Model-based engineering knowledge Experience writing successful R&D or consultancy proposals Experience working on international consultancy projects Additional language skills Attributes & Behaviours Professional and confident working with a wide range of stakeholders Collaborative, inquisitive, and solutions-focused Comfortable working independently while contributing fully to a team Discreet, diplomatic, and trustworthy Adaptable, with an understanding that roles evolve in a growing organisation Aligned with strong values around integrity, fairness, trust, and excellence Qualifications Essential Degree in a relevant subject (e.g. Software Development, Computer Science, Mathematics, Engineering) from a reputable institution Right to work in the UK Desirable Relevant CPD or formal certifications (AWS, Python, Front-End Development, Cyber Security, etc.) CPD or qualifications linked to the net-zero or energy transition sector What's on Offer Permanent position Salary between £42,000 - £62,000, depending on experience Newcastle upon Tyne-based role Opportunity to work on truly innovative, world-leading technology Supportive, collaborative team environment Real scope to influence products, processes, and future direction
Job Title: DevSecOps Security Consultant Location: Sheffield or Birmingham (hybrid - 3 days per week) Salary/Rate: (Apply online only) per day inside IR35 Start Date: May Job Type: Initial contract until 18/05/2027 Company Introduction We have an exciting opportunity now available with one of our sector-leading consultancy clients! They are currently looking for a skilled DevSecOps Security Consultant to join their client at a Tier 1 bank in either Sheffield or Birmingham on a hybrid basis. Job Responsibilities/Objectives We are seeking a highly skilled and experienced Senior Cybersecurity SME / Consultant to join the Engineering Excellence and Enablement team. The successful candidate will work across global engineering platforms to benchmark, uplift, and continuously evolve cybersecurity maturity. The successful candidate will play a critical role in ensuring that build systems, runtime infrastructure, and developer tooling are secure by design, while enabling rapid and resilient software delivery across the bank. This role offers a unique opportunity to shape the cybersecurity posture of engineering platforms at one of the world?s leading financial institutions, ensuring the bank can deliver digital services securely, reliably, and at scale. Framework and Assessment Develop and maintain an Engineering-Platform Cybersecurity Maturity Framework to standardise assessments across platforms. Conduct comprehensive platform security reviews (build systems, CI/CD pipelines, runtime infrastructure, developer tooling) against defined framework criteria. Perform threat modelling and gap analysis, identifying vulnerabilities and systemic risks impacting source code, artifacts, and workloads. Engineering Platform Security Enablement Establish standardised secure architecture and engineering patterns for build systems, CI/CD pipelines, runtime environments, and developer tooling. Define and enforce platform security baselines using policy-as-code and automated controls. Partner with platform owners to remediate critical gaps and implement scalable solutions for artifact integrity, access control, and configuration security. Integrate vulnerability management, SBOM, provenance, and code-signing practices within engineering workflows. Roadmap Development & Execution Prioritise identified gaps based on business risk, regulatory impact, and operational criticality. Collaborate with platform owners and engineering leads to build actionable security roadmaps, balancing quick wins with long-term strategic improvements. Partner with engineering teams to design, develop, and embed security patterns and best practices into engineering platforms. Stakeholder Engagement & Governance Serve as a trusted advisor to platform owners, senior technology stakeholders, and Cybersecurity leadership, translating technical risks into business impact. Represent the function in key governance forums, providing updates on maturity progress, roadmap delivery, and risk posture. Influence and align stakeholders across federated engineering teams to ensure consistent adoption of cybersecurity best practices. Continuous Improvement Track and report maturity scores, ensuring measurable improvement across platforms. Continuously evolve the maturity framework in response to emerging threats, technology evolution, and regulatory expectations. Drive a culture of secure-by-design engineering through engagement, advocacy, and knowledge sharing. Required Skills/Experience The ideal candidate will have the following: Proven expertise in Cybersecurity within large-scale, regulated financial institutions or similarly complex environments. Deep technical knowledge of engineering platforms, including CI/CD systems, build tools, artifact repositories, runtime environments, and developer tooling. Strong experience with DevSecOps practices, including secure pipeline design, integration of security scanning tools, and automation of security controls. Strong knowledge and understanding of service mesh, cryptography, network security, application security, vulnerability management, and risk management. Demonstrable ability to conduct threat modelling, platform security assessments, and gap analysis. Experience building and implementing maturity models, frameworks, or roadmaps in complex enterprise environments. Strong stakeholder management skills, with the ability to influence senior leadership and drive change across federated technology teams. Excellent communication skills, with the ability to translate technical risk into business impact. Desirable Skills/Experience Although not essential, the following skills are desired by the client: Professional certifications such as CISSP, CISM, CCSK, CCSP, or equivalent. Hands-on knowledge of cloud security (AWS, Azure, GCP) and container orchestration platforms (e.g., Kubernetes). Experience in international and diverse environments, with exposure to regulatory engagement. Familiarity with engineering excellence practices such as SLSA, supply chain security, SBOM, or secure developer tooling initiatives. If you are interested in this opportunity, please apply now with your updated CV in Microsoft Word/PDF format. Disclaimer Notwithstanding any guidelines given to level of experience sought, we will consider candidates from outside this range if they can demonstrate the necessary competencies. Square One is acting as both an employment agency and an employment business, and is an equal opportunities recruitment business. Square One embraces diversity and will treat everyone equally. Please see our website for our full diversity statement.
Apr 22, 2026
Contractor
Job Title: DevSecOps Security Consultant Location: Sheffield or Birmingham (hybrid - 3 days per week) Salary/Rate: (Apply online only) per day inside IR35 Start Date: May Job Type: Initial contract until 18/05/2027 Company Introduction We have an exciting opportunity now available with one of our sector-leading consultancy clients! They are currently looking for a skilled DevSecOps Security Consultant to join their client at a Tier 1 bank in either Sheffield or Birmingham on a hybrid basis. Job Responsibilities/Objectives We are seeking a highly skilled and experienced Senior Cybersecurity SME / Consultant to join the Engineering Excellence and Enablement team. The successful candidate will work across global engineering platforms to benchmark, uplift, and continuously evolve cybersecurity maturity. The successful candidate will play a critical role in ensuring that build systems, runtime infrastructure, and developer tooling are secure by design, while enabling rapid and resilient software delivery across the bank. This role offers a unique opportunity to shape the cybersecurity posture of engineering platforms at one of the world?s leading financial institutions, ensuring the bank can deliver digital services securely, reliably, and at scale. Framework and Assessment Develop and maintain an Engineering-Platform Cybersecurity Maturity Framework to standardise assessments across platforms. Conduct comprehensive platform security reviews (build systems, CI/CD pipelines, runtime infrastructure, developer tooling) against defined framework criteria. Perform threat modelling and gap analysis, identifying vulnerabilities and systemic risks impacting source code, artifacts, and workloads. Engineering Platform Security Enablement Establish standardised secure architecture and engineering patterns for build systems, CI/CD pipelines, runtime environments, and developer tooling. Define and enforce platform security baselines using policy-as-code and automated controls. Partner with platform owners to remediate critical gaps and implement scalable solutions for artifact integrity, access control, and configuration security. Integrate vulnerability management, SBOM, provenance, and code-signing practices within engineering workflows. Roadmap Development & Execution Prioritise identified gaps based on business risk, regulatory impact, and operational criticality. Collaborate with platform owners and engineering leads to build actionable security roadmaps, balancing quick wins with long-term strategic improvements. Partner with engineering teams to design, develop, and embed security patterns and best practices into engineering platforms. Stakeholder Engagement & Governance Serve as a trusted advisor to platform owners, senior technology stakeholders, and Cybersecurity leadership, translating technical risks into business impact. Represent the function in key governance forums, providing updates on maturity progress, roadmap delivery, and risk posture. Influence and align stakeholders across federated engineering teams to ensure consistent adoption of cybersecurity best practices. Continuous Improvement Track and report maturity scores, ensuring measurable improvement across platforms. Continuously evolve the maturity framework in response to emerging threats, technology evolution, and regulatory expectations. Drive a culture of secure-by-design engineering through engagement, advocacy, and knowledge sharing. Required Skills/Experience The ideal candidate will have the following: Proven expertise in Cybersecurity within large-scale, regulated financial institutions or similarly complex environments. Deep technical knowledge of engineering platforms, including CI/CD systems, build tools, artifact repositories, runtime environments, and developer tooling. Strong experience with DevSecOps practices, including secure pipeline design, integration of security scanning tools, and automation of security controls. Strong knowledge and understanding of service mesh, cryptography, network security, application security, vulnerability management, and risk management. Demonstrable ability to conduct threat modelling, platform security assessments, and gap analysis. Experience building and implementing maturity models, frameworks, or roadmaps in complex enterprise environments. Strong stakeholder management skills, with the ability to influence senior leadership and drive change across federated technology teams. Excellent communication skills, with the ability to translate technical risk into business impact. Desirable Skills/Experience Although not essential, the following skills are desired by the client: Professional certifications such as CISSP, CISM, CCSK, CCSP, or equivalent. Hands-on knowledge of cloud security (AWS, Azure, GCP) and container orchestration platforms (e.g., Kubernetes). Experience in international and diverse environments, with exposure to regulatory engagement. Familiarity with engineering excellence practices such as SLSA, supply chain security, SBOM, or secure developer tooling initiatives. If you are interested in this opportunity, please apply now with your updated CV in Microsoft Word/PDF format. Disclaimer Notwithstanding any guidelines given to level of experience sought, we will consider candidates from outside this range if they can demonstrate the necessary competencies. Square One is acting as both an employment agency and an employment business, and is an equal opportunities recruitment business. Square One embraces diversity and will treat everyone equally. Please see our website for our full diversity statement.