Open for short engagements · Q3 2026

Security that ships,
not security that
says no.

I'm James Elliott — a developer turned DevSecOps engineering manager. I help teams build security that works like good driver-assist: brakes when you need them, lane-assist when you don't, never the handbrake. Short, sharp engagements only.

Practice
DevSecOps
Engagements
2–12 weeks · No long retainers
Based in
UK · Remote-first
Format
Advisory · Audit · Coaching
01 · Services

Short engagements. Real outcomes.

02 · How I work

I'm not the Department of No.

P/01

Yes, and…

"No" is rarely the answer. The job is finding the route that ships the work and keeps you safe — even if it means a detour.

P/02

Pragmatic over pure

A 70% control your team actually runs beats a 100% control they route around. I optimise for what gets used in production on a Tuesday.

P/03

Lane-assist, not handbrake

Good security should sit in the background and gently nudge — not jolt the wheel out of your hands. If a control feels like a handbrake, it's the wrong control.

P/04

Short over long

I take fixed-scope engagements with a defined end. If I'm still here in twelve months, something's gone wrong — and that's not the deal.

03 · Writing

Notes on strategy, execution, & getting things shipped.

04 · About

I came up building things — that still shapes how I work.

I started my career as a developer, shipping product code before the term DevSecOps existed. Over time I gravitated toward the seams — where security, platform, and product collide — and ended up running engineering teams whose job is to keep those seams from tearing.

Good security feels like lane-assist, not a handbrake. It should keep you in the lane while you focus on the road ahead.

These days I lead a DevSecOps engineering function and consult on the side. The work I'm proudest of usually looks the same from the outside: a team that stopped firefighting, started shipping, and quietly raised its security posture without anyone calling it a "transformation".

If your strategy lives in a slide deck and your engineers are routing around it, we should talk.

05 · Get in touch

Let's talk about
your security strategy.

The first 30 minutes are free. Tell me where you are, what's been tried, and what's on fire. If I'm the right fit we'll scope something concrete. If I'm not, you'll leave with a useful second opinion.

Book a 30-min call