Categories
Jobs in the UK
gravity9 is recruiting Java engineers and architects for a portfolio of engagements across UK central government. These are large-scale, data-intensive modernisation programmes: replacing legacy systems that carry statutory weight, decomposing monoliths that serve millions of users, and building secure data platforms where access control and auditability are first-class architectural concerns rather than late additions.
We are hiring across two overlapping profiles — Senior Java Developer and Application / Migration Architect — and expect most people to move between programmes as engagements start and complete. Several of these are hands-on architect roles: you will own design decisions and also write production code
The kind of work
The following are representative of current and upcoming engagements. Individual roles will draw on some of this, not all of it — we are more interested in engineers who can work confidently at the intersection of Java and data than in a checklist match against any one programme.
Secure data catalogue and access-control platform
A greenfield metadata catalogue acting as a federated index over data held across independent domains, so that authorised parties can locate and retrieve data the catalogue itself never holds. The work includes designing an attribute-based access control model over attributes such as clearance, nationality, organisational unit and compartment; enforcing those policies inside the database query path rather than filtering results afterwards; application-layer encryption with externally managed keys; hybrid lexical and semantic search with access filtering applied before candidate retrieval rather than after it; and a tamper-evident audit trail that can reconstruct why a given record was returned, redacted or withheld.
Real-time decision-support data architecture
Replacing point-to-point integration across a multi-vendor estate with a microservices architecture and a common data layer, so that operational data flows in near real time instead of over days. The work includes target-state architecture and decision records, change-data-capture ingest pipelines from upstream data services, ontology and mapping-layer design across suppliers with competing data models, separation of system, reference and insight data classes including time-series, and deployment topologies spanning cloud-hosted services down to constrained edge hardware.
Legacy-to-document-model migration at national scale
Migrating hundreds of millions of records and tens of terabytes of XML out of a legacy relational platform into a sharded document store, in support of a COBOL-to-Java microservices rewrite. The work includes a configuration-driven XML-to-JSON transformation framework backed by a versioned schema registry — twenty years of history, multiple record types and continual schema and semantic drift; CDC and streaming pipelines, or a checkpointed parallel bulk-extract alternative; a field-level mapping validation and reconciliation framework robust enough to stand up to audit; a replay and failure-diagnostics harness with dead-letter routing and idempotent re-runs; and repeated dress rehearsals toward a single cutover window with no dual running.
Monolith decomposition and data-ownership migration
Breaking a distributed monolith of well over a hundred Java services sharing a handful of database clusters into domain-owned services — moving from borrowed data to owned data without reintroducing hidden coupling. The work includes bounded-context analysis to establish which domain genuinely owns which collections, in-place data remodelling ahead of any physical move, a data-access facade with feature-flagged per-request routing between old and new stores, dual-write / backfill / reconcile / read-switch cutover lifecycles with a defined rollback at every step, cluster-to-cluster streaming and live migration tooling, and automated parallel-run and diff-on-read testing.
What you will be doing
Emphasis varies by role and programme, but MongoDB is the common thread. Every one of these engagements involves modelling for it, migrating onto it, or building on top of it, and genuine depth here is what most differentiates candidates.
Architecture and design
• Produce high- and low-level designs, security and data architectures, and architecture decision records — and take them through client design authorities and formal governance gates
• Make and defend architectural trade-offs in front of both engineering and non-technical stakeholders, including client technical authorities and third-party suppliers
• Analyse real access patterns and validate target MongoDB document models against genuine throughput, query and sharding requirements before they are baselined
• Design integration boundaries in multi-vendor programmes where you own one component and must collaborate across the seams of others
Hands-on build
• Build production Java services and RESTful APIs (Spring Boot or similar), designed for integration by multiple consuming systems and documented to OpenAPI
• Design and implement MongoDB document models, aggregation pipelines, indexing and sharding strategies, and integrate them cleanly into Java service layers rather than through a leaky abstraction
• Build data pipelines: CDC and streaming ingest, transformation frameworks, checkpointed batch extract workers, and MongoDB sink configuration and tuning at terabyte scale
• Implement access control, encryption and audit within the application and data layer, including enforcement inside the MongoDB query path, rather than bolted on around it
• Write the tests: unit, integration, golden-record fixtures, parallel-run reconciliation, and load and stress harnesses that prove performance under realistic volumes
• Work across both MongoDB Atlas and Enterprise Advanced, including Kubernetes-hosted deployments, and with the migration and sync tooling around them
Data modernisation and migration
• Model relational, XML or other legacy schemas onto MongoDB document models, handling schema and semantic drift through versioned, configuration-driven mappings rather than forked code
• Design and prove cutover mechanisms — dual-write, backfill, reconcile, read-switch, rollback — for systems where a failed migration is not an acceptable outcome
• Build validation and reconciliation tooling that satisfies audit: completeness, field-level fidelity, and query-level equivalence between old and new
Security, access control and assurance
• Design and implement attribute- or role-based access control models, including enforcement at the data layer and policy administration
• Work with application-layer and field-level encryption — MongoDB client-side field level and queryable encryption, and externally managed key material
• Produce tamper-evident audit trails and observability that answer not just what happened but why
Client-facing delivery and enablement
• Work as an embedded member of a small delivery team, frequently alongside client engineers and other suppliers
• Run workshops, playbacks and sprint demonstrations; produce design documentation, integration guides and operational runbooks
• Support knowledge transfer and upskilling of client teams — on these programmes enablement is a deliverable, not an afterthought
• Use AI-assisted engineering tooling as part of normal delivery, within the constraints client security policy sets
Essential
• Strong hands-on Java — building and running production services and RESTful APIs with Spring Boot or an equivalent framework
• MongoDB — solid working experience covering document modelling, querying, aggregation pipelines and indexing, and integrating MongoDB into Java application layers. Atlas and/or Enterprise Advanced
• Data-intensive systems — demonstrable experience of pipelines, migrations or integrations at meaningful scale, and sound reasoning about throughput, ordering, idempotency and failure recovery
• API design — clean, well-documented REST interfaces suitable for integration by multiple consuming systems
• Testing — genuine automated testing discipline, plus practical experience of load and stress testing against realistic volumes
• Infrastructure and deployment — Terraform or equivalent infrastructure as code, containerised deployment on Kubernetes, and AWS or a comparable cloud
• Communication — able to write clear design documentation and hold your own in a client design authority or architecture review
• UK resident, and either holding current UK SC clearance or clearly eligible to obtain it
For architect-level roles we additionally expect:
• Proven design authority on a delivery of comparable size and sensitivity, while remaining hands-on enough to prototype, pair and review code
• Experience operating inside multi-vendor or multi-supplier programmes, including holding a technical position when other suppliers hold a different one
Desirable
• UK public sector, or another regulated and security-conscious environment
• Kafka and change-data-capture tooling such as Debezium; stream processing
• Legacy modernisation patterns — strangler fig, operational data layers, dual running and phased cutover
• Domain-driven design and bounded-context analysis; monolith decomposition
• Attribute-based access control and policy-as-code frameworks (OPA, Casbin, XACML-based systems)
• Field-level or client-side encryption, key management, HSM/KMS and KMIP integration
• Search — Lucene-based or Atlas Search, vector search, hybrid retrieval and RAG patterns
• Metadata standards such as DCAT or Dublin Core; data cataloguing, data mesh and federated data architecture concepts
• Event-driven architecture and consistency patterns in distributed systems (saga, eventual consistency)
• Oracle, COBOL or other mainframe and legacy platform familiarity
• Time-series or geospatial data; deployment to constrained or edge hardware
• AI-assisted development workflows and agentic coding tools
Working context
Engagement Contract. Typically three to twelve months per programme, with a strong likelihood of rolling onto the next. Some roles begin part-time through a design phase before going full-time for build.
Clearance SC clearance is the standard requirement for these roles, and current SC will always be the fastest route onto a programme. We will consider especially strong candidates who hold BPSS only and can sponsor SC in those cases, though clearance takes roughly three months and start dates will reflect that.
Residency UK resident. All work on these programmes is delivered from the UK by UK-onshore staff.
Working model Predominantly remote with periodic onsite attendance. Locations vary by programme — expect occasional travel to client sites including London, Manchester and Leeds.
Environment Work is typically delivered through client-supplied devices or VDI, with VPN access to client environments. You should be comfortable operating within defined information-handling and access constraints, and with the pace that government security and onboarding processes set.
Team shape Small, focused, multi-disciplinary teams. On several programmes gravity9 delivers alongside partner organisations and other suppliers, and you will need to work effectively across those boundaries.
Timing These roles support a growing pipeline of central government work. Some engagements are contracted and mobilising; others are in contract negotiation with expected start dates in the coming months. We are building the bench now so that we can mobilise quickly, and clearance lead times mean early conversations are worthwhile even where a start date is not yet fixed.