Lead Security Engineer
hackajob United KingdomLead Security Engineer
hackajob
United Kingdom
4 days ago
Be among the first 25 applicants
See who hackajob has hired for this role
Save
hackajob is collaborating with Made Tech to connect them with exceptional professionals for this role.Made Tech helps UK government and public sector organisations build better digital services — and security is central to that mission. As a Lead Security Engineer in our Cyber practice, you'll be the most senior security engineering voice on client engagements, setting technical direction for how organisations design, build, and defend secure systems. You'll work across complex government programmes where the stakes are real: services that affect citizens, systems that hold sensitive data, and teams that need to move quickly without cutting corners.
This isn't a role where you sit at the edge of delivery reviewing outputs. You'll be embedded in multidisciplinary teams, shaping how security is engineered into everyday work — from threat modelling and architecture at design time to hardened, monitored systems in production. You'll build trusted relationships with client engineering leads, platform teams, and senior stakeholders, translating between deep technical decisions and the trade-offs senior leaders need to understand. You'll bring the judgement to know when a heavyweight security architecture is warranted and when a lighter-weight, faster-moving approach serves the engagement better.
At Lead level, your impact extends beyond the immediate team. You'll establish security engineering standards and reference architectures across engagements, grow the technical capability of the people around you — colleagues and client engineers alike — and contribute to how Made Tech's Cyber practice develops as a community. If you'd rather build the paved road than police the off-road, who treat security as an engineering discipline rather than a compliance exercise, and who cares about leaving client teams genuinely stronger than you found them, this role is for you.
Key responsibilities
- Own end-to-end technical security architecture across engagements. Design secure-by-default reference architectures, set patterns for identity, network, and data protection, and maintain living technical standards — feeding directly into how teams build, not just how they're audited.
- Lead vulnerability remediation as an engineering programme. Define the prioritisation framework — drawing on EPSS, KEV, CVSS, and asset criticality — set remediation SLAs, own the risk-acceptance register, and drive fixes directly into delivery backlogs alongside product teams. Report programme KPIs (MTTR by severity, backlog age, coverage, recurrence rate) to senior stakeholders.
- Drive security into the team's normal engineering rhythm. Embed threat modelling, secure code review, SAST, SCA, dependency policy, and container scanning into design and delivery cycles — building the tooling and automation that make this the default, not a specialist handover at the end of a sprint.
- Navigate UK government security standards with confidence — as an engineer, not a paperwork exercise. Design systems and controls that satisfy the NCSC Cyber Assessment Framework, GovAssure, Cyber Essentials, and HMG Security Policy Framework, applying them proportionately across engagements as guardrails that enable safe delivery, not barriers to it. Engage with government security communities and coordinate with departmental technical teams.
- Communicate security risk in terms that drive engineering decisions. Report system posture, remediation programme performance, and architectural risk to senior client stakeholders — tailoring the frame for the audience and structuring reports around the decisions the reader needs to make, not just the findings.
- Set the standard for incident response and detection engineering. Build and drive adoption of detection, alerting, and IR tooling across engagements, own the IR-to-vulnerability-management feedback loop, and coordinate cross-team exercises including known-exploited-vulnerability scramble drills.
- Grow the people around you. Mentor colleagues across the practice and at client organisations, pair on complex or unfamiliar engineering problems, and create structured development opportunities — including for client engineers who may not yet have strong security habits.
- Contribute to Made Tech's Cyber practice beyond delivery. Shape practice standards, contribute to hiring and technical calibration, build and share expertise externally, and help grow a security engineering community that raises capability across the organisation.
Essential
- Deep hands-on experience designing and building secure cloud architectures (AWS, Azure, or GCP) at scale, including IAM, network segmentation, and data protection patterns.
- Proven track record embedding security tooling and automation into CI/CD pipelines and engineering workflows across multiple teams.
- Strong proficiency in at least one programming/scripting language, used to build production-grade security tooling (not just scripts).
The following would strengthen your application. We don't expect every candidate to bring all of these.
Certifications
- OSCP, OSWE, or equivalent offensive security credential
- AWS/Azure/GCP security specialty certification
- CKS (Certified Kubernetes Security Specialist)
- Experience establishing and operating vulnerability remediation programmes at organisational scale — including risk-based prioritisation using EPSS, KEV, and asset criticality, and driving fixes across multiple delivery teams.
- Evidence of designing systems that satisfy UK government security frameworks — GovAssure, CAF, Cyber Essentials, HMG Security Policy Framework — in a complex multi-supplier or multi-team environment, as an architect rather than an assessor.
- Experience conducting or coordinating technical security reviews and penetration testing in UK public sector contexts, including remediating findings and briefing senior technical stakeholders.
- Working knowledge of exposure management beyond CVE-only approaches — incorporating misconfiguration, identity exposure, and attack-path analysis using cloud-native tooling (AWS Inspector, GuardDuty, Security Hub, or equivalents).
- Experience securing software supply chains — SBOM generation, dependency provenance, artifact signing — and integrating this into build pipelines rather than a standalone assurance process.
- Experience building or shaping security engineering capability within a consultancy, programme delivery, or multi-client environment — including growing technical skills in colleagues and client teams.
- Evidence of acting as a trusted technical adviser to senior client stakeholders — anchoring recommendations on engineering outcomes, challenging briefs constructively, and making security value visible through what gets shipped.
- Experience setting team ways of working in iterative delivery environments — establishing retrospective cadences, collaborative problem-solving norms, and pairing practices that spread security knowledge across the team.
- Deep familiarity with structured threat modelling approaches — STRIDE, MITRE ATT&CK, attack trees — and experience embedding these into agile delivery ceremonies.
- Experience integrating SAST, SCA, dependency scanning, and container security tooling into CI/CD pipelines as part of a shift-left security approach, including building custom tooling where off-the-shelf doesn't fit.
Job benefits
We are always listening to our growing teams and evolving the benefits available to our people. As we scale, as do our benefits and we are scaling quickly. We've recently introduced a flexible benefit platform which includes a Smart Tech scheme, Cycle to work scheme, and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan. We’re also big on connection and have an optional social and wellbeing calendar of events for all employees to join should they choose to.
Here are some of our most popular benefits listed below:
30 days Holiday - we offer 30 days of paid annual leave
Flexible Working Hours - we are flexible with what hours you work
Flexible Parental Leave - we offer flexible parental leave options
Remote Working - we offer part time remote working for all our staff
Paid counselling - we offer paid counselling as well as financial and legal advice
At this point, we hope you're feeling excited about Made Tech and the job opportunity. Get in touch with our talent team if you’d like an informal chat about the role and your suitability before applying. We are hiring for this role directly, so will not respond to any CVs sent via external recruitment agencies.
SC Eligibility
An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result, we're looking for all successful candidates for this role to have eligibility.
Eligibility for SC requires 5 years' UK residency and 5 year' employment history (or back to full-time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC, we won't be able to progress your application and we will contact you to let you know why.
Support in applying
If you need this job description in another format, or other support in applying, please email talent@madetech.com.
We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. We’re collectively continuing to grow a culture that is happy, healthy, safe and inspiring for people of all backgrounds and experiences, so we encourage people from underrepresented groups to apply for roles with us.
When you apply, we’ll put you in touch with a member of our talent team who can help with any needs or adjustments we may need to make to help with your application. We’ve put together this blog as a resource to share more about reasonable adjustments and some examples of what this could include. We also welcome any feedback on how we can improve the experience for future candidates.
Working hours: Our standard hours are Monday to Friday, but the nature of this role means some work outside normal hours may be required, for example during release and change windows, planned maintenance, or to align with client operating hours. This is occasional rather than routine, and we'll always give as much notice as we can and agree it with you in advance wherever possible.
-
Seniority level
Mid-Senior level -
Employment type
Full-time -
Job function
Information Technology -
Industries
Software Development
Referrals increase your chances of interviewing at hackajob by 2x
See who you know Get notified when a new job is posted.Similar jobs
-
Staff Security Engineer, Product Security
Staff Security Engineer, Product Security
Chainalysis
United Kingdom 1 week ago -
Staff Infrastructure Security Engineer
Staff Infrastructure Security Engineer
GitLab
United Kingdom 1 day ago -
Senior Security Engineer
Senior Security Engineer
Olo
United Kingdom 3 weeks ago -
Senior Security Engineer - Blue Team
Senior Security Engineer - Blue Team
Olo
United Kingdom 3 months ago -
Principal Security Engineer
Principal Security Engineer
Auros
United Kingdom 1 week ago -
Senior Staff Information Security Engineer
Senior Staff Information Security Engineer
NMI
United Kingdom 3 days ago -
Senior Security Engineer, Bug Bounty
Senior Security Engineer, Bug Bounty
Mozilla
United Kingdom 1 week ago -
Principal Cloud Security Engineer
Principal Cloud Security Engineer
LastPass
United Kingdom 1 week ago -
Senior Security Engineer, SEAR
Senior Security Engineer, SEAR
Apple
Cheltenham, England, United Kingdom 1 month ago -
Senior Security Engineer
Senior Security Engineer
Zenobē
United Kingdom 6 days ago -
Senior Security Engineer
Senior Security Engineer
Zepz
United Kingdom 1 week ago -
Principal Security Engineer
Principal Security Engineer
Kinsei Recruitment
London, England, United Kingdom 1 year ago -
Senior Security Engineer
Senior Security Engineer
Mattermost
United Kingdom 1 week ago -
Senior Threat & Vulnerability Engineer | Remote (UK) | Cloud-Native SaaS
Senior Threat & Vulnerability Engineer | Remote (UK) | Cloud-Native SaaS
La Fosse
United Kingdom 4 weeks ago -
Senior Product Security Engineer
Senior Product Security Engineer
Collibra
United Kingdom 2 weeks ago -
Principal Security Engineer
Principal Security Engineer
Auros
Moorland, England, United Kingdom 1 month ago -
Senior Security Engineer
Senior Security Engineer
Samsara
United Kingdom 3 weeks ago -
Senior Product Security Engineer
Senior Product Security Engineer
Chainguard
United Kingdom 1 week ago -
Senior Security Engineer
Senior Security Engineer
hackajob
United Kingdom 4 days ago -
Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA
Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA
GitLab
United Kingdom 1 day ago -
Senior Security Engineer (UK Remote - £110k)
Senior Security Engineer (UK Remote - £110k)
Lawrence Harvey
United Kingdom £100,000.00 - £110,000.00 4 weeks ago -
Security Operations Engineer, EMEA
Security Operations Engineer, EMEA
Cohere
London, England, United Kingdom 4 days ago -
Security Engineer
Security Engineer
Primer
United Kingdom 1 week ago -
Platform Security Engineer
Platform Security Engineer
Complexio
United Kingdom 5 months ago -
Lead Security & Compliance Analyst
Lead Security & Compliance Analyst
ev.energy
United Kingdom £85,900.00 - £105,200.00 6 days ago -
Senior Cyber Security Engineer
Senior Cyber Security Engineer
ENSEK
Nottingham, England, United Kingdom 2 months ago -
Senior Security Engineer
Senior Security Engineer
OVO
United Kingdom 1 day ago
People also viewed
-
Senior Cloud Security Engineer
Senior Cloud Security Engineer
Belfast, Northern Ireland, United Kingdom 2 weeks ago -
Senior Software Security Engineer
Senior Software Security Engineer
London, England, United Kingdom £98,000.00 - £115,000.00 2 weeks ago -
Senior Application Security Engineer
Senior Application Security Engineer
United Kingdom $230,000.00 - $230,000.00 2 weeks ago -
Senior Cloud Security Engineer
Senior Cloud Security Engineer
United Kingdom £90,000.00 - £110,000.00 6 days ago -
Senior Information Security Engineer - Application Security
Senior Information Security Engineer - Application Security
United Kingdom 45 minutes ago -
Senior Application Security Engineer (Remote - United Kingdom)
Senior Application Security Engineer (Remote - United Kingdom)
United Kingdom 1 week ago -
Senior Security Engineer, Docker Desktop
Senior Security Engineer, Docker Desktop
United Kingdom 1 day ago -
Senior Application Security Engineer (Remote - United Kingdom)
Senior Application Security Engineer (Remote - United Kingdom)
London, England, United Kingdom 1 week ago -
Senior Security Engineer
Senior Security Engineer
United Kingdom £105,000.00 - £115,000.00 3 days ago -
OT Security Lead
OT Security Lead
United Kingdom £75,000.00 - £75,000.00 1 week ago
Similar Searches
-
Principal Security Engineer jobs
569 open jobs -
Network Services Engineer jobs
2,025 open jobs -
Principal Technical Architect jobs
549 open jobs -
Senior Security Engineer jobs
2,191 open jobs -
Computer System Analyst jobs
20,560 open jobs -
Senior Resident Engineer jobs
2,195 open jobs -
Information Security Engineer jobs
1,810 open jobs -
Security Architect jobs
3,553 open jobs -
Staff Engineer jobs
18,732 open jobs -
Security Researcher jobs
2,946 open jobs -
Information Security Manager jobs
717 open jobs -
Principal Enterprise Architect jobs
333 open jobs -
Second Engineer jobs
527 open jobs -
Information Security Architect jobs
645 open jobs -
Security Engineer jobs
14,272 open jobs -
Security Risk Manager jobs
741 open jobs -
Security Operations Manager jobs
1,084 open jobs -
Principal System Engineer jobs
576 open jobs
Only part of this posting is shown here. Read the full description