Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Security Engineer

Hackajob

Lead Security Engineer

Made Tech helps UK government and public sector organisations build better digital services — and security is central to that mission. As a Lead Security Engineer in our Cyber practice, you'll be the most senior security engineering voice on client engagements, setting technical direction for how organisations design, build, and defend secure systems. You'll work across complex government programmes where the stakes are real: services that affect citizens, systems that hold sensitive data, and teams that need to move quickly without cutting corners. This isn't a role where you sit at the edge of delivery reviewing outputs. You'll be embedded in multidisciplinary teams, shaping how security is engineered into everyday work — from threat modelling and architecture at design time to hardened, monitored systems in production. You'll build trusted relationships with client engineering leads, platform teams, and senior stakeholders, translating between deep technical decisions and the trade-offs senior leaders need to understand. You'll bring the judgement to know when a heavyweight security architecture is warranted and when a lighter-weight, faster-moving approach serves the engagement better. At Lead level, your impact extends beyond the immediate team. You'll establish security engineering standards and reference architectures across engagements, grow the technical capability of the people around you — colleagues and client engineers alike — and contribute to how Made Tech's Cyber practice develops as a community. If you'd rather build the paved road than police the off-road, who treat security as an engineering discipline rather than a compliance exercise, and who cares about leaving client teams genuinely stronger than you found them, this role is for you.

Key Responsibilities
  • Own end-to-end technical security architecture across engagements. Design secure-by-default reference architectures, set patterns for identity, network, and data protection, and maintain living technical standards — feeding directly into how teams build, not just how they're audited.
  • Lead vulnerability remediation as an engineering programme. Define the prioritisation framework — drawing on EPSS, KEV, CVSS, and asset criticality — set remediation SLAs, own the risk-acceptance register, and drive fixes directly into delivery backlogs alongside product teams. Report programme KPIs (MTTR by severity, backlog age, coverage, recurrence rate) to senior stakeholders.
  • Drive security into the team's normal engineering rhythm. Embed threat modelling, secure code review, SAST, SCA, dependency policy, and container scanning into design and delivery cycles — building the tooling and automation that make this the default, not a specialist handover at the end of a sprint.
  • Navigate UK government security standards with confidence — as an engineer, not a paperwork exercise. Design systems and controls that satisfy the NCSC Cyber Assessment Framework, GovAssure, Cyber Essentials, and HMG Security Policy Framework, applying them proportionately across engagements as guardrails that enable safe delivery, not barriers to it. Engage with government security communities and coordinate with departmental technical teams.
  • Communicate security risk in terms that drive engineering decisions. Report system posture, remediation programme performance, and architectural risk to senior client stakeholders — tailoring the frame for the audience and structuring reports around the decisions the reader needs to make, not just the findings.
  • Set the standard for incident response and detection engineering. Build and drive adoption of detection, alerting, and IR tooling across engagements, own the IR-to-vulnerability-management feedback loop, and coordinate cross-team exercises including known-exploited-vulnerability scramble drills.
  • Grow the people around you. Mentor colleagues across the practice and at client organisations, pair on complex or unfamiliar engineering problems, and create structured development opportunities — including for client engineers who may not yet have strong security habits.
  • Contribute to Made Tech's Cyber practice beyond delivery. Shape practice standards, contribute to hiring and technical calibration, build and share expertise externally, and help grow a security engineering community that raises capability across the organisation.
Skills, Knowledge and Expertise
Essential
  • Deep hands-on experience designing and building secure cloud architectures (AWS, Azure, or GCP) at scale, including IAM, network segmentation, and data protection patterns.
  • Proven track record embedding security tooling and automation into CI/CD pipelines and engineering workflows across multiple teams.
  • Strong proficiency in at least one programming/scripting language, used to build production-grade security tooling (not just scripts).
Desirable

The following would strengthen your application. We don't expect every candidate to bring all of these.

Certifications
  • OSCP, OSWE, or equivalent offensive security credential
  • AWS/Azure/GCP security specialty certification
  • CKS (Certified Kubernetes Security Specialist)
Capabilities and experience
  • Experience establishing and operating vulnerability remediation programmes at organisational scale — including risk-based prioritisation using EPSS, KEV, and asset criticality, and driving fixes across multiple delivery teams.
  • Evidence of designing systems that satisfy UK government security frameworks — GovAssure, CAF, Cyber Essentials, HMG Security Policy Framework — in a complex multi-supplier or multi-team environment, as an architect rather than an assessor.
  • Experience conducting or coordinating technical security reviews and penetration testing in UK public sector contexts, including remediating findings and briefing senior technical stakeholders.
  • Working knowledge of exposure management beyond CVE-only approaches — incorporating misconfiguration, identity exposure, and attack-path analysis using cloud-native tooling (AWS Inspector, GuardDuty, Security Hub, or equivalents).
  • Experience securing software supply chains — SBOM generation, dependency provenance, artifact signing — and integrating this into build pipelines rather than a standalone assurance process.
  • Experience building or shaping security engineering capability within a consultancy, programme delivery, or multi-client environment — including growing technical skills in colleagues and client teams.
  • Evidence of acting as a trusted technical adviser to senior client stakeholders — anchoring recommendations on engineering outcomes, challenging briefs constructively, and making security value visible through what gets shipped.
  • Experience setting team ways of working in iterative delivery environments — establishing retrospective cadences, collaborative problem-solving norms, and pairing practices that spread security knowledge across the team.
Tooling and practice familiarity
  • Deep familiarity with structured threat modelling approaches — STRIDE, MITRE ATT&CK, attack trees — and experience embedding these into agile delivery ceremonies.
  • Experience integrating SAST, SCA, dependency scanning, and container security tooling into CI/CD pipelines as part of a shift-left security approach, including building custom tooling where off-the-shelf doesn't fit.

Made Tech sponsors attainment of recognised cyber certifications for staff in scope. If you don't yet hold the listed credentials but are actively working toward them, or can demonstrate equivalent capability through your experience, we'd still welcome your application.

Job Benefits

We are always listening to our growing teams and evolving the benefits available to our people. As we scale, as do our benefits and we are scaling quickly. We've recently introduced a flexible benefit platform which includes a Smart Tech scheme, Cycle to work scheme, and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan. We're also big on connection and have an optional social and wellbeing calendar of events for all employees to join should they choose to. Here are some of our most popular benefits listed below: 30 days Holiday — we offer 30 days of paid annual leave Flexible Working Hours — we are flexible with what hours you work Flexible Parental Leave — we offer flexible parental leave options Remote Working — we offer part time remote working for all our staff Paid counselling — we offer paid counselling as well as financial and legal advice

SC Eligibility

An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result, we're looking for all successful candidates for this role to have eligibility. Eligibility for SC requires 5 years' UK residency and 5 year employment history (or back to full-time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC, we won't be able to progress your application and we will contact you to let you know why.

Support in applying

If you need this job description in another format, or other support in applying, please email View email address on click.appcast.io. We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. We're collectively continuing to

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Lead Security Engineer in United States vacancy
  • $132k - $238k

     ...Fortune 50 company, and one of America’s leading retailers. Behind the brand our guests love...  ...at Target is on a mission to secure the systems, tools, and processes that team...  ...invite you to join us as a Lead Security Engineer within the Target Proactive Security organization... 
    Suggested
    Full time
    Temporary work
    Work experience placement
    Flexible hours

    Target

    Brooklyn Park, MN
    1 day ago
  • $121k - $173k

     ...Established  nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering  expertise are solely dedicated to...  ...Position Summary    The Lead AI Security Engineer is a senior technical role responsible... 
    Suggested
    Full time
    Work from home
    Relocation
    Flexible hours
    2 days per week

    FM

    Johnston, RI
    9 hours ago
  •  ...that is inclusive to all. Toll Brothers, America's leading luxury home builder, seeks a Lead Security Engineerto join our team at our Corporate office in...  ...Pennsylvania.What is the opportunity?The Lead Security Engineer is a senior technical resource on the Cyber &... 
    Suggested
    Full time
    Work at office
    Local area

    Toll Brothers

    Fort Washington, PA
    5 days ago
  •  ...of the fastest private supercomputers in the world. (We've melted GPUs getting here.)About the RoleWe're looking for a lead-level Security Engineer and Architect to own system, network, and host security end-to-end for a rapidly growing on-prem, Kubernetes-based AI factory... 
    Suggested
    Shift work

    Alembic

    San Francisco, CA
    1 day ago
  • $126.23k - $210.38k

     ...If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Lead Security Engineer to join our team in Fort Washington, Pennsylvania (US-PA), United States (US).The Security Engineer is a hands-on technical... 
    Suggested
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    Flexible hours

    NTT DATA

    Fort Washington, PA
    3 days ago
  •  ...future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.As a Senior Lead Security Engineer at JPMorganChase within the Cybersecurity and Technology Controls line of business, you are an integral part of an agile... 

    JP Morgan Chase

    Wilmington, DE
    1 day ago
  • $132.1k - $220.1k

    The Lead Security Software Engineer at CME Group participates in all functions related to software security design, secure SDLC techniques, and applying strong, secure design patterns with minimal oversight at a task level. This position acts as a constructive, communicative... 
    Full time
    Work experience placement
    Local area
    Worldwide

    CME- Group

    Chicago, IL
    3 days ago
  •  ...future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers. As a Senior Lead Security Engineer at JPMorgan Chase within Cybersecurity and Technology Controls, you are an integral part of an agile team that delivers... 

    JP Morgan Chase

    Wilmington, DE
    5 days ago
  • Labcorp is seeking a Lead Network Security Engineer - Palo Alto to join our team at our Durham, NC location!Location: Durham, NC.Applicants who live within 35 miles of Durham, NC location will follow a hybrid schedule. This schedule includes a minimum of three in office... 
    Full time
    Temporary work
    Casual work
    Internship
    Work at office
    Remote work
    Monday to Friday
    Flexible hours
    Day shift
    3 days per week

    Laboratory Corporation of America

    Durham, NC
    4 days ago
  •  ...where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the...  ...of the world's largest and most influential companies.As a Lead Security Engineer at JPMorgan Chase within the Cybersecurity and Technology... 

    JP Morgan Chase

    Plano, TX
    4 days ago
  •  ...where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the...  ...of the world's largest and most influential companies.As a Lead Security Engineer at JPMorgan Chase within the Cybersecurity Technology &... 

    JP Morgan Chase

    Tampa, FL
    2 days ago
  • $120.5k - $180.7k

    The Lead Offensive Security Engineer will lead hands-on offensive security testing across Ecolab’s commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile applications, APIs, cloud... 
    Hourly pay
    Minimum wage
    Full time
    Local area
    Flexible hours

    Ecolab

    Naperville, IL
    22 hours ago
  • $178.9k - $252.7k

     ...).What you'll doJoin our Cloud & Infrastructure Security team as a Technical Leader to define the strategy, lead the programs, deliver automation, and drive the...  ...supporting response and remediation efforts with engineering teamsEstablish technical security baselines and... 
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    DocuSign

    Seattle, WA
    3 days ago
  •  ...future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.As a Senior Lead Security Engineer at JPMorganChase within the, you are an integral part of an agile team that works to deliver software solutions that... 
    For contractors

    JP Morgan Chase

    Plano, TX
    5 days ago
  • $143.76k - $269.55k

    Job DescriptionWe’re seeking a Lead, SDLC Security Engineering (Manager) to lead the implementation, operation, and adoption of security tooling, automated guardrails, and secure SDLC practices across the Productivity Solutions Division. This role will manage a small security... 
    Full time
    Local area
    Remote work

    Agilent Technologies

    Santa Clara, CA
    3 days ago
  • As a Senior Lead Software Security Engineer at JPMorganChase, you are an integral part of an agile team that works to enhance, build, and deliver trusted technology products in a secure, stable, and scalable way. Drive significant business impact through your capabilities... 
    For contractors

    JP Morgan Chase

    Plano, TX
    1 day ago
  • Take on a crucial role where you'll be a key part of a high-performing team delivering secure software solutions. As a Lead Security Engineer at JPMorganChase within the CTC, you are an integral part of team that works to deliver software solutions that satisfy pre-defined... 

    JP Morgan Chase

    Plano, TX
    1 day ago
  •  ...cybersecurity team where your expertise in cryptographic infrastructure and secure hardware directly protects the financial systems trusted by millions of people around the globe.As a Sr Lead Security Engineer at JPMorganChase within the Cybersecurity & Technology Controls team... 

    JP Morgan Chase

    Seattle, WA
    1 day ago
  • $133.6k - $220.4k

    Job Classification:Technology - Engineering & CloudAre you interested in building capabilities...  ...your profession at one of the world’s leading financial services institutions. Your Team...  ...a highly skilled Lead Infrastructure Security Engineer with deep expertise in Cloud Access... 
    Full time
    Part time

    PGIM

    Newark, NJ
    3 days ago
  •  ...where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the...  ...of the world's largest and most influential companies.As a Lead Security Engineer at JPMorgan Chase within the CTC Emerging Technologies... 
    Contract work

    JP Morgan Chase

    Plano, TX
    5 days ago
  • $133.6k - $220.4k

    Job Classification:Technology - Engineering & CloudAre you interested in building capabilities...  ...advancing your profession at one of the world’s leading financial services institutions.  Your Team & RoleAs a Lead, Infrastructure Security Engineer in Security Services Data... 
    Full time
    Part time

    PGIM

    Newark, NJ
    4 days ago
  • $133.6k - $220.4k

    Job Classification:Technology - Engineering & CloudAre you interested in building capabilities that...  ...your profession at one of the world’s leading financial services institutions.Your Team & RoleAs a Lead Infrastructure Security Engineer in the Identity Governance and Administration... 
    Full time
    Part time

    PGIM

    Newark, NJ
    5 days ago
  • $127.5k - $236.5k

     ...technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Lead, Information Security Systems Engineering (ISSE) Job Code: 40400 Job Location: Chantilly, VA Job Schedule: 5/8 Monday - Friday Job... 
    Full time
    Remote work
    Monday to Friday
    Flexible hours

    L3Harris Technologies

    Chantilly, Loudoun County, VA
    2 hours ago
  • Boston, MAHybridFull Time$200k - $225kJob DescriptionA leading global investment management firm is hiring a Senior Cloud Security Engineer to join its cybersecurity team. The organization manages investment strategies across public and private markets for a global institutional... 
    Full time

    Motion Recruitment

    Boston, MA
    4 days ago
  • $132k - $238k

     ...recognized brands and one of America's leading retailers. But behind the brand our guests...  ...now, we are up to big things! Target's security team is a place where innovation happens...  ...culture that combines ongoing learning, engineering excellence, and stellar outcomes? We are... 
    Full time
    Contract work
    Temporary work
    Work experience placement
    Flexible hours

    Target

    Brooklyn Park, MN
    3 days ago
  •  ...ideal candidate will be able to start ASAP, have strong knowledge of various security initiatives including DLP, ISE, WIPs, Checkpoint, Cisco ASA, etc.• This person will be a technical lead on design and implementation. Strong documentation and oral skills are required... 
    Immediate start

    SA Technologies

    Atlanta, GA
    3 days ago
  • Corporate Security Engineering - Lead Engineer RoleAt BNY, our culture allows us to run our company better and enables employees’ growth and success. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the... 
    Work at office
    Remote work
    Worldwide
    Flexible hours

    The Bank of New York Mellon

    Pittsburgh, PA
    4 days ago
  • $275k - $395k

     ...Lead Security Engineer We're looking for a Lead Security Engineer to help build the security foundation. This is a hands-on role: you'll set technical direction for security across our product and infrastructure, go deep in the code and the cloud yourself, and help... 
    Work at office
    Local area

    SUNO

    Boston, MA
    2 days ago
  • Job SummaryAs a Senior Lead AI Security Engineer in our Cybersecurity team, you will design and deliver secure artificial intelligence solutions that support critical cyber use cases. You will play a key role in shaping platform standards and governance, collaborating with... 
    Work at office

    JP Morgan Chase

    Columbus, OH
    1 day ago
  •  ...RAs, ADCS, and HSM platforms. Implement and maintain secure cryptographic practices aligned with enterprise security standards...  ...and security compliance frameworks. Experience leading PKI engineering initiatives and mentoring technical teams. Required Experience... 
    Temporary work

    Techvilla Solutions

    Boston, MA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Security Engineer. Be the first to apply!