Back to search
Anson McCade Linkedin · Posted 28d ago

Lead Security Engineer

United Kingdom

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

An opportunity is available for an experienced Senior Security Engineer to join a high-performing technology team delivering secure, cloud-native software solutions for enterprise and public sector clients.


This role sits at the intersection of application security, cloud security and DevSecOps, working within multi-disciplinary Agile teams to embed security controls throughout the Secure Software Development Lifecycle (SSDLC). The successful candidate will be responsible for implementing automated security tooling, driving vulnerability management practices and ensuring robust protection across modern cloud platforms.


The position requires strong technical capability, hands-on DevSecOps experience and the ability to influence engineering teams by promoting secure-by-design principles.


Key Responsibilities

  • Collaborate daily with application development and cloud engineering teams to integrate security requirements into Agile sprint planning and backlog prioritisation.
  • Embed DevSecOps practices across CI/CD pipelines, ensuring continuous security validation.
  • Implement and maintain automated security tooling, including:
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Secret scanning
  • Container security scanning
  • Software composition analysis
  • Automate compliance with cloud security baselines such as CIS Benchmarks.
  • Lead threat modelling sessions and vulnerability management initiatives.
  • Translate findings from security tools into prioritised, actionable security stories for delivery teams.
  • Validate implementation of architectural security patterns and secure coding standards.
  • Coordinate with external providers to scope and manage penetration testing activities.
  • Drive adoption of cyber security best practices within Agile software teams.
  • Mentor and develop junior engineers, fostering a security-first engineering culture.


Essential Requirements

  • Proven experience implementing application security or cloud platform security controls.
  • Experience working as an AI Security Engineer, securing AI/ML systems and data pipelines.
  • Strong understanding of web application security principles, including OWASP Top 10 risks.
  • Practical knowledge of modern cryptography, including:
  • Encryption in transit (TLS)
  • Encryption at rest
  • Hashing and digital signatures
  • Hands-on experience with:
  • Threat modelling
  • Vulnerability management
  • Application security testing
  • Penetration testing coordination
  • Experience integrating security tooling into CI/CD pipelines.


Proficiency with:

  • Git or modern version control systems
  • A scripting language (Bash, PowerShell)
  • A programming language (Python, Java, .NET, JavaScript)
  • Infrastructure as Code tools (Terraform, ARM Templates, Ansible)
  • Ability to clearly communicate complex security risks to both technical and non-technical stakeholders.


Desirable Experience

  • Industry-recognised cyber security certification.
  • Experience within Commercial, Public Sector or Defence environments.
  • AWS or Azure associate/mid-level certifications.
  • Active participation in the cyber security community (OWASP, Hack The Box, Capture the Flag events).
  • Experience working within Agile frameworks such as Scrum or Kanban.


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search