Senior Security Engineer

Made Tech


Job Location:

London - UK

Yearly Salary: GBP 55000 - 75000
Posted on: 25 days ago
Vacancies: 1 Vacancy

Job Summary

We help UK public sector organisations build and run digital services that are secure trustworthy and resilient. As a Senior Security Engineer in our Cyber practice you will need to be able to take end-to-end ownership of securing the systems we build; embedding security into delivery pipelines and building the tooling and automation that keep complex government services safe by default.

This is a hands-on engineering role with real scope. You will work across client engagements where the stakes are high; services handling sensitive citizen data cloud-native systems built on AWS Azure or GCP and delivery teams shipping continuously under regulatory pressure (NCSC CAF NIS Regulations HMG Security Policy Framework). You will not be filling in compliance checklists; you will be building the controls pipelines and patterns that make secure delivery the path of least resistance.

As a senior engineer you will be expected to raise the bar on engineering practices around you; through the code and infrastructure you ship the patterns you set and by mentoring colleagues and client engineers we believe security is a continuous engineering concern. Youll be central to making that real.


Key Responsibilities


  • Build secure architectures for cloud-native systems applying secure-by-design patterns zero-trust principles and least-privilege access across AWS Azure or GCP environments.
  • Embed security into CI/CD pipelines integrating SAST DAST SCA and infrastructure-as-code scanning so vulnerabilities are caught before they ship not after.
  • Support threat modelling and design reviews with engineering teams using structured methods (STRIDE MITRE ATT&CK) to identify risks early and influence architecture decisions directly.
  • Build and maintain security tooling and automation from policy-as-code and IaC guardrails (Terraform OPA/Conftest) to custom scripts and integrations that scale good security practice across teams.
  • Support vulnerability management by triaging findings from scanning and pentest engagements prioritising by exploitability and impact and applying mitigation and remediations.
  • Support incident response readiness building detection and alerting into systems running exercises and improving playbooks based on whats actually observable in the stack.
  • Mentor and pair with engineers sharing secure coding and secure design practices directly in the codebase and helping client teams build their own security engineering capability over time.
  • Contribute to the commercial and technical health of engagements flagging architectural risk early and surfacing opportunities to strengthen a clients security posture through better engineering not more process.

Skills Knowledge & Expertise


Essential
  • Strong hands-on experience securing cloud infrastructure in AWS Azure or GCP including IAM design network security and secrets management.
  • Experience embedding security tooling into CI/CD pipelines (SAST DAST SCA container/IaC scanning).
  • Proficiency in at least one scripting/programming language (Python Go or similar) for building security automation and tooling.
  • Experience with detection engineering creating and managing data streams (Cribl Kinesis) and SIEM tooling (Splunk QRadar Sentinel ArcSight) or building alerting/observability for security events from across an enterprise.
  • Experience setting up segregated and secured hypervisor environments for the testing of potentially malicious software or code.
Desirable
  • Certifications such as OSCP AWS/Azure/GCP security specialty certifications
  • Experience with infrastructure-as-code (Terraform CloudFormation Pulumi) and policy-as-code enforcement (OPA Sentinel Checkov).
  • Experience supporting penetration testing and vulnerability scanning and working closely with teaming team members to mitigate or remediate findings.
  • Working knowledge of container and Kubernetes security image hardening admission controls runtime protection.
  • Familiarity with UK government security frameworks (GovAssure NCSC Cyber Assessment Framework HMG SPF)
  • Experience contributing reusable security patterns tooling or paved-road templates back into an engineering practice.
  • Evidence of mentoring engineers on secure coding and secure design including pairing code review or internal training.
  • Experience co-designing solutions with engineering teams and stakeholders
What you will bring:
  • Engineering-first instincts. You would rather fix a systemic issue with a pipeline check or a paved road than write another finding in a report.
  • A team-first mindset. You pair you share you coach and you make it safe for engineers to ask is this secure enough without getting a lecture.
  • Confidence communicating across boundaries. You can go from a Terraform PR review to explaining risk trade-offs to a delivery lead without switching brains.
  • Genuine ownership. You see security work through from beginning to the end recognising the importance of ownership of a solution not just recommending actions along the way.


Job Benefits


We are always listening to our growing teams and evolving the benefits available to our people. As we scale as do our benefits and we are scaling quickly. Weve recently introduced a flexible benefit platform which includes a Smart Tech scheme Cycle to work scheme and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan. Were also big on connection and have an optional social and wellbeing calendar of events for all employees to join should they choose to.

Here are some of our most popular benefits listed below:

An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result were looking for all successful candidates for this role to have eligibility.

Eligibility for SC requires 5 years UK residency and 5 year employment history (or back to full-time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC we wont be able to progress your application and we will contact you to let you know why.

Support in applying
If you need this job description in another format or other support in applying please email .

We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. Were collectively continuing to grow a culture that is happy healthy safe and inspiring for people of all backgrounds and experiences so we encourage people from underrepresented groups to apply for roles with us.

When you apply well put you in touch with a member of our talent team who can help with any needs or adjustments we may need to make to help with your application. Weve put together this blog as a resource to share more about reasonable adjustments and some examples of what this could include. We also welcome any feedback on how we can improve the experience for future candidates.

Required Experience:

Senior IC

We help UK public sector organisations build and run digital services that are secure trustworthy and resilient. As a Senior Security Engineer in our Cyber practice you will need to be able to take end-to-end ownership of securing the systems we build; embedding security into delivery pipelines and ...

About Company

Company Logo

We provide Digital, Data and Technology services to help organisations make a positive impact – fast.

View Profile View Profile