🛡️

Lead Security Engineer

📍 UK Permanent Cyber Security

Lead Security Engineer
London
£77,000

Our client operates a broad technology estate spanning cloud platforms, e-commerce, in-house engineering and an extensive SaaS footprint. Their cybersecurity function protects that estate against an evolving threat landscape while enabling the business to grow, comply and operate efficiently.

They are now appointing a Lead Security Engineer to design, build and operate the security controls that underpin their cyber resilience programme. Reporting directly to the Group Information Security Manager, your focus will be the architectural, engineering and programme work that moves the security maturity dial across the Group.

This is a role for someone who wants to shape rather than maintain. It is a lean function — you and the Group Information Security Manager are the security team. Priorities will shift with the business, scope will evolve, and you will be expected to pick up what needs picking up rather than wait for ideal-shape work.

What the position entails

– Translating identified security objectives into engineered, automated and durably-owned controls
– Designing, building and operating security controls across cloud, e-commerce, engineering and SaaS environments
– Reducing reliance on tacit knowledge by formalising capability through process and design
– Driving foundational visibility programmes across asset and application management, identity and data, moving towards continuous, evidence-based assurance
– Using AI and automation as deliberate force multipliers
– Partnering with IT, Engineering, Product, Operations, Finance and other stakeholders to embed security into how the business actually operates

What we’re looking for

– Strong hands-on security engineering and architecture experience across cloud and SaaS-heavy estates
– A builder’s mindset — someone who improves maturity rather than simply maintains controls
– Confidence working with limited oversight and sound independent judgment
– The ability to influence engineers, product teams and senior stakeholders without formal authority
– Comfort with automation and AI as practical tools
– Flexibility and pragmatism in a small, fast-moving function

What you get

– Permanent, full-time role with genuine ownership and influence
– Remote / hybrid working, with regular presence at a London office
– Direct line to the Group Information Security Manager and senior stakeholders
– The chance to shape a security programme from the ground up rather than inherit someone else’s