Made Tech

Lead Security Engineer

Made Tech
Apply
2 months ago
London, United KingdomStaff+

Responsibilities

  • Own technical security architecture, secure-by-default reference architectures, identity, network, and data protection patterns across engagements.
  • Lead vulnerability remediation programmes, including risk prioritisation, remediation SLAs, risk acceptance, delivery-backlog integration, and KPI reporting.
  • Embed threat modelling, secure code review, SAST, SCA, dependency policy, and container scanning into engineering workflows.
  • Design and implement controls aligned with the NCSC Cyber Assessment Framework, GovAssure, Cyber Essentials, and HMG Security Policy Framework.
  • Communicate security posture, remediation performance, and architectural risk to senior client stakeholders.
  • Build and drive adoption of detection, alerting, and incident-response tooling, including the IR-to-vulnerability-management feedback loop.
  • Mentor colleagues and client engineers, contribute to hiring and technical calibration, and help develop the Cyber practice and security engineering community.

Requirements

  • Deep hands-on experience designing and building secure cloud architectures at scale using AWS, Azure, or GCP, including IAM, network segmentation, and data protection patterns.
  • Proven experience embedding security tooling and automation into CI/CD pipelines and engineering workflows across multiple teams.
  • Strong proficiency in at least one programming or scripting language used to build production-grade security tooling.
  • Experience with vulnerability remediation programmes, risk-based prioritisation, UK government security frameworks, technical security reviews, penetration testing, exposure management, and software supply-chain security is desirable.
  • Familiarity with AWS Inspector, GuardDuty, Security Hub, SBOM generation, dependency provenance, artifact signing, and cloud-native exposure analysis is desirable.
  • Familiarity with STRIDE, MITRE ATT&CK, attack trees, SAST, SCA, dependency scanning, and container security tooling is desirable.
  • OSCP, OSWE, an equivalent offensive-security credential, a cloud security specialty certification, or CKS certification would strengthen the application.
  • Equivalent capability through experience is accepted for candidates who do not hold the listed credentials.

Benefits

  • 30 days of paid annual leave.
  • Flexible working hours and part-time remote working for all staff.
  • Flexible parental leave options.
  • Paid counselling plus financial and legal advice.
  • Smart Tech and Cycle to Work schemes, an individual benefits allowance usable for a healthcare cash plan or pension plan, and optional social and wellbeing events.
  • Made Tech sponsors recognised cyber certification attainment for staff in scope.
  • Standard working hours are Monday to Friday, with occasional work outside normal hours during release or change windows, planned maintenance, or client operating hours.
Made Tech

About Made Tech

501-1,000 employees

Made Tech designs, builds, and operates digital services for the UK public sector, including central government, local authorities, and the NHS. Its consulting-led model covers agile delivery, cloud engineering, DevOps, and bespoke software across technologies like Ruby on Rails, Node.js, and Go. Founded in 2012 and headquartered in London, the company is publicly listed and has delivered services such as Homes for Ukraine and digital access to NHS support.

Contact me