Lead Security Engineer

Made Tech

Manchester

Hybrid

GBP 60,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

30 days of paid annual leave
Flexible working hours
Remote working options
Paid counselling services

Job summary

Made Tech is seeking a Lead Security Assurance Engineer in Manchester, focusing on enhancing security capabilities within public sector organizations. In this role, you'll establish assurance frameworks, lead vulnerability management programmes, and mentor colleagues while ensuring effective communication of security risks to clients.

Your expertise in navigating UK government security standards and your ability to integrate security assurance into engineering workflows will be key in driving impactful change. A supportive environment with flexible working hours and growth opportunities awaits you.

Qualifications

  • Experience in leading vulnerability management programmes at an organisational scale.
  • Proficiency in navigating UK government security standards.
  • Ability to communicate security risk effectively to senior stakeholders.

Responsibilities

  • Own end-to-end assurance across engagements.
  • Develop risk-based assurance frameworks and maintain evidence of control effectiveness.
  • Mentor colleagues and client staff to enhance security capabilities.

Skills

Certified Information Systems Auditor (CISA)
Certified Information Systems Security Professional (CISSP)

Job description

Made Tech helps UK government and public sector organisations build better digital services — and security is central to that mission. As a Lead Security Assurance Engineer in our Cyber practice, you'll be the most senior security assurance voice on client engagements, setting the technical direction for how organisations identify, assess, and respond to security risk. You'll work across complex government programmes where the stakes are real: services that affect citizens, systems that hold sensitive data, and teams that need to move quickly without cutting corners.

This isn't a role where you sit at the edge of delivery reviewing outputs. You'll be embedded in multidisciplinary teams, shaping how security assurance is woven into everyday engineering work — from threat modelling at design time to control testing in production. You'll build trusted relationships with client security teams, senior stakeholders, and government security communities, translating between technical findings and the risk decisions that senior leaders need to make. You'll bring the judgement to know when a full ISO 27001 governance programme is appropriate and when a lighter-weight approach serves the engagement better.

At Lead level, your impact extends beyond the immediate team. You'll establish assurance frameworks and standards across engagements, grow the security capability of the people around you — colleagues and client staff alike — and contribute to how Made Tech's Cyber practice develops as a community. If you're someone who builds capability rather than gatekeeping decisions, who treats security as an engineering concern rather than a compliance exercise, and who cares about leaving client teams genuinely stronger than you found them, this role is for you.

Key responsibilities
  • Own end-to-end assurance across engagements. Establish risk-based assurance frameworks, coordinate audit programmes, and maintain living evidence of control effectiveness — feeding findings into vulnerability management backlogs and governance reporting rather than treating audits as point-in-time events.
  • Lead vulnerability management as a programme, not a process. Define the prioritisation framework — drawing on EPSS, KEV, CVSS, and asset criticality — set remediation SLAs, own the risk-acceptance register, negotiate remediation plans with IT operations and product teams, and report programme KPIs (MTTR by severity, backlog age, coverage, recurrence rate) to senior stakeholders.
  • Drive security into the team's normal rhythm. Embed threat modelling, secure code review, SAST, SCA, dependency policy, and container scanning into design and delivery cycles — making security a shared engineering responsibility rather than a specialist handover at the end of a sprint.
  • Navigate UK government security standards with confidence. Apply the NCSC Cyber Assessment Framework, GovAssure, Cyber Essentials, HMG Security Policy Framework, and relevant legislation (UK GDPR, NIS Regulations) proportionately across engagements — framing standards as guardrails that enable safe delivery, not barriers to it. Engage with government security communities and coordinate with departmental security teams.
  • Communicate security risk in terms that drive decisions. Report security posture, audit findings, and vulnerability programme performance to senior client stakeholders — tailoring the frame for the audience, showing trends over time, and structuring reports around the decisions the reader needs to make, not just the findings.
  • Set the standard for incident response and detection readiness. Drive adoption of incident response practices across engagements, own the IR-to-vulnerability-management feedback loop, and coordinate cross-team exercises including known-exploited-vulnerability scramble drills.
  • Grow the people around you. Mentor colleagues across the practice and at client organisations, pair on complex or unfamiliar assurance work, and create structured development opportunities — including for client engineers who may not yet have strong security habits.
  • Contribute to Made Tech's Cyber practice beyond delivery. Shape practice standards, contribute to hiring and calibration, build and share expertise externally, and help grow a security assurance community that raises capability across the organisation.
Skills, knowledge and expertise
  • Hold one of the following — Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) — or an equivalent senior audit and assurance credential.

The following would strengthen your application. We don't expect every candidate to bring all of these.

Certifications
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Security Manager (CISM)
  • NCSC Certified Cyber Professional (CCP)
Capabilities and experience
  • Experience establishing and operating vulnerability management programmes at organisational scale — including risk-based prioritisation using EPSS, KEV, and asset criticality, and managing remediation across multiple delivery teams
  • Evidence of leading compliance programmes against UK government frameworks — GovAssure, CAF, Cyber Essentials, HMG Security Policy Framework — in a complex multi-supplier or multi-team environment
  • Experience conducting or coordinating security audits in UK public sector contexts, including producing formal findings and briefings for senior government stakeholders
  • Working knowledge of exposure management beyond CVE-only approaches — incorporating misconfiguration, identity exposure, and attack-path analysis using cloud-native tooling (AWS Inspector, GuardDuty, Security Hub, or equivalents)
  • Experience assessing and assuring supply chain security — including third-party and vendor risk — and integrating supplier risk into wider assurance and governance programmes
  • Experience building or shaping security assurance capability within a consultancy, programme delivery, or multi-client environment — including growing technical security skills in colleagues and client teams
  • Evidence of acting as a trusted adviser to senior client stakeholders — anchoring security recommendations on client outcomes, challenging briefs constructively, and making security value visible rather than reporting activity
  • Experience setting team ways of working in iterative delivery environments — establishing retrospective cadences, collaborative problem-solving norms, and pairing practices that spread security knowledge across the team
Tooling and practice familiarity
  • Familiarity with structured threat modelling approaches — STRIDE, MITRE ATT&CK, attack trees — and experience embedding these into agile delivery ceremonies
  • Experience integrating SAST, SCA, dependency scanning, and container security tooling into CI/CD pipelines as part of a shift-left security approach

Made Tech sponsors attainment of recognised cyber certifications for staff in scope. If you don't yet hold the listed credentials but are actively working toward them, or can demonstrate equivalent capability through your experience, we'd still welcome your application.

We are always listening to our growing teams and evolving the benefits available to our people. As we scale, as do our benefits and we are scaling quickly. We've recently introduced a flexible benefit platform which includes a Smart Tech scheme, Cycle to work scheme, and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan. We’re also big on connection and have an optional social and wellbeing calendar of events for all employees to join should they choose to.

Here are some of our most popular benefits listed below:

30 days Holiday - we offer 30 days of paid annual leave

Flexible Working Hours - we are flexible with what hours you work

Flexible Parental Leave - we offer flexible parental leave options

Remote Working - we offer part time remote working for all our staff

Paid counselling - we offer paid counselling as well as financial and legal advice

At this point, we hope you're feeling excited about Made Tech and the job opportunity. Get in touch with our talent team if you’d like an informal chat about the role and your suitability before applying. We are hiring for this role directly, so will not respond to any CVs sent via external recruitment agencies.

An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result, we’re looking for all successful candidates for this role to have eligibility.

Eligibility for SC requires 5 years' UK residency and 5 year' employment history (or back to full-time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC, we won't be able to progress your application and we will contact you to let you know why.

Support in applying

If you need this job description in another format, or other support in applying, please email talent@madetech.com.

We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. We’re collectively continuing to grow a culture that is happy, healthy, safe and inspiring for people of all backgrounds and experiences, so we encourage people from underrepresented groups to apply for roles with us.

When you apply, we’ll put you in touch with a member of our talent team who can help with any needs or adjustments we may need to make to help with your application. We’ve put together this blog as a resource to share more about reasonable adjustments and some examples of what this could include. We also welcome any feedback on how we can improve the experience for future candidates.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

Made Tech Limited • Bristol

On-site
GBP 75,000 - 90,000
30 days Holiday
Flexible Working Hours
Flexible Parental Leave
+2
Principal Security Architect
Principal Security Architect

Made Tech Limited • Greater London

Hybrid
GBP 90,000 - 130,000
30 days Holiday including bank holidays
Remote Working options
Paid counselling services
Senior Security Engineer
Senior Security Engineer

Made Tech Limited • Manchester

Hybrid
GBP 90,000 - 120,000
30 days Holiday
Flexible Working Hours
Remote Working
+1
Lead Technical Architect
Lead Technical Architect

Made Tech • Bristol, Greater London, Manchester, Swansea

Hybrid
GBP 70,000 - 90,000
30 days Holiday
Flexible Working Hours
Flexible Parental Leave
+2
Senior Security Analyst
Senior Security Analyst

Made Tech Limited • West of England

On-site
GBP 50,000 - 60,000
Lead Delivery Manager
Lead Delivery Manager

Made Tech Limited • City Of London

On-site
GBP 80,000 - 100,000
Paid counselling
Flexible benefits platform
Health cash plan
+3
Client Partner – Central Government
Client Partner – Central Government

慨正橡扯 • Bristol

On-site
GBP 90,000 - 140,000
30 days holiday
Remote working option (part-time)
Pension plan
Lead Delivery Manager
Lead Delivery Manager

Made Tech Limited • Greater London

On-site
GBP 90,000 - 120,000
Paid counselling
Flexible benefit platform
Cycle to work scheme
Senior Service Delivery Manager
Senior Service Delivery Manager

Made Tech Limited • Greater London

On-site
GBP 60,000 - 80,000
Paid counselling and legal advice
Flexible benefit platform
Optional social and wellness events
+1
Client Partner - central government
Client Partner - central government

Made Tech Limited • United Kingdom

Hybrid
GBP 90,000 - 150,000
Smart Tech scheme
Cycle to Work
Health care cash plan
+3