SC Cleared - Senior Security Engineer - Inside IR35

Sanderson Government & Defence

Greater London

On-site

GBP 77,000 - 129,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sanderson Government & Defence is seeking a Senior Security Engineer to own end-to-end security for government projects. You will embed security into delivery pipelines and build automation that keeps complex services secure by default.

You will raise the bar on engineering practices, shaping patterns and tooling across AWS, Azure, or GCP environments, and supporting threat modelling, vulnerability management, and incident response with a security-first mindset.

Qualifications

  • Strong hands-on experience securing cloud infrastructure in AWS, Azure, or GCP.
  • Experience embedding security tooling into CI/CD pipelines (SAST, DAST, SCA, container/IaC scanning).
  • Proficiency in at least one scripting/programming language (Python, Go, or similar) for building security automation and tooling.
  • Experience with detection engineering, creating and managing data streams (Cribl, Kinesis) and SIEM tooling (Splunk, QRadar, Sentinel, ArcSight).
  • Experience setting up segregated and secured hypervisor environments for testing potentially malicious software or code.

Responsibilities

  • Build secure architectures for cloud-native systems—apply secure-by-design patterns, zero-trust, least-privilege access.
  • Embed security into CI/CD pipelines, integrating SAST/DAST/SCA and IaC scanning.
  • Support threat modelling and design reviews with engineering teams using STRIDE and MITRE ATT&CK.
  • Build and maintain security tooling and automation from policy-as-code and IaC guardrails.
  • Support vulnerability management and incident response readiness; triage findings and improve playbooks.
  • Contribute to client engagements by surfacing architectural security recommendations.
  • Mentor engineers on secure coding and secure design through pairing and reviews.

Skills

Cloud security
CI/CD security tooling
Scripting
Detection engineering
Hypervisor security

Tools

Terraform
OPA/Conftest
Splunk
QRadar
Sentinel

Job description

SC Cleared - Senior Security Engineer - Inside IR35

  • Location: Bristol, Manchester, London
  • Type: 3 days on-site
  • Clearance: SC Cleared
  • IR35: Inside
  • Rate(s): £500 - £700 (Varying levels of Seniority)
  • Length: Initial 6 months

Sanderson G&D are seeking a number of Security Engineers for a range of Public Sector projects. As a Senior Security Engineer in our clients Cyber practice, you will need to be able to take end-to-end ownership of securing the systems they build; embedding security into delivery pipelines and building the tooling and automation that keep complex government services safe by default.

As a senior engineer, you will be expected to raise the bar on engineering practices around you; through the code and infrastructure you ship, the patterns you set, we believe security is a continuous engineering concern.

Key responsibilities
  • Build secure architectures for cloud-native systems - applying secure-by-design patterns, zero-trust principles, and least-privilege access across AWS, Azure, or GCP environments.
  • Embed security into CI/CD pipelines, integrating SAST, DAST, SCA, and infrastructure-as-code scanning so vulnerabilities are caught before they ship, not after.
  • Support threat modelling and design reviews with engineering teams, using structured methods (STRIDE, MITRE ATT&CK) to identify risks early and influence architecture decisions directly.
  • Build and maintain security tooling and automation from policy-as-code and IaC guardrails (Terraform, OPA/Conftest) to custom scripts and integrations that scale good security practice across teams.
  • Support vulnerability management by triaging findings from scanning and pentest engagements, prioritising by exploitability and impact, and applying mitigation and remediations.
  • Support incident response readiness - building detection and alerting into systems, running exercises, and improving playbooks based on what's actually observable in the stack.
  • Contribute to the commercial and technical health of engagements, flagging architectural risk early and surfacing opportunities to strengthen a client's security posture through better engineering, not more process.
Skills, knowledge and expertise
Essential
  • Strong hands-on experience securing cloud infrastructure in AWS, Azure, or GCP, including IAM design, network security, and secrets management.
  • Experience embedding security tooling into CI/CD pipelines (SAST, DAST, SCA, container/IaC scanning).
  • Proficiency in at least one scripting/programming language (Python, Go, or similar) for building security automation and tooling.
  • Experience with detection engineering, creating and managing data streams (Cribl, Kinesis) and SIEM tooling (Splunk, QRadar, Sentinel, ArcSight) , or building alerting/observability for security events from across an enterprise.
  • Experience setting up segregated and secured hypervisor environments for the testing of potentially malicious software or code.
Broader Skills
Desirable
  • Certifications such as OSCP, AWS/Azure/GCP security specialty certifications,
  • Experience with infrastructure-as-code (Terraform, CloudFormation, Pulumi) and policy-as-code enforcement (OPA, Sentinel, Checkov).
  • Experience supporting penetration testing and vulnerability scanning, and working closely with teaming team members to mitigate or remediate findings.
  • Working knowledge of container and Kubernetes security, image hardening, admission controls, runtime protection.
  • Familiarity with UK government security frameworks (GovAssure, NCSC Cyber Assessment Framework, HMG SPF)
  • Experience contributing reusable security patterns, tooling, or paved-road templates back into an engineering practice.
  • Evidence of mentoring engineers on secure coding and secure design, including pairing, code review, or internal training.
  • Experience co-designing solutions with engineering teams and stakeholders
Reasonable Adjustments:

Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Made Tech Limited • Bristol

On-site
GBP 55,000 - 75,000
30 days Holiday
Flexible Working Hours
Flexible Parental Leave
+2
Security Architect - SC Cleared
Security Architect - SC Cleared

Sanderson Government & Defence • Greater London

Hybrid
GBP 101,000 - 109,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Synergize Consulting Limited • Reading

Hybrid
GBP 81,000 - 115,000
Security Engineer (Site Reliability Engineering)
Security Engineer (Site Reliability Engineering)

Sanderson Government & Defence • Greater London

Hybrid
GBP 101,000 - 109,000
Senior Security Engineer
Senior Security Engineer

Made Tech Limited • Manchester

Hybrid
GBP 90,000 - 120,000
30 days Holiday
Flexible Working Hours
Remote Working
+1
SC Cleated Field Solutions Engineer
SC Cleated Field Solutions Engineer

Experis • City Of London

Hybrid
GBP 104,000 - 136,000
Technical Engineering/Project Manager - SC Cleared - Inside
Technical Engineering/Project Manager - SC Cleared - Inside

Sanderson Government & Defence • Oxford

On-site
GBP 92,000 - 148,000
Senior Security Architect
Senior Security Architect

develop • Greater London

Hybrid
GBP 90,000 - 110,000
Up to £110,000 salary
Benefits package
Remote or hybrid working
Lead Security Analyst
Lead Security Analyst

Made Tech Limited • Bristol

On-site
GBP 65,000 - 80,000
30 days Holiday
Flexible Working Hours
Remote Working – part-time
+5
Security Architect
Security Architect

TXP • City Of London

On-site