Turn this role into an interview — a resume and cover letter built around what this employer wants.
Motability Operations Ltd is seeking a Security & Governance Engineer to partner with the Sustainability & Business Change programme, embedding security into design, development and operations. You will act as the primary security contact for SBC initiatives, guiding risk-based decisions and maturing the Information Security Front Door.
You will work with delivery teams to define security requirements, perform threat modelling, engage in security reviews and coordinate remediation with
Reporting to the Application Security Team Lead and Programme Manager for Sustainability & Business Change (SBC), the Security & Governance Engineer will act as the embedded security contact for the SBC programme, working closely with delivery squads to embed security throughout the design, implementation and operation of technology. Alongside this core responsibility, you'll support the wider Security Engineering function, helping mature how Information Security engages with delivery teams across Motability Operations.
As part of the Information Security function, you'll be the primary security contact for a portfolio of initiatives across the SBC programme. You'll provide practical, risk based security guidance that supports programme delivery, helping assess incoming requests, understand its security risk and determine the appropriate level of security engagement and assurance. Working alongside business analysts, architects, product owners, delivery managers and engineering teams, you'll help define security requirements, influence solution design and make sure security is considered at the right stages of the delivery lifecycle.
The role sits within the Application Security team, which forms part of a wider Information Security function of around 40 security professionals. You'll work closely with specialists across Application Security, Security Operations, Identity, IT Continuity, Security Architecture and Cloud Security, recognising when specialist expertise is required and bringing the right teams into delivery at the right time. You'll help teams navigate Information Security effectively while building strong relationships across the business.
You'll also play a role in operating and maturing the Information Security Front Door capability, helping teams engage with Information Security consistently and at the right point in delivery.
You'll help assess incoming demand, understand the level of security risk and coordinate the right level of assurance and specialist support, creating a straightforward and proportionate experience for teams seeking security guidance.
Although security consultancy is at the heart of the role, you'll remain technically engaged throughout delivery. You'll work alongside engineering teams to understand solutions, identify security risks, support threat modelling and design reviews, and provide practical guidance that helps teams build securely. Where deeper specialist knowledge is required, you'll work with colleagues across Information Security to bring the right expertise into delivery. It's well suited to someone who enjoys influencing outcomes through consultancy while remaining close to the technology and the teams building it.
Success in the role will be reflected in the quality of security engagement across the SBC programme, the maturity of the Information Security Front Door, and the consistent application of proportionate, risk based security assurance. You'll help improve threat modelling and security review practices, ensure security risks are clearly understood and prioritised, and help delivery teams access the right Information Security expertise when they need it. As the capability grows, you'll also have opportunities to mentor colleagues and contribute to the continued development of our Application Security operating model.
You're an experienced cyber security professional who enjoys working with people as much as solving technical problems. You understand that effective security comes from collaboration, helping delivery teams build secure solutions rather than acting as a gatekeeper. You're comfortable working with both technical and non-technical stakeholders, translating complex security concepts into clear, practical advice that supports informed decision making.
You have a strong consulting mindset and are comfortable managing multiple initiatives at the same time, balancing business priorities with security risk. Alongside your consultancy skills, you enjoy staying technically involved and taking opportunities to design and implement security improvements where they make a real difference. You're naturally curious, collaborative and always looking for ways to improve how security is delivered across the organisation.
You’ll need all of these.