Join a high-performing security team where you’ll work directly with engineering and product teams to embed security into the way modern software is designed, built and delivered.
This is a senior, hands-on security role for someone who is technically strong, comfortable working alongside developers and architects, and passionate about making security an enabler rather than a blocker.
You’ll join an established technology business entering an exciting period of security transformation, with the opportunity to influence both day-to-day engineering practices and the organisation’s longer-term security strategy.
The role Working closely with the CISO, security team and cross-functional engineering teams, you’ll help build security into the software development lifecycle from the outset.
A major focus will be
DevSecOps and application security, helping engineering teams identify and address security risks during design and development rather than finding them at the end of the delivery process.
You’ll be involved across: - Embedding security practices throughout the SDLC and DevOps lifecycle
- Working directly with developers, architects and platform teams on secure design and engineering
- Integrating security controls and automation into CI/CD pipelines
- Conducting code reviews, security testing and providing guidance around secure coding
- Supporting threat modelling and identifying application, API and cloud security risks
- Improving security automation, vulnerability management and security tooling
- Providing pragmatic security advice that enables engineering teams to continue delivering at pace
- Contributing to the organisation’s wider security strategy and programme of work
- Supporting security risk assessments, incident response and threat intelligence
- Helping evaluate and introduce emerging security technologies and approaches
- Mentoring other security professionals and helping lift security capability across the wider technology environment
What we're looking for We’re particularly interested in someone who has strong technical security foundations and understands how modern software engineering teams actually operate.
You’ll ideally bring: - Strong hands-on DevSecOps or application security experience
- Experience embedding security within engineering, development or product teams
- A good understanding of software development and the ability to engage credibly with experienced developers and architects
- Practical experience integrating security into CI/CD pipelines, including areas such as SAST, DAST, SCA and infrastructure-as-code scanning
- Strong knowledge of cloud security, ideally within Azure or another major cloud platform
- Experience securing modern architectures including APIs, containers, Kubernetes and/or serverless environments
- Knowledge of secure SDLC practices, threat modelling and secure coding principles
- Experience with security automation, vulnerability scanning and security testing tooling
- An understanding of security risk management and frameworks such as NIST and ISO 27001
- Strong communication skills and the confidence to challenge technical decisions constructively when required
Experience with Microsoft security technologies such as Entra ID, Defender, Sentinel or related Azure security services would be beneficial.
Certifications such as CISSP, CISM, CCSP or Azure Security Engineer Associate are advantageous but not essential.
Why consider this role? This isn't a role where security sits on the sidelines reviewing projects after the important technical decisions have already been made.
You’ll work alongside engineering teams, influence architecture and development practices, and help determine how security is built into products and platforms from the beginning.
There’s also plenty happening. The security function is evolving, there is a significant programme of work ahead, and you’ll have the opportunity to contribute to both immediate technical challenges and the future direction of security across the organisation.
If you enjoy being close to engineering, solving complex security problems and helping teams build secure technology without unnecessarily slowing delivery, we’d love to hear from you.
Apply now or get in touch for a confidential discussion.Job ref:DD4074531