Lead Security Engineer
Summary
Hands-on technical lead who sets the direction for security engineering and testing at a Northern Ireland tech firm serving government, healthcare and financial clients. Day to day: penetration testing, security code review, threat modelling, embedding security in agile teams, and managing a small team of security engineers, using AWS/Azure, Burp Suite, OWASP ZAP, Nmap, Nessus, Kali and Metasploit
Lead Security Engineer (Security Testing & Engineering)
A hands-on technical leadership role setting the direction for security engineering and testing across a rapidly expanding cyber capability - remote-first within Northern Ireland, £70,000-£80,000.
About the Company
Our client is a well-established Northern Ireland technology business building platforms and services for government, healthcare and global financial organisations. Their cyber and AI security function has grown from a handful of people to around twenty in the past year and is building towards fifty. This role exists because the engineering side of that capability has reached the point where it needs someone to own its direction rather than simply deliver within it.
The Role
You will decide how security testing and engineering gets done here - the methodology, how engagements are scoped, what good output looks like and which tools the team standardises on - while staying hands-on enough to do the work yourself and stay credible with the agile delivery teams you sit alongside. Alongside that you will manage and develop a small group of engineers, and act as the technical voice that makes security risk land clearly with clients as well as colleagues.
Key Responsibilities
- Lead security engineering and security testing across the business's platforms and services.
- Set the direction on testing methodology, engagement scoping, outputs and tooling decisions.
- Perform and document penetration tests against web applications, networks and infrastructure.
- Assess application and infrastructure source code from a security standpoint.
- Embed security practice into agile delivery teams throughout the software development lifecycle.
- Run threat modelling workshops that translate technical risk into terms stakeholders can act on.
- Manage, coach and develop a small team of security engineers, owning performance and career development.
- Work with external penetration testing providers to turn report findings into actionable engineering work.
What You'll Need
Essential:
- Deep hands-on expertise securing web applications and cloud platforms on AWS or Azure, backed by a cloud certification.
- Expertise testing software and infrastructure security using manual and automated tooling such as Burp Suite, OWASP ZAP, Nmap, Nessus, Kali and Metasploit.
- Strong source code review capability across both application and infrastructure code.
- Working command of Continuous Security, CI and CD techniques, with programming or scripting across Linux, Windows or macOS.
- Fluency in the standards and attack patterns that shape the work - NCSC, NIST, CIS, PCI, GDPR, OWASP ASVS and the OWASP Top 10.
- Demonstrable experience managing, mentoring and coaching engineers, with the communication skills to convey security complexity to non-technical audiences.
Desirable:
- Penetration testing certifications such as OSCP, CREST or TIGER.
- Current UK security clearance, or clear eligibility to obtain it.
- Experience building security tooling or products rather than only consuming them.
- Detection engineering experience, or exposure to the Microsoft security stack including Sentinel and Defender.
- DevSecOps and secure software delivery experience in an agile environment.
- Active involvement in the security community through conference speaking, writing or open source contribution.
- Use of AI tooling within your own daily working practice.
Why Apply?
- Genuine ownership - you set the engineering and testing direction rather than inheriting someone else's.
- Remote-first working with minimal mandatory office attendance, from anywhere in Northern Ireland.
- £70,000-£80,000, with the band open to discussion for the right person.
- A capability more than doubling in size, where early hires are expected to become its future leaders.
- Client-facing work without the sales pressure - no targets, no revenue responsibility, around ten percent of the role.
- Technical depth is valued over breadth; this is a specialist team rather than a generalist consultancy.
- Work spanning citizen-facing government services, healthcare platforms and global financial systems.
Interested?
For a confidential conversation about the role, message Jordan Madden on LinkedIn.