> Markdown version of [/jobs/ext/1119535-lead-security-engineer-independent-contractor](https://www.wearedevelopers.com/jobs/ext/1119535-lead-security-engineer-independent-contractor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - Independent Contractor - **Company:** Ironsail - **Location:** UK (Remote available) - **Experience:** Expert - **Salary:** £31,429.0 - £47,133.0 - **Contract:** Contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Systems Engineering, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Engineering, Code Review, Cyber Security, Continuous Integration, Cursor (Graphical User Interface Elements), Linux, DevOps, Digital Forensics, Multi-Factor Authentication, Identity and Access Management, Python (Programming Language), Key Management, Network Security, Linux System Administration, Log Analysis, Windows PowerShell, Role-Based Access Control, Reliability Engineering, Phishing, Software Engineering, Software Vulnerability Management, Backup and Restore, EndPointSecurity, Scripting, Cloud Platform System, Cyberark, GitHub Copilot, Software Security, Kubernetes, Deployment Automation, Hashicorp, Nessus, Terraform, GPT, Devsecops, Qualys, Docker, Security Orchestration, Automation & Response - **Published:** July 2, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=db9e0ad0a9e937cc ## About the Role We are specifically looking for engineers. Candidates should have 7+ years of hands-on experience in one or more of the following: * DevOps Engineering * DevSecOps * Infrastructure Engineering * Systems Engineering * Cloud Engineering * Site Reliability Engineering (SRE) * Security Engineering * Senior Software Engineering with infrastructure ownership Required Technical Experience You have personally implemented production security controls including: * Linux administration * AWS, Azure and/or GCP * Identity & Access Management * Privileged Access Management * MFA * Endpoint Detection & Response * Vulnerability Management * Network Security * Backup & Disaster Recovery You also have experience with: * Python * Bash * PowerShell * CI/CD security * Infrastructure as Code * Kubernetes * Docker * Cloud-native infrastructure What We're Looking For You are a builder. You can walk into an unfamiliar environment, quickly understand how systems work, identify the highest-risk security issues, prioritize what matters, and begin implementing improvements. You've built security programs-not simply audited them. You don't hand engineering teams a list of recommendations. You implement the solutions yourself. You enjoy startups, ambiguity, ownership, and solving difficult engineering problems. Nice to Have * Healthcare or pharmaceutical experience * HIPAA * CyberArk * Delinea * HashiCorp Vault * Kubernetes Security * Terraform * Incident Response * Digital Forensics Certifications are appreciated but not required, including: * CISSP * CISM * CISA * Security+ * AWS Security Specialty This Role Is Not a Fit If * Your experience is primarily governance, compliance, or auditing. * You have never personally implemented production security controls. * You rely on engineering teams to deploy your recommendations. * You prefer strategy and policy over hands-on engineering. * You are uncomfortable being the first dedicated security owner. ## Description * Site Reliability Engineer (SRE) * Security Engineer * Senior Software Engineer with infrastructure ownership If your experience is primarily governance, compliance, auditing, consulting, or risk management, this role is unlikely to be the right fit. If you've personally built infrastructure, secured cloud environments, automated deployments, implemented production security controls, and enjoy owning technical outcomes, we'd love to speak with you. Why This Role Is Different This isn't joining an existing security department. You'll build it. You'll become the technical owner responsible for designing, implementing, and continuously improving security across our cloud infrastructure, applications, engineering processes, and internal systems. You'll work directly with Engineering, DevOps, Product, and Leadership to establish security as a core engineering function-not a compliance checkbox. You'll have significant autonomy to shape how security is implemented across the company. Why We're Hiring Following a recent internal security review, we've identified several areas requiring dedicated ownership, including: * Privileged Access Management (PAM) * Endpoint security * Identity & Access Management (IAM) * Vulnerability Management * Backup & Disaster Recovery * Security monitoring and alerting * Security automation * Formal onboarding and offboarding processes * Access governance * Security architecture ownership Today these responsibilities are distributed across Engineering and DevOps. We want one experienced engineer to own them. What You'll DoSecurity Engineering * Assess existing cloud infrastructure and security posture * Design and implement security architecture improvements * Harden Linux systems and cloud environments * Secure applications, endpoints, and production infrastructure * Design practical remediation strategies * Build scalable security standards Implement and manage * Privileged Access Management (PAM) * Identity & Access Management (IAM) * Multi-Factor Authentication (MFA) * Endpoint Detection & Response (EDR) * Backup & Disaster Recovery * Network Security * Secrets Management, * Nessus * Qualys * Security monitoring platforms * Alerting * Security metrics * Configuration reviews * Security code reviews * Internal security assessments * Access reviews * Phishing simulations Own remediation through completion. Security Operations * Respond to incidents * Perform root cause analysis * Improve monitoring * Automate repetitive security tasks * Improve operational resilience * Design secure engineering workflows Identity & Access Management Own: * Employee onboarding * Employee offboarding * Role-based access control * Privileged account governance * Least-privilege access * Periodic access reviews Compliance Security comes first. Compliance follows. You'll support initiatives including: * HIPAA * SOC 2 * ISO 27001 You'll also: * Support vendor security reviews * Coordinate penetration tests * Assist cyber insurance requirements * Drive remediation of audit findings AI-First Engineering Ironsail is an AI-first engineering company. We expect our Lead Security Engineer to use AI every day. Examples include: * Threat investigations * Security research * Log analysis * Incident response * Security automation * Python scripting * Report generation * Vulnerability remediation * Infrastructure analysis We expect candidates to already be comfortable using tools such as: * Claude * ChatGPT * Gemini * Cursor * GitHub Copilot * Similar AI engineering tools Candidates should be able to explain how AI improves their daily engineering workflow., * Have you personally been responsible for building or significantly improving a security program in an organization where no dedicated security function previously existed? * Do you actively use AI tools (ChatGPT, Claude, Gemini, Copilot, Cursor, etc.) as part of your daily cybersecurity workflow? * Have you personally implemented and managed security controls such as PAM, MFA, endpoint protection, vulnerability management, or access control systems in a production environment? * Are you comfortable serving as the first dedicated security hire and independently identifying, prioritizing, and remediating security risks with minimal oversight? ## Related Videos - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Speak, Code, Deploy: Transforming Developer Experience with Voice Commands](https://www.wearedevelopers.com/videos/1159-speak-code-deploy-transforming-developer-experience-with-voice-commands) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)