SC Cleared - Senior Security Engineer - Inside IR35

Sanderson Recruitment Plc
Manchester, UK
9 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Kubernetes Security Amazon Web Services Software System Penetration Testing Microsoft Azure Cloud Computing Code Review Software Design Patterns Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Key Management Network Security
+20 more
ArcSight SIEM Tool Zero Trust Network Access Secure Coding Security Information and Event Management Data Streaming Systems Integration Software Vulnerability Management Policy as Code Pulumi Scripting Google Cloud Delivery Pipeline Mitre Att&ck QRadar Cloudformation Terraform Splunk Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Sanderson G&D are seeking a number of Security Engineers for a range of Public Sector projects. As a Senior Security Engineer in our clients Cyber practice, you will need to be able to take end-to-end ownership of securing the systems they build; embedding security into delivery pipelines and building the tooling and automation that keep complex government services safe by default., * Build secure architectures for cloud-native systems - applying secure-by-design patterns, zero-trust principles, and least-privilege access across AWS, Azure, or GCP environments.

  • Embed security into CI/CD pipelines, integrating SAST, DAST, SCA, and infrastructure-as-code scanning so vulnerabilities are caught before they ship, not after.
  • Support threat modelling and design reviews with engineering teams, using structured methods (STRIDE, MITRE ATT&CK) to identify risks early and influence architecture decisions directly.
  • Build and maintain security tooling and automation from policy-as-code and IaC guardrails (Terraform, OPA/Conftest) to custom scripts and integrations that scale good security practice across teams.
  • Support vulnerability management by triaging findings from scanning and pentest engagements, prioritising by exploitability and impact, and applying mitigation and remediations.
  • Support incident response readiness - building detection and alerting into systems, running exercises, and improving playbooks based on what’s actually observable in the stack.
  • Contribute to the commercial and technical health of engagements, flagging architectural risk early and surfacing opportunities to strengthen a client’s security posture through better engineering, not more process.

Requirements

As a senior engineer, you will be expected to raise the bar on engineering practices around you; through the code and infrastructure you ship, the patterns you set, we believe security is a continuous engineering concern., * Strong hands-on experience securing cloud infrastructure in AWS, Azure, or GCP, including IAM design, network security, and secrets management.

  • Experience embedding security tooling into CI/CD pipelines (SAST, DAST, SCA, container/IaC scanning).
  • Proficiency in at least one scripting/programming language (Python, Go, or similar) for building security automation and tooling.
  • Experience with detection engineering, creating and managing data streams (Cribl, Kinesis) and SIEM tooling (Splunk, QRadar, Sentinel, ArcSight) , or building alerting/observability for security events from across an enterprise.
  • Experience setting up segregated and secured hypervisor environments for the testing of potentially malicious software or code., * Certifications such as OSCP, AWS/Azure/GCP security specialty certifications,
  • Experience with infrastructure-as-code (Terraform, CloudFormation, Pulumi) and policy-as-code enforcement (OPA, Sentinel, Checkov).
  • Experience supporting penetration testing and vulnerability scanning, and working closely with teaming team members to mitigate or remediate findings.
  • Working knowledge of container and Kubernetes security, image hardening, admission controls, runtime protection.
  • Familiarity with UK government security frameworks (GovAssure, NCSC Cyber Assessment Framework, HMG SPF)
  • Experience contributing reusable security patterns, tooling, or paved-road templates back into an engineering practice.
  • Evidence of mentoring engineers on secure coding and secure design, including pairing, code review, or internal training.
  • Experience co-designing solutions with engineering teams and stakeholders

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:55 min

Contrasting Terraform with Pulumi and cloud-specific tools

Devlin Duldulao · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:20 min

Overview of infrastructure as code tools

Alexander Bubeck · WWC 2023

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all