Lead Security Engineer

The World
Baginton, UK
17 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
ÂŁ85,451.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Software as a Service Cloud Computing Security Cyber Security Information Leak Prevention Identity and Access Management Intrusion Detection and Prevention Open Web Application Security Zero Trust Network Access Retail Software Security Information and Event Management
+5 more
Software Vulnerability Management Large Language Models Cloudflare Marketplace SentinelOne Expertise

Job description

World of Books Group UK-based | Remote / Hybrid World of Books Group Permanent, Full-time “This is a role for someone who wants to shape rather than maintain.” The Opportunity World of Books Group is a certified B Corp and one of the world’s largest sellers of pre-loved books, operating across the UK, US, and Hungary. Our technology estate spans cloud platforms, e-commerce marketplaces, in-house engineering, and a broad SaaS footprint - and we’re looking for the person who will make it safer. As Lead Security Engineer, you’ll design, build, and operate the controls that underpin our cyber resilience programme. You’ll report directly to the Group Information Security Manager and work with real autonomy - shaping the roadmap, choosing the tools, and driving the engineering work that moves our security maturity forward. This is a genuinely hands-on role. You’ll treat AI and automation as force multipliers, influence across IT, Engineering, Product, and Finance without holding formal authority, and leave decisions documented in a way that outlasts individuals. What You’ll Focus On Your initial priorities will be: Asset and Application Visibility: establishing continuous, automated discovery and ownership of our hardware, software, cloud, and SaaS estate Zero Trust Enforcement: identity-aware access controls across remote and internal services Data Loss Prevention: phased DLP coverage against our highest-risk data flows

Requirements

Identity Lifecycle: strengthening JML processes in Entra ID and key SaaS platforms Your wider remit will grow to include detection engineering, vulnerability management, AI security governance, third-party risk, and security tooling strategy - you’ll help set the sequence. What We’re Looking For Essential: 5+ years in security engineering or architecture, with clear progression in technical depth Hands-on delivery across at least three of: cloud security (GCP/AWS), identity and access management (Entra ID), SIEM and detection engineering, DLP, zero trust Sound judgment under uncertainty - you can make and defend security decisions with incomplete data Practical AI and automation fluency - you use it habitually to multiply your impact A track record of influencing engineering, product, and leadership stakeholders Comfortable in a small, high-trust team where you set your own direction Nice to have: Experience with Rapid7 InsightVM / InsightIDR, SentinelOne, Cloudflare, OneTrust, Microsoft Purview, or KnowBe4 Background in e-commerce, marketplace, or retail technology Familiarity with NIST CSF, ISO 27001, OWASP LLM Top 10, or similar frameworks

Benefits & conditions

Infrastructure-as-code (Terraform), scripting (Python, PowerShell), or detection-as-code workflows What We Offer Competitive salary, plus Group benefits Remote / hybrid working, UK-based, with flexible London office presence A clear mandate to drive change - not maintain the status quo A modern toolchain: Rapid7 (MDR), SentinelOne, OneTrust, and AI tooling at org level A business with genuine mission - B Corp certified, sustainability-led, and growing What Success Looks Like in Year One A current, trusted view of the full asset and application estate with clear ownership A progressing zero trust enforcement capability, with measurable reduction in implicit-trust paths Meaningful reduction in manual audit effort across security controls Trusted cross-functional relationships - you’re seen as someone who unblocks, not gates Sound like you? We’d love to hear from you. Apply via LinkedIn or send your CV directly. We review applications on a rolling basis.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:56 min

Configuring server-side rendering and Cloudflare deployment

Francesco Napoletano Francesco Napoletano ¡ World Congress 2024

3:06 min

Joining a new marketplace with a distributed engineering team

John Bettiol ¡ World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

1:21 min

Deploying serverless logic directly to Cloudflare Workers

Edoardo Dusi ¡ LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ World Congress 2022

Videos

See all

Related articles

See all