Lead Security Engineer

Ocho
Belfast, UK
5 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Amazon Web Services Software System Penetration Testing Automation of Tests Microsoft Azure Burp Suite Cloud Computing Code Review Cyber Security Nmap Open Web Application Security Security Software Software Engineering
+6 more
SQL Injection Web Applications Cross-Site Scripting (XSS) Metasploit Nessus Vulnerability Analysis

Job description

Lead Security Engineer A senior technical role leading security engineering and testing within a cyber security team that has doubled in size over the past six months and is continuing to grow. The Opportunity This is a genuinely exciting moment to join. The team has gone from 6 to 16 people in six months, with plans to reach 30 to 35 within the year. It is led by a CISO who is quality-focused and culturally driven, building a commercially credible, specialist-led security practice rather than hiring for headcount. The Role You will lead security engineering and testing efforts, setting direction on methodology, tooling, and engagement scoping. Working alongside agile delivery teams, you will embed good security practice throughout the software development lifecycle, advise clients directly, and help grow the skills of more junior engineers. Day-to-day Lead security testing engagements, including penetration tests on web applications, networks, and infrastructure. Define and evolve

Requirements

our security testing methodology, outputs, and tool selection. Conduct source code reviews and embed security into CI/CD pipelines. Coach and develop a small team, supporting performance and career growth. Advise customers and colleagues on security best practice, translating complexity for varied audiences. Experience Expertise securing web applications and cloud platforms (AWS or Azure). Hands-on experience with manual and automated security testing tools. Strong knowledge of security standards such as NCSC, NIST, OWASP ASVS, GDPR, and PCI. Familiarity with common attack vectors including OWASP Top 10, XSS, SQL injection, and MITM. Experience in Continuous Security, CI, and CD practices. Proven ability to mentor and develop team members. Comfortable advising clients directly and communicating clearly with non-technical audiences. Desirable Penetration testing qualification such as OSCP, CREST, or TIGER. Experience with tools including Burp Suite, OWASP-ZAP, Nmap, Nessus, or Metasploit.

Benefits & conditions

Background working in agile delivery or consultancy environments. Active involvement in the security community. Package Share options Hybrid/Remote working - Belfast 35 days annual leave inc stat Enhanced pension scheme Private health Please apply now if you are meeting the above criteria or contact Andrew Harrison directly. Skills: Penetration testing Web application Cloud security OWASP CI/CD DevSecOps Benefits: Work From Home

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

1:17 min

Evaluating security vulnerabilities and user experience

Julian Richter Julian Richter · World Congress 2025

Videos

See all

Related articles

See all