> Markdown version of [/jobs/ext/2100289-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/2100289-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** Ocho - **Location:** Belfast, UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Automation of Tests, Microsoft Azure, Burp Suite, Cloud Computing, Code Review, Cyber Security, Nmap, Open Web Application Security, Security Software, Software Engineering, SQL Injection, Web Applications, Cross-Site Scripting (XSS), Metasploit, Nessus, Vulnerability Analysis - **Published:** August 18, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5845410162 ## About the Role our security testing methodology, outputs, and tool selection. Conduct source code reviews and embed security into CI/CD pipelines. Coach and develop a small team, supporting performance and career growth. Advise customers and colleagues on security best practice, translating complexity for varied audiences. Experience Expertise securing web applications and cloud platforms (AWS or Azure). Hands-on experience with manual and automated security testing tools. Strong knowledge of security standards such as NCSC, NIST, OWASP ASVS, GDPR, and PCI. Familiarity with common attack vectors including OWASP Top 10, XSS, SQL injection, and MITM. Experience in Continuous Security, CI, and CD practices. Proven ability to mentor and develop team members. Comfortable advising clients directly and communicating clearly with non-technical audiences. Desirable Penetration testing qualification such as OSCP, CREST, or TIGER. Experience with tools including Burp Suite, OWASP-ZAP, Nmap, Nessus, or Metasploit. ## Description Lead Security Engineer A senior technical role leading security engineering and testing within a cyber security team that has doubled in size over the past six months and is continuing to grow. The Opportunity This is a genuinely exciting moment to join. The team has gone from 6 to 16 people in six months, with plans to reach 30 to 35 within the year. It is led by a CISO who is quality-focused and culturally driven, building a commercially credible, specialist-led security practice rather than hiring for headcount. The Role You will lead security engineering and testing efforts, setting direction on methodology, tooling, and engagement scoping. Working alongside agile delivery teams, you will embed good security practice throughout the software development lifecycle, advise clients directly, and help grow the skills of more junior engineers. Day-to-day Lead security testing engagements, including penetration tests on web applications, networks, and infrastructure. Define and evolve ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)