Senior Security Assurance Engineer

Hackajob Ltd
Bristol, UK
1 day ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£75,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Information Systems Cloud Platform System Mitre Att&ck SC Clearance

Job description

  • We design and lead security audits across complex government systems, combining automated scanning with manual testing and framing findings around risk and remediation.
  • We drive continuous compliance monitoring against Cyber Essentials, the NCSC Cyber Assessment Framework, GovAssure, UK GDPR, and NIS Regulations.
  • We lead risk assessments and threat-modelling sessions using proportionate methodologies such as ISO 27005, NIST RMF, STRIDE, or MITRE ATT&CK.
  • We communicate security findings and risk clearly to technical teams and senior stakeholders, structuring reports around the decisions people need to make.
  • We embed security as a continuous engineering concern throughout delivery, supporting threat modelling and security reviews, challenging risky designs, and mentoring colleagues on secure-by-default practices.
  • We support and assess supply-chain and third-party security through proportionate assurance processes aligned with recognised standards.
  • We mentor and coach colleagues and client team members, sharing knowledge openly and contributing to wider team capability.
  • We contribute to the commercial and strategic health of engagements by managing scope, surfacing risks, and identifying unmet client needs.

Technologies:

  • AWS
  • Azure
  • Cloud
  • GCP
  • Support
  • Security

Requirements

  • We require one of the following: Certified Information Systems Auditor (CISA), Systems Security Certified Practitioner (SSCP), or an equivalent audit and assurance practitioner credential.
  • We welcome CRISC or CISSP as desirable certifications.
  • We need experience advising clients on UK government security frameworks, including GovAssure, the NCSC Cyber Assessment Framework, Cyber Essentials Plus, and the HMG Security Policy Framework.
  • We need experience leading risk assessments using structured methodologies such as ISO 27005, NIST RMF, or FAIR, and embedding risk outputs into programme governance.
  • We need demonstrated ability to design security controls and governance approaches for cloud environments, including AWS, Azure, or GCP.
  • We need working knowledge of incident response planning, including policy establishment and team readiness assessment.
  • We need experience conducting or leading supply-chain security assessments, including third-party risk and software provenance.
  • We need familiarity with tools for continuous compliance monitoring, automated controls testing, or cloud security posture management.
  • We look for evidence of actively shaping your own development, including a T-shaped specialism, feedback seeking, and knowledge sharing.
  • We value experience contributing reusable assets such as playbooks, templates, tooling, or patterns back into a practice or community.
  • We value experience running or contributing to structured mentoring relationships, pairing sessions, or retrospectives that improved team capability or ways of working.
  • We value experience co-designing solutions with clients and stakeholders, and delivering value anchored to outcomes rather than outputs.
  • We value experience conducting skills-based assessment of candidates, contributing to interview scripts, or calibrating assessment criteria for fair and consistent evaluation.
  • You must be eligible for SC security clearance, which requires 5 years UK residency and 5 years employment history or education history.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · World Congress 2022

2:06 min

Generating embeddings using the OpenAI API

Rainer Stropek Rainer Stropek · LIVE

Videos

See all

Related articles

See all