> Markdown version of [/jobs/ext/2159882-senior-security-assurance-engineer](https://www.wearedevelopers.com/jobs/ext/2159882-senior-security-assurance-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Assurance Engineer - **Company:** Hackajob Ltd - **Location:** Bristol, UK (Remote available) - **Experience:** Expert - **Salary:** £75,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Information Systems, Cloud Platform System, Mitre Att&ck, SC Clearance - **Published:** August 21, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5849540721 ## About the Role * We require one of the following: Certified Information Systems Auditor (CISA), Systems Security Certified Practitioner (SSCP), or an equivalent audit and assurance practitioner credential. * We welcome CRISC or CISSP as desirable certifications. * We need experience advising clients on UK government security frameworks, including GovAssure, the NCSC Cyber Assessment Framework, Cyber Essentials Plus, and the HMG Security Policy Framework. * We need experience leading risk assessments using structured methodologies such as ISO 27005, NIST RMF, or FAIR, and embedding risk outputs into programme governance. * We need demonstrated ability to design security controls and governance approaches for cloud environments, including AWS, Azure, or GCP. * We need working knowledge of incident response planning, including policy establishment and team readiness assessment. * We need experience conducting or leading supply-chain security assessments, including third-party risk and software provenance. * We need familiarity with tools for continuous compliance monitoring, automated controls testing, or cloud security posture management. * We look for evidence of actively shaping your own development, including a T-shaped specialism, feedback seeking, and knowledge sharing. * We value experience contributing reusable assets such as playbooks, templates, tooling, or patterns back into a practice or community. * We value experience running or contributing to structured mentoring relationships, pairing sessions, or retrospectives that improved team capability or ways of working. * We value experience co-designing solutions with clients and stakeholders, and delivering value anchored to outcomes rather than outputs. * We value experience conducting skills-based assessment of candidates, contributing to interview scripts, or calibrating assessment criteria for fair and consistent evaluation. * You must be eligible for SC security clearance, which requires 5 years UK residency and 5 years employment history or education history. ## Description * We design and lead security audits across complex government systems, combining automated scanning with manual testing and framing findings around risk and remediation. * We drive continuous compliance monitoring against Cyber Essentials, the NCSC Cyber Assessment Framework, GovAssure, UK GDPR, and NIS Regulations. * We lead risk assessments and threat-modelling sessions using proportionate methodologies such as ISO 27005, NIST RMF, STRIDE, or MITRE ATT&CK. * We communicate security findings and risk clearly to technical teams and senior stakeholders, structuring reports around the decisions people need to make. * We embed security as a continuous engineering concern throughout delivery, supporting threat modelling and security reviews, challenging risky designs, and mentoring colleagues on secure-by-default practices. * We support and assess supply-chain and third-party security through proportionate assurance processes aligned with recognised standards. * We mentor and coach colleagues and client team members, sharing knowledge openly and contributing to wider team capability. * We contribute to the commercial and strategic health of engagements by managing scope, surfacing risks, and identifying unmet client needs. Technologies: * AWS * Azure * Cloud * GCP * Support * Security ## Related Videos - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [AI for Enterprise Developers - Dr. Damir Dobric](https://www.wearedevelopers.com/videos/1831-ai-for-enterprise-developers-dr-damir-dobric) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)