> Markdown version of [/jobs/ext/3564790-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/3564790-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** Encord - **Location:** London, UK - **Experience:** Expert - **Salary:** £91,932.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Software as a Service, Cloud Computing Security, DevOps, Identity and Access Management, Key Management, Network Segmentation, Open Source Intelligence, Anti-Phishing, Secure Coding, Security Information and Event Management, Software Vulnerability Management, EndPointSecurity, Data Logging, Data Processing, Spoofing, Bug Reporting, Terraform, Static Application Security Testing, Dynamic Application Security Testing - **Published:** October 3, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5909696331 ## About the Role * Around 7-8 years of hands-on security experience, with a strong focus on organisation security. * Experience rolling out or re-architecting SSO, MFA, and conditional access across a company. * Experience deploying and managing MDM and EDR across a macOS fleet. * A track record of building automated joiner/mover/leaver flows and user access reviews. * Experience running SaaS security, including discovering shadow IT, reviewing app permissions, and assessing new tools before adoption. * Experience putting guardrails around AI tool usage, such as approved tool lists, data handling rules, and vendor reviews of AI providers. * Ownership of, or significant contribution to, ISO 27001 and/or SOC 2 audits, including policies, control evidence, and auditor walkthroughs. * Experience defending against targeted phishing ("whaling") and business email compromise, such as fake CEO payment requests, invoice fraud, and gift card scams. * Experience leading or supporting security incidents such as phishing compromises, account takeovers, or lost devices. * Experience running third-party and vendor risk assessments and advising on the security of new tools before they're adopted. * Experience partnering with DevOps/Platform teams to secure cloud environments (ideally GCP), including IAM, network segmentation, secrets management, logging, and CSPM. * A habit of writing policies and runbooks that people can easily follow. * A thoughtful approach to change: you've rolled out new controls with clear communication, phased approaches, and a focus on keeping the employee experience smooth. Nice to have * Experience with Infrastructure-as-Code (e.g. Terraform). * Experience owning vulnerability management across infrastructure, including scanning, prioritisation, remediation tracking, and SLAs. * Experience building and improving detection and monitoring, centralising logs into a SIEM and defining meaningful alerts. * Experience implementing and tuning SAST, DAST, SCA, and secrets scanning in CI/CD pipelines. * Experience coordinating external penetration tests and bug reports, and driving fixes to closure with engineering teams. * Experience helping engineers write secure code through guidance, patterns, and lightweight training. * Experience supporting sales and customer trust by answering security questionnaires and joining customer security calls. * Familiarity with executive digital protection, such as OSINT footprint reviews, impersonation monitoring, and out-of-band verification for sensitive requests. ## Description We're looking for a Lead Security Engineer to own and mature how Encord secures its people, identities, devices, and the SaaS and AI tools we run the business on. You'll be hands-on, building and running controls yourself, while also owning the organisation security programme and acting as the go-to security expert across the company. You'll play a key role in protecting our leadership team from targeted attacks, serve as the technical backbone of our ISO 27001 and SOC 2 programmes, and partner with our DevOps and Platform teams on cloud security. Above all, you'll help us stay safe while keeping our pace. What you'll do * Own identity and access across Encord, including SSO, MFA, conditional access, and automated joiner/mover/leaver processes. * Manage our device security, keeping our macOS fleet protected through MDM and EDR. * Run SaaS and AI security: discovering shadow IT, reviewing app permissions, assessing new tools before adoption, and setting sensible guardrails for how AI tools are used. * Protect our executives and high-risk users from targeted phishing, impersonation, business email compromise, and AI-enabled fraud such as deepfakes. * Act as the technical owner of our ISO 27001 and SOC 2 controls, from policies and evidence through to auditor walkthroughs. * Lead third-party and vendor risk assessments. * Respond to and lead security incidents, and continuously improve how we detect and handle them. * Partner with DevOps and Platform to secure our cloud environment. * Write clear policies and runbooks, and roll out changes in a way that keeps the employee experience smooth.