> Markdown version of [/jobs/ext/36151-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/36151-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** The World - **Location:** Baginton, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software as a Service, Cloud Computing Security, Cyber Security, Information Leak Prevention, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Open Web Application Security, Windows PowerShell, Zero Trust Network Access, Retail Software, Security Information and Event Management, Software Vulnerability Management, Scripting, Large Language Models, Cloudflare, Terraform, Marketplace, SentinelOne Expertise - **Published:** May 31, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=dce354eedb81072a ## About the Role Do you have experience in Terraform?, Do you have a Master's degree?, Essential: * 5+ years in security engineering or architecture, with clear progression in technical depth * Hands-on delivery across at least three of: cloud security (GCP/AWS), identity and access management (Entra ID), SIEM and detection engineering, DLP, zero trust * Sound judgment under uncertainty - you can make and defend security decisions with incomplete data * Practical AI and automation fluency - you use it habitually to multiply your impact * A track record of influencing engineering, product, and leadership stakeholders * Comfortable in a small, high-trust team where you set your own direction Nice to have: * Experience with Rapid7 InsightVM / InsightIDR, SentinelOne, Cloudflare, OneTrust, Microsoft Purview, or KnowBe4 * Background in e-commerce, marketplace, or retail technology * Familiarity with NIST CSF, ISO 27001, OWASP LLM Top 10, or similar frameworks * Infrastructure-as-code (Terraform), scripting (Python, PowerShell), or detection-as-code workflows ## Description As Lead Security Engineer, you'll design, build, and operate the controls that underpin our cyber resilience programme. You'll report directly to the Group Information Security Manager and work with real autonomy - shaping the roadmap, choosing the tools, and driving the engineering work that moves our security maturity forward. This is a genuinely hands-on role. You'll treat AI and automation as force multipliers, influence across IT, Engineering, Product, and Finance without holding formal authority, and leave decisions documented in a way that outlasts individuals. What You'll Focus On Your initial priorities will be: * Asset and Application Visibility: establishing continuous, automated discovery and ownership of our hardware, software, cloud, and SaaS estate * Zero Trust Enforcement: identity-aware access controls across remote and internal services * Data Loss Prevention: phased DLP coverage against our highest-risk data flows * Identity Lifecycle: strengthening JML processes in Entra ID and key SaaS platforms Your wider remit will grow to include detection engineering, vulnerability management, AI security governance, third-party risk, and security tooling strategy - you'll help set the sequence. ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fireside Chat with Cloudflare's Chief Strategy Officer, Stephanie Cohen (with Mike Butcher MBE)](https://www.wearedevelopers.com/videos/1366-fireside-chat-with-cloudflare-s-chief-strategy-officer-stephanie-cohen-with-mike-butcher-mbe) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)