Made Tech
Lead Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Description
Made Tech helps UK government and public sector organisations build better digital services - and security is central to that mission. As a Lead Security Engineer in our Cyber practice, you'll be the most senior security engineering voice on client engagements, setting technical direction for how organisations design, build, and defend secure systems. You'll work across complex government programmes where the stakes are real: services that affect citizens, systems that hold sensitive data, and teams that need to move quickly without cutting corners.
This isn't a role where you sit at the edge of delivery reviewing outputs. You'll be embedded in multidisciplinary teams, shaping how security is engineered into everyday work - from threat modelling and architecture at design time to hardened, monitored systems in production. You'll build trusted relationships with client engineering leads, platform teams, and senior stakeholders, translating between deep technical decisions and the trade-offs senior leaders need to understand. You'll bring the judgement to know when a heavyweight security architecture is warranted and when a lighter-weight, faster-moving approach serves the engagement better.
At Lead level, your impact extends beyond the immediate team. You'll establish security engineering standards and reference architectures across engagements, grow the technical capability of the people around you — colleagues and client engineers alike — and contribute to how Made Tech's Cyber practice develops as a community. If you'd rather build the paved road than police the off-road, who treat security as an engineering discipline rather than a compliance exercise, and who cares about leaving client teams genuinely stronger than you found them, this role is for you.
Key Responsibilities
- Own end-to-end technical security architecture across engagements. Design secure-by-default reference architectures, set patterns for identity, network, and data protection, and maintain living technical standards — feeding directly into how teams build, not just how they're audited.
- Lead vulnerability remediation as an engineering programme. Define the prioritisation framework — drawing on EPSS, KEV, CVSS, and asset criticality — set remediation SLAs, own the risk-acceptance register, and drive fixes directly into delivery backlogs alongside product teams. Report programme KPIs (MTTR by severity, backlog age, coverage, recurrence rate) to senior stakeholders.
- Drive security into the team's normal engineering rhythm. Embed threat modelling, secure code review, SAST, SCA, dependency policy, and container scanning into design and delivery cycles — building the tooling and automation that make this the default, not a specialist handover at the end of a sprint.
- Navigate UK government security standards with confidence — as an engineer, not a paperwork exercise. Design systems and controls that satisfy the NCSC Cyber Assessment Framework, GovAssure, Cyber Essentials, and HMG Security Policy Framework, applying them proportionately across engagements as guardrails that enable safe delivery, not barriers to it. Engage with government security communities and coordinate with departmental technical teams.
- Communicate security risk in terms that drive engineering decisions. Report system posture, remediation programme performance, and architectural risk to senior client stakeholders — tailoring the frame for the audience and structuring reports around the decisions the reader needs to make, not just the findings.
- Set the standard for incident response and detection engineering. Build and drive adoption of detection, alerting, and IR tooling across engagements, own the IR-to-vulnerability-management feedback loop, and coordinate cross-team exercises including known-exploited-vulnerability scramble drills.
- Grow the people around you. Mentor colleagues across the practice and at client organisations, pair on complex or unfamiliar engineering problems, and create structured development opportunities — including for client engineers who may not yet have strong security habits.
- Contribute to Made Tech's Cyber practice beyond delivery. Shape practice standards, contribute to hiring and technical calibration, build and share expertise externally, and help grow a security engineering community that raises capability across the organisation.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Skills, Knowledge and Expertise
Essential
- Deep hands-on experience designing and building secure cloud architectures (AWS, Azure, or GCP) at scale, including IAM, network segmentation, and data protection patterns.
- Proven track record embedding security tooling and automation into CI/CD pipelines and engineering workflows across multiple teams.
- Strong proficiency in at least one programming/scripting language, used to build production-grade security tooling (not just scripts).
Desirable
The following would strengthen your application. We don't expect every candidate to bring all of these.
Certifications
- OSCP, OSWE, or equivalent offensive security credential
- AWS/Azure/GCP security specialty certification
- CKS (Certified Kubernetes Security Specialist)
Capabilities and experience
- Experience establishing and operating vulnerability remediation programmes at organisational scale — including risk-based prioritisation using EPSS, KEV, and asset criticality, and driving fixes across multiple delivery teams.
- Evidence of designing systems that satisfy UK government security frameworks — GovAssure, CAF, Cyber Essentials, HMG Security Policy Framework — in a complex multi-supplier or multi-team environment, as an architect rather than an assessor.
- Experience conducting or coordinating technical security reviews and penetration testing in UK public sector contexts, including remediating findings and briefing senior technical stakeholders.
- Working knowledge of exposure management beyond CVE-only approaches — incorporating misconfiguration, identity exposure, and attack-path analysis using cloud-native tooling (AWS Inspector, GuardDuty, Security Hub, or equivalents).
- Experience securing software supply chains — SBOM generation, dependency provenance, artifact signing — and integrating this into build pipelines rather than a standalone assurance process.
- Experience building or shaping security engineering capability within a consultancy, programme delivery, or multi-client environment — including growing technical skills in colleagues and client teams.
- Evidence of acting as a trusted technical adviser to senior client stakeholders — anchoring recommendations on engineering outcomes, challenging briefs constructively, and making security value visible through what gets shipped.
- Experience setting team ways of working in iterative delivery environments — establishing retrospective cadences, collaborative problem-solving norms, and pairing practices that spread security knowledge across the team.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Tooling and practice familiarity
- Deep familiarity with structured threat modelling approaches — STRIDE, MITRE ATT&CK, attack trees — and experience embedding these into agile delivery ceremonies.
- Experience integrating SAST, SCA, dependency scanning, and container security tooling into CI/CD pipelines as part of a shift-left security approach, including building custom tooling where off-the-shelf doesn't fit.
Made Tech sponsors attainment of recognised cyber certifications for staff in scope. If you don't yet hold the listed credentials but are actively working toward them, or can demonstrate equivalent capability through your experience, we'd still welcome your application.
What We Will Provide You
Balancing Life and Work:
- ✈️ Flexible Holiday – We trust you to take as much holiday as you need
- 🕰️ Flexible Working Hours – We are flexible with what hours you work
- 🗓️ Flexible Working Days – We are flexible to the amount of days you work in a week
- 👶 Flexible Parental Leave – We provide flexible parental leave options
- 👩 💻 Remote Working – We offer part-time remote working for all our staff
- 🤗 Paid counselling – We offer paid counselling as well as financial and legal advice
- 🏖️ Paid anniversary break – We celebrate your 3 and 5 year anniversary with us by buying your family a holiday
Making Work as Fabulous as Possible:
- 💻 Work Ready – We'll buy you a Macbook, ergonomic equipment, books, conferences, training, and more
- 💡 Learning – We offer 12 days per year of personal learning time and a £300 personal learning budget
- 🍽️ Friday Lunches – We randomly match up 8 colleagues every Friday and pay for lunch
- 🍻 Friday Drinks – We pay for social drinks on a Friday
Compensating You Fairly:
- 💷 Transparent Salary Bands – We publish salary bands so you know you're being fairly compensated
- 👌 Annual Salary Reviews – We review your salary on an annual basis
- ⛷️ Pension Scheme – We provide a pension scheme so you can save for your future and we'll contribute to it
- 🚄 Season Ticket Loan – We provide loans to help you pay for your travel
- 🚲 Cycle To Work Scheme – We offer the cycle to work scheme to help pay for your bicycle
- 🚕 Expenses Paid – Taxi to a meeting? Want to take a customer to lunch? Expenses are no hassle!
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London