Rodeo
Get started

hackajob

Senior Security Engineer

United Kingdom
Posted about 19 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

hackajob is collaborating with Made Tech to connect them with exceptional professionals for this role.

We help UK public sector organisations build and run digital services that are secure, trustworthy, and resilient. As a Senior Security Engineer in our Cyber practice, you will need to be able to take end-to-end ownership of securing the systems we build; embedding security into delivery pipelines and building the tooling and automation that keep complex government services safe by default.

This is a hands-on engineering role with real scope. You will work across client engagements where the stakes are high; services handling sensitive citizen data, cloud-native systems built on AWS, Azure or GCP, and delivery teams shipping continuously under regulatory pressure (NCSC CAF, NIS Regulations, HMG Security Policy Framework). You will not be filling in compliance checklists; you will be building the controls, pipelines, and patterns that make secure delivery the path of least resistance.

As a senior engineer, you will be expected to raise the bar on engineering practices around you; through the code and infrastructure you ship, the patterns you set, and by mentoring colleagues and client engineers, we believe security is a continuous engineering concern. You'll be central to making that real.

Key responsibilities

  • Build secure architectures for cloud-native systems — applying secure-by-design patterns, zero-trust principles, and least-privilege access across AWS, Azure, or GCP environments.
  • Embed security into CI/CD pipelines, integrating SAST, DAST, SCA, and infrastructure-as-code scanning so vulnerabilities are caught before they ship, not after.
  • Support threat modelling and design reviews with engineering teams, using structured methods (STRIDE, MITRE ATT&CK) to identify risks early and influence architecture decisions directly.
  • Build and maintain security tooling and automation from policy-as-code and IaC guardrails (Terraform, OPA/Conftest) to custom scripts and integrations that scale good security practice across teams.
  • Support vulnerability management by triaging findings from scanning and pentest engagements, prioritising by exploitability and impact, and applying mitigation and remediations.
  • Support incident response readiness — building detection and alerting into systems, running exercises, and improving playbooks based on what's actually observable in the stack.
  • Mentor and pair with engineers, sharing secure coding and secure design practices directly in the codebase, and helping client teams build their own security engineering capability over time.
  • Contribute to the commercial and technical health of engagements, flagging architectural risk early and surfacing opportunities to strengthen a client's security posture through better engineering, not more process.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Skills, knowledge and expertise

Essential

  • Strong hands-on experience securing cloud infrastructure in AWS, Azure, or GCP, including IAM design, network security, and secrets management.
  • Experience embedding security tooling into CI/CD pipelines (SAST, DAST, SCA, container/IaC scanning).
  • Proficiency in at least one scripting/programming language (Python, Go, or similar) for building security automation and tooling.
  • Experience with detection engineering, creating and managing data streams (Cribl, Kinesis) and SIEM tooling (Splunk, QRadar, Sentinel, ArcSight), or building alerting/observability for security events from across an enterprise.
  • Experience setting up segregated and secured hypervisor environments for the testing of potentially malicious software or code.

Desirable

  • Certifications such as OSCP, AWS/Azure/GCP security specialty certifications,
  • Experience with infrastructure-as-code (Terraform, CloudFormation, Pulumi) and policy-as-code enforcement (OPA, Sentinel, Checkov).
  • Experience supporting penetration testing and vulnerability scanning, and working closely with teaming team members to mitigate or remediate findings.
  • Working knowledge of container and Kubernetes security, image hardening, admission controls, runtime protection.
  • Familiarity with UK government security frameworks (GovAssure, NCSC Cyber Assessment Framework, HMG SPF)
  • Experience contributing reusable security patterns, tooling, or paved-road templates back into an engineering practice.
  • Evidence of mentoring engineers on secure coding and secure design, including pairing, code review, or internal training.
  • Experience co-designing solutions with engineering teams and stakeholders

What You Will Bring

  • Engineering-first instincts. You would rather fix a systemic issue with a pipeline check or a paved road than write another finding in a report.
  • A team-first mindset. You pair, you share, you coach — and you make it safe for engineers to ask "is this secure enough?" without getting a lecture.
  • Confidence communicating across boundaries. You can go from a Terraform PR review to explaining risk trade-offs to a delivery lead without switching brains.
  • Genuine ownership. You see security work through from beginning to the end, recognising the importance of ownership of a solution, not just recommending actions along the way.

Job benefits

We are always listening to our growing teams and evolving the benefits available to our people. As we scale, as do our benefits and we are scaling quickly. We've recently introduced a flexible benefit platform which includes a Smart Tech scheme, Cycle to work scheme, and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan. We’re also big on connection and have an optional social and wellbeing calendar of events for all employees to join should they choose to.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Here are some of our most popular benefits listed below:

  • 30 days Holiday - we offer 30 days of paid annual leave
  • Flexible Working Hours - we are flexible with what hours you work
  • Flexible Parental Leave - we offer flexible parental leave options
  • Remote Working - we offer part time remote working for all our staff
  • Paid counselling - we offer paid counselling as well as financial and legal advice

At this point, we hope you're feeling excited about Made Tech and the job opportunity. Get in touch with our talent team if you’d like an informal chat about the role and your suitability before applying. We are hiring for this role directly, so will not respond to any CVs sent via external recruitment agencies.

SC Eligibility

An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result, we're looking for all successful candidates for this role to have eligibility.

Eligibility for SC requires 5 years' UK residency and 5 year' employment history (or back to full-time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC, we won't be able to progress your application and we will contact you to let you know why.

Support in applying

If you need this job description in another format, or other support in applying, please email talent@madetech.com.

We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. We’re collectively continuing to grow a culture that is happy, healthy, safe and inspiring for people of all backgrounds and experiences, so we encourage people from underrepresented groups to apply for roles with us.

When you apply, we’ll put you in touch with a member of our talent team who can help with any needs or adjustments we may need to make to help with your application. We’ve put together this blog as a resource to share more about reasonable adjustments and some examples of what this could include. We also welcome any feedback on how we can improve the experience for future candidates.

Working hours

Our standard hours are Monday to Friday, but the nature of this role means some work outside normal hours may be required, for example during release and change windows, planned maintenance, or to align with client operating hours. This is occasional rather than routine, and we'll always give as much notice as we can and agree it with you in advance wherever possible.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Cloud Security
AWS
Azure
GCP
CI/CD Pipelines
SAST/DAST/SCA
Python
Go
Terraform
SIEM
Threat Modelling
Incident Response
Kubernetes Security
IAM Design
Network Security
Policy-as-Code

Location

United Kingdom

Sign up to applySee more jobs like this