
Real job — pulled straight from Made Tech’s careers page · Verified July 15, 2026 · No reposts.
Job description
Made Tech is hiring a Senior Security Assurance Engineer — a full-time, remote role. Apply directly on Made Tech's careers page below.
Senior Security Engineer
Department: Technology
Employment Type: Permanent
Location: l, l, Any UK Office Hub (Bristol / London / Manchester / Swansea), Hybrid
This is a hands-on engineering role with real scope. You will work across client engagements where the stakes are high; services handling sensitive citizen data, cloud-native systems built on AWS, Azure or GCP, and delivery teams shipping continuously under regulatory pressure (NCSC CAF, NIS Regulations, HMG Security Policy Framework). You will not be filling in compliance checklists; you will be building the controls, pipelines, and patterns that make secure delivery the path of least resistance.
Key Responsibilities
- Build secure architectures for cloud-native systems — applying secure-by-design patterns, zero-trust principles, and least-privilege access across AWS, Azure, or GCP environments.
- Embed security into CI/CD pipelines, integrating SAST, DAST, SCA, and infrastructure-as-code scanning so vulnerabilities are caught before they ship, not after.
- Support threat modelling and design reviews with engineering teams, using structured methods (STRIDE, MITRE ATT&CK) to identify risks early and influence architecture decisions directly.
- Build and maintain security tooling and automation from policy-as-code and IaC guardrails (Terraform, OPA/Conftest) to custom scripts and integrations that scale good security practice across teams.
- Support vulnerability management by triaging findings from scanning and pentest engagements, prioritising by exploitability and impact, and applying mitigation and remediations.
- Support incident response readiness — building detection and alerting into systems, running exercises, and improving playbooks based on what's actually observable in the stack.
- Mentor and pair with engineers, sharing secure coding and secure design practices directly in the codebase, and helping client teams build their own security engineering capability over time.
- Contribute to the commercial and technical health of engagements, flagging architectural risk early and surfacing opportunities to strengthen a client's security posture through better engineering, not more process.
Skills, Knowledge & Expertise
- Strong hands-on experience securing cloud infrastructure in AWS, Azure, or GCP, including IAM design, network security, and secrets management.
- Experience embedding security tooling into CI/CD pipelines (SAST, DAST, SCA, container/IaC scanning).
- Proficiency in at least one scripting/programming language (Python, Go, or similar) for building security automation and tooling.
- Experience with detection engineering, creating and managing data streams (Cribl, Kinesis) and SIEM tooling (Splunk, QRadar, Sentinel, ArcSight) , or building alerting/observability for security events from across an enterprise.
- Experience setting up segregated and secured hypervisor environments for the testing of potentially malicious software or code.
- Certifications such as OSCP, AWS/Azure/GCP security specialty certifications,
- Experience with infrastructure-as-code (Terraform, CloudFormation, Pulumi) and policy-as-code enforcement (OPA, Sentinel, Checkov).
- Experience supporting penetration testing and vulnerability scanning, and working closely with teaming team members to mitigate or remediate findings.
- Working knowledge of container and Kubernetes security, image hardening, admission controls, runtime protection.
- Familiarity with UK government security frameworks (GovAssure, NCSC Cyber Assessment Framework, HMG SPF)
- Experience contributing reusable security patterns, tooling, or paved-road templates back into an engineering practice.
- Evidence of mentoring engineers on secure coding and secure design, including pairing, code review, or internal training.
- Experience co-designing solutions with engineering teams and stakeholders
- Engineering-first instincts. You would rather fix a systemic issue with a pipeline check or a paved road than write another finding in a report.
- A team-first mindset. You pair, you share, you coach — and you make it safe for engineers to ask "is this secure enough?" without getting a lecture.
- Confidence communicating across boundaries. You can go from a Terraform PR review to explaining risk trade-offs to a delivery lead without switching brains.
- Genuine ownership. You see security work through from beginning to the end, recognising the importance of ownership of a solution, not just recommending actions along the way.
Job Benefits
At this point, we hope you're feeling excited about Made Tech and the job opportunity. Get in touch with our talent team if you’d like an informal chat about the role and your suitability before applying. We are hiring for this role directly, so will not respond to any CVs sent via external recruitment agencies.
SC Eligibility
Support in applying
Working hours: Our standard hours are Monday to Friday, but the nature of this role means some work outside normal hours may be required, for example during release and change windows, planned maintenance, or to align with client operating hours. This is occasional rather than routine, and we'll always give as much notice as we can and agree it with you in advance wherever possible.
Get Senior Security Assurance Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
Is Senior Security Assurance Engineer at Made Tech a remote job?
Yes, Senior Security Assurance Engineer at Made Tech is a remote position. Candidates in Bristol, UK, London, UK, Manchester, UK, Swansea, UK may be preferred.
What skills are required for Senior Security Assurance Engineer at Made Tech?
The required skills for Senior Security Assurance Engineer at Made Tech include: CISA, CISSP, AWS, Azure, GCP, SIEM.
What is the seniority level for Senior Security Assurance Engineer at Made Tech?
Senior Security Assurance Engineer at Made Tech is a Senior level position.
How do I apply for Senior Security Assurance Engineer at Made Tech?
You can view the full description and apply for Senior Security Assurance Engineer at Made Tech on EchoJobs: https://echojobs.io/job/made-tech-senior-security-assurance-engineer-technology-3i7f8.