Senior Security Assurance Engineer
Key details
- Compensation
- $75,000
Job Description
Salary: £75,000 - 75,000 per year
Requirements
- We require one of the following: Certified Information Systems Auditor (CISA), Systems Security Certified Practitioner (SSCP), or an equivalent audit and assurance practitioner credential.
- We welcome CRISC or CISSP as desirable certifications.
- We need experience advising clients on UK government security frameworks, including GovAssure, the NCSC Cyber Assessment Framework, Cyber Essentials Plus, and the HMG Security Policy Framework.
- We need experience leading risk assessments using structured methodologies such as ISO 27005, NIST RMF, or FAIR, and embedding risk outputs into programme governance.
- We need demonstrated ability to design security controls and governance approaches for cloud environments, including AWS, Azure, or GCP.
- We need working knowledge of incident response planning, including policy establishment and team readiness assessment.
- We need experience conducting or leading supply-chain security assessments, including third-party risk and software provenance.
- We need familiarity with tools for continuous compliance monitoring, automated controls testing, or cloud security posture management.
- We look for evidence of actively shaping your own development, including a T-shaped specialism, feedback seeking, and knowledge sharing.
- We value experience contributing reusable assets such as playbooks, templates, tooling, or patterns back into a practice or community.
- We value experience running or contributing to structured mentoring relationships, pairing sessions, or retrospectives that improved team capability or ways of working.
- We value experience co-designing solutions with clients and stakeholders, and delivering value anchored to outcomes rather than outputs.
- We value experience conducting skills-based assessment of candidates, contributing to interview scripts, or calibrating assessment criteria for fair and consistent evaluation.
- You must be eligible for SC security clearance, which requires 5 years UK residency and 5 years employment history or education history.
Responsibilities
- We design and lead security audits across complex government systems, combining automated scanning with manual testing and framing findings around risk and remediation.
- We drive continuous compliance monitoring against Cyber Essentials, the NCSC Cyber Assessment Framework, GovAssure, UK GDPR, and NIS Regulations.
- We lead risk assessments and threat-modelling sessions using proportionate methodologies such as ISO 27005, NIST RMF, STRIDE, or MITRE ATT&CK.
- We communicate security findings and risk clearly to technical teams and senior stakeholders, structuring reports around the decisions people need to make.
- We embed security as a continuous engineering concern throughout delivery, supporting threat modelling and security reviews, challenging risky designs, and mentoring colleagues on secure-by-default practices.
- We support and assess supply-chain and third-party security through proportionate assurance processes aligned with recognised standards.
- We mentor and coach colleagues and client team members, sharing knowledge openly and contributing to wider team capability.
- We contribute to the commercial and strategic health of engagements by managing scope, surfacing risks, and identifying unmet client needs.
Technologies
- AWS
- Azure
- Cloud
- GCP
- Support
- Security
More
We are Made Tech, a consultancy focused on helping UK public sector organisations build and run digital services that are secure, trustworthy, and resilient. We believe good security outcomes come from embedding security into delivery as a continuous concern, not bolting it on at the end. We offer a flexible benefits package that includes a Smart Tech scheme, Cycle to Work scheme, and an individual benefits allowance that can be used toward a healthcare cash plan or pension plan. We also provide 30 days of paid annual leave, flexible working hours, flexible parental leave, part-time remote working, paid counselling, and access to financial and legal advice. We support connection through an optional social and wellbeing calendar, and we encourage applicants from underrepresented groups to apply. We are hiring directly and welcome informal conversations with our talent team about the role and suitability.
last updated 31 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Range from 21 indexed roles at this employer: $40,000 - $100,000(mid ~80238)
Context may refresh in the background.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Security Engineer jobs, or every remote job category.
Lead Data Engineer
Senior Cloud Engineer
Cloud Engineer
Source: DevITJobs • Last updated 1d ago