Lead Software Security Engineer

Lead Software Security Engineer

Edinburgh Full-Time 59100 - 82500 £ / year (est.) No home office possible
F

At a Glance

  • Tasks: Lead secure product development and conduct security reviews in a collaborative environment.
  • Company: Join the FCA, a key regulator ensuring fairness in UK financial markets.
  • Benefits: Enjoy hybrid working, 25 days holiday, private healthcare, and a strong pension scheme.
  • Why this job: Make a real impact in public service while growing your tech skills in a supportive culture.
  • Qualifications: Experience in software development, secure coding, and cloud security is essential.
  • Other info: We value diversity and offer adjustments for accessibility throughout the application process.

The predicted salary is between 59100 - 82500 £ per year.

The Lead Security Engineer role is responsible for technical oversight of secure product development, security testing and security operations. You will work closely with FCA product owners, architects, service managers, and third-party suppliers who provide the development resources to the FCA to:

  • Embed secure engineering practices in development workflows, ensuring compliance with Secure by Design principles
  • Conduct structured and ad hoc security reviews of code, infrastructure and CI/CD pipelines
  • Define and document secure development lifecycle (SDLC) processes aligned with product needs
  • Lead security education initiatives for development teams and product stakeholders
  • Establish and enforce security requirements for new features, APIs and system enhancements
  • Assess and improve security maturity, advocating risk-based methodologies, tooling and automation

What will you get from the role?

  • Opportunity to grow in a technology-focused career with meaningful skill development
  • Supportive and collaborative team culture, fostering strong internal and cross-team connections
  • Purpose-driven environment, united by a shared commitment to public service and impact
  • Emphasis on work-life balance, prioritising smart working over excessive hours
  • Empowering workplace that values autonomy, trust and effective decision-making
  • Genuine commitment to diversity, inclusion and leadership with strong interpersonal skills

Which skills are required?

  • Minimum experience in commercial software development, secure coding practices and cloud security services (ideally AWS)
  • Experience in reviewing code security, leading cyber incident resolution and improving security processes in development teams
  • Experience working with microservices architecture and implementing security tooling in a development context

Essential:

  • Strong commercial awareness, assessing supplier proposals and driving cost-effective security solutions
  • Ability to integrate security with software innovation while ensuring adherence to organisational standards
  • Expertise in security methodologies, including threat modelling and risk assessment
  • Deep understanding of technology trends and industry standards in information security
  • Proven track record of delivering security-focused assets, including incident reports, secure coding templates and training programmes

Desirable:

  • Familiarity with the FCA, its remit, and strategic priorities
  • Relevant security certifications, including CompTIA Security+, GSEC, CySA+, CCSP, OSCP or CISSP

Our Values & Diversity:

We are proud to be an inclusive employer and our ambition is to cultivate a culture for all employees that respects their individual strengths, views, and experiences. We believe that our differences and similarities enable us to be a better organisation – one that makes better decisions, drives innovation, and delivers better regulation.

Benefits of working at the FCA:

  • 25 days holiday per year plus bank holidays
  • Hybrid working (work from home up to 60% of your time)
  • Private healthcare with Bupa
  • A non-contributory Pension of at least 8% of basic salary each month
  • Life assurance of eight times your basic salary
  • Income protection
  • Competitive flexible benefits scheme which gives you the opportunity to create a personalised benefits package, tailored to suit your lifestyle.

Application Support:

We are dedicated to removing barriers and ensuring our application process is accessible to everyone. We offer a range of adjustments to make your application experience as comfortable and straightforward as possible.

Useful Information and Timeline:

  • This role is graded as: Lead Associate - Regulatory
  • Advert Closing Date: Midnight 07 July
  • CV Review/Shortlist: w/c 07 July
  • First Round Case Study Assessment: w/c 14 July
  • Competency Based Interview: w/c 28 July

If you have a question, please contact: benjamin.paulon@fca.org.uk. Applications must be submitted through our online portal. Applications sent via email will not be accepted.

Lead Software Security Engineer employer: Financial Conduct Authority

The FCA is an exceptional employer, offering a supportive and collaborative work culture that prioritises employee growth and well-being. With a strong commitment to diversity and inclusion, employees benefit from a purpose-driven environment, flexible working arrangements, and a comprehensive benefits package, including private healthcare and a generous pension scheme. Located in vibrant cities like Edinburgh and Leeds, the FCA provides meaningful career opportunities in a technology-focused role that directly impacts public service.
F

Contact Detail:

Financial Conduct Authority Recruiting Team

benjamin.paulon@fca.org.uk

StudySmarter Expert Advice 🤫

We think this is how you could land Lead Software Security Engineer

✨Tip Number 1

Familiarise yourself with the FCA's mission and values. Understanding their commitment to public service and regulatory excellence will help you align your responses during interviews, showcasing how your personal values resonate with theirs.

✨Tip Number 2

Brush up on your knowledge of secure coding practices and cloud security services, particularly AWS. Being able to discuss specific examples of how you've implemented these in past roles will demonstrate your expertise and readiness for the position.

✨Tip Number 3

Prepare to discuss your experience with microservices architecture and security tooling. Highlighting your hands-on experience in these areas will show that you can effectively integrate security within software innovation, a key requirement for this role.

✨Tip Number 4

Consider obtaining relevant security certifications if you haven't already. Certifications like CompTIA Security+ or CISSP can bolster your application and demonstrate your commitment to professional development in the field of security engineering.

We think you need these skills to ace Lead Software Security Engineer

Commercial Software Development
Secure Coding Practices
Cloud Security Services (AWS)
Code Security Review
Cyber Incident Resolution
Microservices Architecture
Security Tooling Implementation
Strong Commercial Awareness
Integration of Security with Software Innovation
Security Methodologies (Threat Modelling, Risk Assessment)
Understanding of Technology Trends in Information Security
Delivery of Security-Focused Assets
Relevant Security Certifications (CompTIA Security+, GSEC, CySA+, CCSP, OSCP, CISSP)
Leadership and Training Skills
Ability to Advocate for Security Best Practices

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in software development, secure coding practices, and cloud security services. Emphasise your familiarity with microservices architecture and any security certifications you hold.

Craft a Strong Cover Letter: In your cover letter, express your passion for security engineering and how your skills align with the FCA's mission. Mention specific examples of how you've embedded secure engineering practices in previous roles.

Showcase Your Technical Skills: Detail your experience with security methodologies, threat modelling, and risk assessment. Provide examples of security-focused assets you've delivered, such as incident reports or training programmes.

Prepare for the Interview: Research the FCA's values and strategic priorities. Be ready to discuss how you can contribute to their goals, particularly in enhancing security processes and fostering a collaborative team culture.

How to prepare for a job interview at Financial Conduct Authority

✨Understand Secure by Design Principles

Familiarise yourself with the Secure by Design principles as they are crucial for this role. Be prepared to discuss how you have embedded secure engineering practices in your previous projects and how you can apply these principles at the FCA.

✨Showcase Your Technical Expertise

Highlight your experience in commercial software development, secure coding practices, and cloud security services, particularly AWS. Be ready to provide examples of how you've reviewed code security and led cyber incident resolutions in past roles.

✨Demonstrate Leadership in Security Education

The role involves leading security education initiatives. Prepare to discuss any training programmes or workshops you've conducted in the past, and how you plan to advocate for security best practices among development teams at the FCA.

✨Be Ready for Scenario-Based Questions

Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about how you would approach security reviews of code, infrastructure, and CI/CD pipelines, and be ready to articulate your thought process clearly.

F
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>