SC Cleared - Senior Security Engineer - Inside IR35

SC Cleared - Senior Security Engineer - Inside IR35

Full-Time 63000 - 77000 £ / year (est.) No working from home possible
Sanderson Government and Defence

At a Glance

  • Tasks: Secure cloud systems and embed security into delivery pipelines for government projects.
  • Company: Join a leading tech firm focused on public sector security solutions.
  • Benefits: Competitive pay, flexible work arrangements, and opportunities for professional growth.
  • Other info: Inclusive workplace valuing diversity and offering support throughout the recruitment process.
  • Why this job: Make a real difference in securing vital government services while advancing your career.
  • Qualifications: Experience in cloud security, CI/CD integration, and scripting languages required.

The predicted salary is between 63000 - 77000 £ per year.

Location: Bristol, Manchester, London

Type: 3 days on-site

Clearance: SC Cleared

IR35: Inside

Rate(s): £500 - £700 (Varying levels of Seniority)

Length: Initial 6 months

Sanderson G&D are seeking a number of Security Engineers for a range of Public Sector projects. As a Senior Security Engineer in our clients Cyber practice, you will need to be able to take end-to-end ownership of securing the systems they build; embedding security into delivery pipelines and building the tooling and automation that keep complex government services safe by default. As a senior engineer, you will be expected to raise the bar on engineering practices around you; through the code and infrastructure you ship, the patterns you set, we believe security is a continuous engineering concern.

Key responsibilities:
  • Build secure architectures for cloud-native systems - applying secure-by-design patterns, zero-trust principles, and least-privilege access across AWS, Azure, or GCP environments.
  • Embed security into CI/CD pipelines, integrating SAST, DAST, SCA, and infrastructure-as-code scanning so vulnerabilities are caught before they ship, not after.
  • Support threat modelling and design reviews with engineering teams, using structured methods (STRIDE, MITRE ATT&CK) to identify risks early and influence architecture decisions directly.
  • Build and maintain security tooling and automation from policy-as-code and IaC guardrails (Terraform, OPA/Conftest) to custom scripts and integrations that scale good security practice across teams.
  • Support vulnerability management by triaging findings from scanning and pentest engagements, prioritising by exploitability and impact, and applying mitigation and remediations.
  • Support incident response readiness - building detection and alerting into systems, running exercises, and improving playbooks based on what's actually observable in the stack.
  • Contribute to the commercial and technical health of engagements, flagging architectural risk early and surfacing opportunities to strengthen a client's security posture through better engineering, not more process.
Skills, knowledge and expertise:
  • Essential: Strong hands-on experience securing cloud infrastructure in AWS, Azure, or GCP, including IAM design, network security, and secrets management.
  • Experience embedding security tooling into CI/CD pipelines (SAST, DAST, SCA, container/IaC scanning).
  • Proficiency in at least one scripting/programming language (Python, Go, or similar) for building security automation and tooling.
  • Experience with detection engineering, creating and managing data streams (Cribl, Kinesis) and SIEM tooling (Splunk, QRadar, Sentinel, ArcSight), or building alerting/observability for security events from across an enterprise.
  • Experience setting up segregated and secured hypervisor environments for the testing of potentially malicious software or code.
  • Broader Skills Desirable: Certifications such as OSCP, AWS/Azure/GCP security specialty certifications.
  • Experience with infrastructure-as-code (Terraform, CloudFormation, Pulumi) and policy-as-code enforcement (OPA, Sentinel, Checkov).
  • Experience supporting penetration testing and vulnerability scanning, and working closely with team members to mitigate or remediate findings.
  • Working knowledge of container and Kubernetes security, image hardening, admission controls, runtime protection.
  • Familiarity with UK government security frameworks (GovAssure, NCSC Cyber Assessment Framework, HMG SPF).
  • Experience contributing reusable security patterns, tooling, or paved-road templates back into an engineering practice.
  • Evidence of mentoring engineers on secure coding and secure design, including pairing, code review, or internal training.
  • Experience co-designing solutions with engineering teams and stakeholders.

Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

SC Cleared - Senior Security Engineer - Inside IR35 employer: Sanderson Government and Defence

Join a forward-thinking organisation that values user-centred design and offers a collaborative work environment in the heart of London. With a strong commitment to diversity and inclusion, we provide our employees with opportunities for professional growth while working on impactful government projects that shape digital services. Enjoy a flexible working model that balances on-site collaboration with remote work, ensuring a rewarding and meaningful career path.

Sanderson Government and Defence

Contact Details:

Sanderson Government and Defence Recruitment Team

We think you need these skills to ace SC Cleared - Senior Security Engineer - Inside IR35

Cloud Security (AWS, Azure, GCP)
IAM Design
Network Security
Secrets Management
CI/CD Pipeline Security Integration (SAST, DAST, SCA)
Scripting/Programming (Python, Go)
Detection Engineering