Lead Security Engineer

Lead Security Engineer

Full-Time 70000 - 90000 £ / year (est.) No working from home possible
W

At a Glance

  • Tasks: Lead the charge in shaping our cyber resilience programme and enhancing security controls.
  • Company: Join World of Books Group, a certified B Corp and leader in pre-loved books.
  • Benefits: Enjoy remote/hybrid work, flexible hours, and a modern toolchain.
  • Other info: Be part of a high-trust team where you set your own direction.
  • Why this job: Make a real impact in a mission-driven company focused on sustainability.
  • Qualifications: 5+ years in security engineering with hands-on experience in cloud security and identity management.

The predicted salary is between 70000 - 90000 £ per year.

This is a role for someone who wants to shape rather than maintain.

World of Books Group is a certified B Corp and one of the world's largest sellers of pre-loved books, operating across the UK, US, and Hungary. Our technology estate spans cloud platforms, e-commerce marketplaces, in-house engineering, and a broad SaaS footprint — and we're looking for the person who will make it safer.

As Lead Security Engineer, you'll design, build, and operate the controls that underpin our cyber resilience programme. You'll report directly to the Group Information Security Manager and work with real autonomy — shaping the roadmap, choosing the tools, and driving the engineering work that moves our security maturity forward.

This is a genuinely hands-on role. You'll treat AI and automation as force multipliers, influence across IT, Engineering, Product, and Finance without holding formal authority, and leave decisions documented in a way that outlasts individuals.

What You'll Focus On

  • Asset and Application Visibility: establishing continuous, automated discovery and ownership of our hardware, software, cloud, and SaaS estate
  • Zero Trust Enforcement: identity-aware access controls across remote and internal services
  • Data Loss Prevention: phased DLP coverage against our highest-risk data flows
  • Identity Lifecycle: strengthening JML processes in Entra ID and key SaaS platforms

Your wider remit will grow to include detection engineering, vulnerability management, AI security governance, third-party risk, and security tooling strategy — you'll help set the sequence.

What We're Looking For

  • 5+ years in security engineering or architecture, with clear progression in technical depth
  • Hands-on delivery across at least three of: cloud security (GCP/AWS), identity and access management (Entra ID), SIEM and detection engineering, DLP, zero trust
  • Sound judgment under uncertainty — you can make and defend security decisions with incomplete data
  • Practical AI and automation fluency — you use it habitually to multiply your impact
  • A track record of influencing engineering, product, and leadership stakeholders
  • Comfortable in a small, high-trust team where you set your own direction

Nice to have:

  • Experience with Rapid7 InsightVM / InsightIDR, SentinelOne, Cloudflare, OneTrust, Microsoft Purview, or KnowBe4
  • Background in e-commerce, marketplace, or retail technology
  • Familiarity with NIST CSF, ISO 27001, OWASP LLM Top 10, or similar frameworks

What We Offer

  • Remote / hybrid working, UK-based, with flexible London office presence
  • A clear mandate to drive change — not maintain the status quo
  • A modern toolchain: Rapid7 (MDR), SentinelOne, OneTrust, and AI tooling at org level
  • A business with genuine mission — B Corp certified, sustainability-led, and growing

What Success Looks Like in Year One

  • A current, trusted view of the full asset and application estate with clear ownership
  • A progressing zero trust enforcement capability, with measurable reduction in implicit-trust paths
  • Meaningful reduction in manual audit effort across security controls
  • Trusted cross-functional relationships — you're seen as someone who unblocks, not gates

Sound like you? We'd love to hear from you. Apply via LinkedIn or send your CV directly. We review applications on a rolling basis.

Note for recruiters: We are managing this search directly and are not accepting agency submissions at this time.

Lead Security Engineer employer: World of Books

World of Books Group is an exceptional employer that empowers its employees to drive meaningful change in a dynamic and supportive environment. With a commitment to sustainability as a certified B Corp, the company offers flexible remote and hybrid working options, a modern toolchain, and ample opportunities for professional growth, making it an ideal place for those looking to make a significant impact in the field of security engineering.

W

Contact Details:

World of Books Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead Security Engineer

Tip Number 1

Network like a pro! Reach out to people in the industry, especially those already working at World of Books Group. A friendly chat can give you insider info and maybe even a referral!

Tip Number 2

Show off your skills! If you’ve got a portfolio or any projects that highlight your security engineering prowess, make sure to share them during interviews. It’s all about proving you can shape the future, not just maintain it.

Tip Number 3

Prepare for hands-on challenges! Since this role is genuinely hands-on, be ready to discuss real-world scenarios and how you’d tackle them. Think about how you’d implement zero trust or enhance data loss prevention.

Tip Number 4

Apply through our website! We love seeing candidates who take the initiative. Plus, it shows you’re genuinely interested in being part of our mission-driven team at World of Books Group.

We think you need these skills to ace Lead Security Engineer

Cyber Resilience
Cloud Security (GCP/AWS)
Identity and Access Management (Entra ID)
SIEM and Detection Engineering
Data Loss Prevention (DLP)
Zero Trust Enforcement
Automation Fluency

Some tips for your application 🫡

Show Your Passion for Security:When you're writing your application, let your enthusiasm for security engineering shine through. We want to see how you can shape our cyber resilience programme and make a real impact!

Tailor Your CV:Make sure your CV highlights your hands-on experience in security engineering, especially in areas like cloud security and identity management. We love seeing how your skills align with what we're looking for!

Be Clear and Concise:Keep your application straightforward and to the point. We appreciate clarity, so make sure your achievements and experiences are easy to read and understand.

Apply Through Our Website:We encourage you to apply directly through our website. It helps us keep track of applications better and ensures you get noticed by the right people!

How to prepare for a job interview at World of Books

Know Your Stuff

Make sure you brush up on your technical knowledge, especially around cloud security, identity management, and zero trust principles. Be ready to discuss specific tools you've used, like Rapid7 or SentinelOne, and how they’ve helped you in past roles.

Show Your Hands-On Experience

This role is all about being hands-on, so come prepared with examples of projects where you’ve designed and implemented security controls. Highlight your experience in automating processes and using AI to enhance security measures.

Demonstrate Your Influence

Since you'll be working across various teams without formal authority, think of instances where you've successfully influenced stakeholders. Share stories that showcase your ability to drive change and build trusted relationships.

Be Ready for Scenario Questions

Expect questions that put you in hypothetical situations related to security challenges. Practice articulating your thought process and decision-making skills under uncertainty, as this will be crucial for the role.