Information Security Specialist - Technical Lead

Manchester
2 days ago
Create job alert

Permanent

Location: Manchester (Hybrid – 2-3 days per week onsite)

Salary: Up to £95,000 (plus car allowance, plus bonus)

About the Client

Our client renowned for its commitment to innovation, scalability, and cutting-edge technology. Operating at the forefront of digital solutions, they leverage bespoke and third-party systems to drive efficiency and enhance business operations. This is an exciting opportunity to join a forward-thinking organisation that prioritises technological evolution and continuous improvement.

How you’ll spend your day

As part of the wider Information Security function, you will play a key role in strengthening application security across the organisation. Working closely with engineering, architecture, and delivery teams, you’ll help ensure applications are designed, developed, and deployed with security at the forefront.

Your responsibilities will include:

  • Designing and evolving the organisation’s application security testing strategy, tooling, and secure coding standards

  • Performing advanced manual and automated security testing, including static and dynamic analysis to identify vulnerabilities and logical flaws

  • Conducting risk assessments, threat modelling, and security design reviews to ensure robust controls are in place

  • Partnering with software development and architecture teams to embed security throughout the secure development lifecycle

  • Leading the security review process across projects to ensure risks are identified and mitigated early

  • Designing and owning software supply chain assurance processes to identify and manage potential vulnerabilities

  • Contributing to and improving security testing methodologies and best practices

  • Mentoring junior members of the team and providing technical leadership on security matters

  • Identifying opportunities to automate manual security processes and implement tooling to improve efficiency

  • Supporting the organisation’s adoption of AI-enabled security processes to enhance detection and response capabilities

    What you’ll bring to this role

    We’re looking for an experienced application security professional who combines strong technical expertise with the ability to collaborate effectively across teams.

    Key experience and skills include:

  • Strong hands-on experience with application security testing, including automated, dynamic, and static testing tools, as well as manual vulnerability assessment

  • Deep understanding of OWASP principles and frameworks, including their use within threat modelling and secure development practices

  • Experience assessing both proprietary and open-source applications for security risks

  • Knowledge of secure development lifecycles and integrating security into engineering workflows

  • Experience working with CI/CD pipelines and associated security tooling

  • Strong technical understanding of code analysis and vulnerability remediation

  • Experience using structured methodologies for web application security testing and reporting

  • Ability to mentor team members and provide technical leadership

  • Excellent communication and documentation skills, with the ability to explain security risks to technical and non-technical stakeholders

    You’ll also bring a proactive mindset, a passion for improving security practices, and a collaborative approach to working with development and infrastructure teams.

    Perks & Benefits:

  • Performance-Based Bonus - Annual bonus paid in two instalments (April & September), based on company and personal performance.

  • Pension Scheme - Employer-matched contributions of up to 7.5%.

  • Hybrid Working - Minimum 2 days per week in the office, with flexibility on which days.

  • Flexible Working Hours - 40-hour workweek with flexibility in how hours are structured.

  • Generous Annual Leave - 25 days holiday + your birthday off, plus bank holidays. Option to buy or sell up to 5 additional days.

  • Free Gym Membership - Available to all employees.

    What happens next?

    One of our Recruitment Consultants will be in touch and inform you if you’ve been successful to the next stage of the process or not, which is a qualification call where we will tell you more about the role and the client, and understand more about you, your experience and career aspirations.

    Should we both wish to proceed, we will submit your details to the client and be in touch regarding the outcome and any further steps.

    The interview process for this client consists of:

  • Stage 1 – 60-90 minutes technical and competency interview via MS Teams

  • Stage 2 – 60-minute interview with hiring manager and head of department focussed on exploring soft skills.

    Equal Opportunities

    We are committed to providing equal opportunities for all candidates and welcome applications from individuals regardless of age, disability, gender identity, marital status, race, religion or belief, sexual orientation, or any other characteristic protected by law. As an employment agency for permanent and contract hires, we are dedicated to promoting a diverse and inclusive workforce, and we encourage applications from underrepresented groups to drive innovation and equality within the workplace.

    Should you require any reasonable adjustments please let us know so we can accommodate for any interactions with us at Biometric Talent, but also inform the client to ensure reasonable adjustments are made to allow for a fair and equitable process

Related Jobs

View all jobs

Information Security Specialist

Information Security Specialist - Technical Lead

Senior IT Security Specialist

Vetting & Security Administrator

Lecturer in Networking and Cyber Security (HE)

Penetration Tester

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

How Many Cyber Security Tools Do You Need to Know to Get a Cyber Security Job?

If you are trying to build or move forward in a cyber security career, it can feel like the list of tools you are expected to know never ends. One job advert asks for SIEM platforms, another mentions penetration testing tools, another lists cloud security, threat intelligence platforms, endpoint detection, scripting languages and compliance frameworks. Scroll LinkedIn and it gets worse. Everyone seems to “know” dozens of tools, certifications and platforms. Here is the reality most cyber security hiring managers agree on: they are not hiring you because you know every tool. They are hiring you because you understand risk, can think like an attacker and a defender, follow process, communicate clearly and make good decisions under pressure. Tools matter — but only when they support those outcomes. So how many cyber security tools do you actually need to know to get a job? For most job seekers, the answer is far fewer than you think. This article explains what employers really expect, which tools are essential, which are role-specific and how to focus your learning so you look credible, not overwhelmed.

What Hiring Managers Look for First in Cyber Security Job Applications (UK Guide)

If you want to stand out in the highly competitive world of cyber security job applications, you need to understand what hiring managers look for before they even finish reading a CV. Cyber security hiring managers scan applications quickly and with specific priorities in mind. They assess not just your technical ability, but your judgement, professionalism, clarity, risk awareness and evidence of impact. This guide explains what hiring managers look for first in cyber security applications across roles like Security Analyst, Security Engineer, Penetration Tester, Incident Responder, Security Architect, Governance Risk and Compliance specialists and Cloud Security positions. Use this as a practical, step-by-step checklist to sharpen your CV, LinkedIn profile, cover letter and portfolio before you apply on www.cybersecurityjobs.tech .

The Skills Gap in Cyber Security Jobs: What Universities Aren’t Teaching

Cyber security has become one of the most critical disciplines in the modern economy. From protecting financial systems and healthcare data to securing national infrastructure, cloud platforms and supply chains, cyber security professionals now sit at the frontline of digital trust. Demand for cyber security talent in the UK has surged. Job vacancies remain high, salaries continue to rise, and organisations across every sector report difficulty hiring skilled professionals. Yet despite this demand, many graduates struggle to break into cyber security roles and employers consistently report that candidates are not job-ready. The problem is not intelligence, ambition or academic effort. It is a persistent and widening skills gap between university education and real-world cyber security work. This article explores that gap in depth: what universities teach well, what they routinely miss, why the gap exists, what employers actually want, and how jobseekers can bridge the divide to build sustainable careers in cyber security.