Lead Software Security Engineer

  • PSR Limited
  • Leeds, Yorkshire
  • Jun 27, 2025
Full time I.T. & Communications

Job Description

To understand how the FCA collects and processes personal data please refer to the FCA privacy notice .

domain and its sub-domains. It does not apply to content on or other domains.

This website is run by the Financial Conduct Authority. We are committed to inclusive design and ensuring that our web content is accessible to all.

For example, that means you should be able to:
  • zoom in up to 300% without the text spilling off the screen
  • navigate most of the website using just a keyboard
  • navigate most of the website using speech recognition software
  • listen to most of the website using a screen reader (including the most recent versions of JAWS, NVDA and VoiceOver)
We've also ensured that the text is clear and easy to understand.

AbilityNet has advice on making your device easier to use if you have a disability.

How accessible this website is We know some parts of this website are not fully accessible:
  • Checkboxes are not accessible using standard voice commands.
  • Some radio buttons are not given group titles when tabbing to them using a screen reader.
  • Edit combo fields with options lists can be difficult to navigate to with voice commands when the field is completed.
  • The programmatic labelling of edit combo fields with options lists is not clear when using a screen reader.
Feedback and contact information If you need information on this website in a different format contact us and tell us:
  • the web address (URL) of the content
  • your name and email address
  • the format you need - for example large print, braille or audio
Reporting accessibility problems with this website We're always looking to improve the accessibility of this website. If you find any problems not listed on this page or think we're not meeting accessibility requirements, contact us .

The Equality and Human Rights Commission (EHRC) is responsible for enforcing the Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 (the 'accessibility regulations'). If you're not happy with how we respond to your complaint, contact the Equality Advisory and Support Service (EASS) .

Technical information about this website's accessibility The Financial Conduct Authority is committed to making its website accessible, in accordance with the Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018.

The content listed below is non-accessible for the following reasons.

Non-compliance with the accessibility regulations
  • Checkboxes are not accessible using standard voice commands such as "Click checkbox" and can only be accessed by using "Tab" commands. This fails WCAG 2.1 success criterion 1.3.1 ( Information & Relationships ).
  • Some radio buttons are not given group titles when tabbing to them using a screen reader. This fails WCAG 2.1 success criterion 1.3.1 ( Information & Relationships ).
  • Edit combo fields with options lists can be difficult to navigate to with voice commands when the field is completed. This fails WCAG 2.1 success criterion 1.3.1 ( Information & Relationships ).
  • The programmatic labelling of edit combo fields with options lists is not clear when using a screen reader. This fails WCAG 2.1 success criterion 1.3.1 ( Information & Relationships ).
What we're doing to improve accessibility We are actively engaging with our site developers and independent accessibility professionals to address the issues above and improve overall accessibility with the eventual goal of attaining full WCAG AA compliance.

Preparation of this Accessibility Statement This statement was prepared on 22nd July 2021. It was last reviewed on 22nd July 2021.

This website was last tested on 02/02/2021. Testing was carried out by Blazie Engineering using the Website Accessibility Conformance Evaluation Methodology (WCAG-EM) approach to deciding on a sample of pages to test.

Lead Software Security Engineer page is loaded Lead Software Security Engineer Apply locations London Leeds Edinburgh time type Full time posted on Posted 2 Days Ago time left to apply End Date: July 7, 2025 (10 days left to apply) job requisition id JR Lead Software Security Engineer

Division - Data, Technology & Innovation

Department - Digital Systems

Salary - National (Edinburgh and Leeds) ranging from £59,100 to £82,500 and London from £64,900 to £90,000 per annum (salary offered will be based on skills and experience)

About the FCA

The FCA regulates the conduct of 45,000 firms in the UK to ensure our financial markets are honest, fair and competitive. Follow this link to find out more About the FCA .

What will you be doing?

The Lead Security Engineer role is responsible for technical oversight of secure product development, security testing and security operations. You will work closely with FCA product owners, architects, service managers, and third-party suppliers who provide the development resources to the FCA to:
  • Embed secure engineering practices in development workflows, ensuring compliance with Secure by Design principles
  • Conduct structured and ad hoc security reviews of code, infrastructure and CI/CD pipelines
  • Define and document secure development lifecycle (SDLC) processes aligned with product needs
  • Lead security education initiatives for development teams and product stakeholders
  • Establish and enforce security requirements for new features, APIs and system enhancements
  • Assess and improve security maturity, advocating risk-based methodologies, tooling and automation
What will you get from the role?
  • Opportunity to grow in a technology-focused career with meaningful skill development
  • Supportive and collaborative team culture, fostering strong internal and cross-team connections
  • Purpose-driven environment, united by a shared commitment to public service and impact
  • Emphasis on work-life balance, prioritising smart working over excessive hours
  • Empowering workplace that values autonomy, trust and effective decision-making
  • Genuine commitment to diversity, inclusion and leadership with strong interpersonal skills
Which skills are required?

We are a Disability Confident Employer; therefore, disabled people or individuals with long-term conditions who best meet the minimum criteria for a role will go through to the next stage of the recruitment process. (To learn more about the Disability Confident Scheme Click Here )

Minimum
  • Experience in commercial software development, secure coding practices and cloud security services (ideally AWS)
  • Experience in reviewing code security, leading cyber incident resolution and improving security processes in development teams
  • Experience working with microservices architecture and implementing security tooling in a development context
Essential
  • Strong commercial awareness, assessing supplier proposals and driving cost-effective security solutions
  • Ability to integrate security with software innovation while ensuring adherence to organisational standards
  • Expertise in security methodologies, including threat modelling and risk assessment
  • Deep understanding of technology trends and industry standards in information security
  • Proven track record of delivering security-focused assets, including incident reports, secure coding templates and training programmes
Desirable
  • Familiarity with the FCA, its remit, and strategic priorities
  • Relevant security certifications, including CompTIA Security+, GSEC, CySA+, CCSP, OSCP or CISSP
Our Values & Diversity

We are proud to be an inclusive employer and our ambition is to cultivate a culture for all employees that respects their individual strengths, views, and experiences. We believe that our differences and similarities enable us to be a better organisation - one that makes better decisions, drives innovation, and delivers better regulation.

Within the workplace you will have access to various employee resource groups which aim to promote and achieve a healthy work / life balance and support our diversity ambitions.

Did you know? 50% of our Executive Committee were the first in their family to attend university.

Benefits of working at the FCA
  • 25 days holiday per year plus bank holidays
  • Hybrid working (work from home up to 60% of your time)
  • Private healthcare with Bupa
  • A non-contributory Pension of at least 8% of basic salary each month (there are several contribution levels that increase depending on your age - up to 12% a month once you reach age 35)
  • Life assurance of eight times your basic salary
  • Income protection
We also have a competitive flexible benefits scheme which gives you the opportunity to create a personalised benefits package, tailored to suit your lifestyle.

Follow this link to see what life is like at the FCA - Life at the FCA

Application Support

We are dedicated to removing barriers and ensuring our application process is accessible to everyone. We offer a range of adjustments to make your application experience as comfortable and straightforward as possible.

If you have an accessibility need, disability, or condition requiring changes to the recruitment process . click apply for full job details