We're on a mission to make a big green dent in the universe by building a truly sustainable energy system globally.
That means making power greener, smarter, and more affordable for everyone.
We put customers at the heart of everything we do: with always-fair prices, transparency and outrageous customer service.
We drive system change: with transformative tech to make renewable energy the norm and end global reliance on fossil fuels.
Octopus Energy Group is made up of 10 businesses spanning 6 countries across 3 continents, including: Octopus Energy Retail, Kraken Technologies, Octopus Energy Generation, Kraken Flex, Octopus Electric Vehicles, and the Octopus Centre for Net Zero. More on OEG @ octopusenergy.group
Octopus Energy started with a bold idea: to build Britain’s first truly digital energy supplier.
By combining world-class tech with brilliant humans who care deeply about customers and driving the renewable energy transition, we made it happen and earlier this year, we became Britain’s largest energy supplier.
Now, we’re scaling fast and building the next generation of products to accelerate the green energy transition. From making it effortless to switch to heat pumps, solar and EVs, to launching smart tariffs and creating renewable generation at scale, we’re solving some of the most complex challenges in energy with speed, creativity and customer obsession. We’re also enabling our global businesses to reach the full capability of what we’ve achieved in the UK, taking the learnings, products and experiences that customers love here and rolling them out worldwide.
At Octopus Tech, you’ll have real ownership, variety, and the chance to shape products that make a tangible difference in people’s lives – lowering bills, enabling greener living, and delivering experiences customers genuinely love. You’ll work side by side with teams across marketing, operations, and data, and see the impact of your work in the real world, fast.
We are very excited to be expanding our Cyber and Information Security team at Octopus Energy! We are looking for an ambitious, knowledgeable, and experienced Lead Security Engineer to join our team, to grow with the rest of the company, and ensure we continue to do so in a secure and safe way.
You will be a key partner in defining what Security is at Octopus. We will be shaping this team to provide a world class support service to our employees, building our way out of problems with engineering firepower and undertaking transformational organisational change.
You’ll play a crucial role in helping to secure our software development processes, securing our platform services, integrating security practices, and shaping a culture of security. This is a creative, and collaborative position that is a full-time member of a Cloud-First organisation. If you’re passionate about Cloud technologies and driving security by design, we encourage you to apply!
Specifically, we're looking for a Lead Security Engineer with at least 5 years of relevant experience. You will lead a team of up to ~6 people and help shape the technical direction of the security engineering function. There will be time within the role for hands-on engineering work.
If this sounds exciting, we’d love to chat.
We offer flexible hybrid working. Don't let location discourage you from applying if you can't make it to an office!
Got any burning questions before then? Drop us a message at [email protected] and we’d love to help!
If this sounds like you then we'd love to hear from you. 🚀
Are you ready for a career with us? We want to ensure you have all the tools and environment you need to unleash your potential. Need any specific accommodations? Whether you require specific accommodations or have a unique preference, let us know, and we'll do what we can to customise your interview process for comfort and maximum magic!
Studies have shown that some groups of people, like women, are less likely to apply to a role unless they meet 100% of the job requirements. Whoever you are, if you like one of our jobs, we encourage you to apply as you might just be the candidate we hire. Across Octopus, we're looking for genuinely decent people who are honest and empathetic. Our people are our strongest asset and the unique skills and perspectives people bring to the team are the driving force of our success. As an equal opportunity employer, we do not discriminate on the basis of any protected attribute. Our commitment is to provide equal opportunities, an inclusive work environment, and fairness for everyone.
What you’ll do...
Have ownership of a functional team within the Cyber Security Team, working closely with the Head of Cyber Security to define strategic objectives and team direction
Manage team priorities and ensures initiatives are completed within deadlines
Collaborate regularly and effectively with the rest of the Cyber Security and Information Security Teams to deliver outcomes
Lead delivery of major initiatives on clear timelines
Build a strong culture of open communication where teammates can ask questions without fear, promoting a positive and inclusive team environment.
Line-manage a team of Security Engineers in the same or similar timezone
Set performance expectations and goals for team members
Regularly review individual and team performance, offering actionable insights and constructive feedback to support and grow team members
Support team delivery for example through code reviews, technology research or architectural guidance
Provide support for production systems owned by your team
Support the implementation of security processes and requirements
Stay abreast of emerging security threats, technologies, and industry trends to continuously enhance the organisation's security strategy
What you'll have...
Proven experience in a leadership role within Security Engineering or closely related field
Strong background in Security Engineering with a deep understanding of security best practices and standards.
Excellent communication, with a focus on doing this asynchronously
Experience of mentoring and coaching a team to perform at a high-level of quality
Experience of incident management
Previous experience working in engineering teams focused one or more of the following areas
Application Security - including web application security concepts, including OWASP Top 10 vulnerabilities, secure coding practices, and static and dynamic application security testing (SAST/DAST) tools
Cloud Security - including good AWS experience (or knowledge) and familiarity with various AWS security services (or familiarity with Azure and/or GCP with a willingness to learn AWS) and cloud security tooling (e.g. CSPM and CNAPP)
Experience in SaaS and/or End-User Device Security - including security posture management tooling and end-user device security tooling such as EDR and ZTNA
Ideally, you will have experience in one or more of the areas mentioned (or others), but we’re not expecting you to be an expert in all areas of security engineering!
What will help...
Security certifications (any of the famous abbreviations)
Certifications from cloud providers’ certification paths
Security qualifications (e.g. apprenticeships or degrees)
Strong skills in creating high-quality, comprehensive security documentation
Familiarity with AWS services and experience in managing cloud security services
Familiarity using Infrastructure-as-Code (IaC) to manage security tooling and services
Familiarity with CI/CD tooling and security best practices
Familiarity with vulnerability management processes and automations
Experience using logging and monitoring tools (whether this was a SIEM system or not) to generate alerts and reports
Knowledge of the MITRE ATT&CK framework
💚 Why else you'll love it here...
💰 Wondering what the salary for this role is? Just ask us! On a call with one of our recruiters it's something we always cover as we genuinely want to match your experience with the correct salary. The reason why we don't advertise is because we honestly have a degree of flexibility and would never want salary to be a reason why someone doesn't apply to Octopus - what's more important to us is finding the right octofit!
🎉 Octopus Energy Group is a unique culture. An organisation where people learn, decide, and build quicker. Where people work with autonomy, alongside a wide range of amazing co-owners, on projects that break new ground. We want your hard work to be rewarded with perks you actually care about! We won best company to work for in 2022, on Glassdoor we were voted 50 best places to work in 2022 and our Group CEO, Greg has recorded a podcast about our culture and how we empower our people. We’ve also been placed in the top 10 companies for senior leadership
🎁 Visit our UK perks hub - Octopus Employee Benefits