Lead Security Engineer
Ohme · London, England, United Kingdom · 2026-08-19
About this role
Ohme is on a mission to accelerate the global transition to clean, affordable energy. We do that by serving as an integrated hardware and software smart-grid platform, focused on the residential EV charging market.
The worlds of energy, transport and artificial intelligence are colliding and Ohme is at the heart of this new era. By using technology and data integrations to connect cars, chargers, people, energy providers and more, Ohme has a powerful platform that puts the consumer at the core.
Ohme has been selling its chargers to consumers since mid 2019 and has had exponential growth since. We are now operating in multiple countries and have partnerships with the likes of VW, Mercedes, Octopus Energy, and other innovative brands.
We are scaling up the business and are building out the team for rapid growth. If you’re interested joining a fast-growing cleantech venture on a data and AI-first journey to speed up the global transition to clean, affordable energy, read on!
We are looking for a Lead Security Engineer to join our technology leadership team as the organisation’s senior security authority. Reporting directly to the CIO, this is a hands-on role: you will build and operate security controls, not just design them. You will work directly alongside engineering and DevOps teams, make pragmatic decisions under real constraints, and be as comfortable configuring a detection rule or reviewing an IaC change as you are presenting a risk position to the CTO. Two things matter most from day one: establishing a coherent security architecture that the organisation can build on, and getting Microsoft Sentinel into a functioning baseline capability.
This is a senior individual contributor role with real scope and autonomy. You will be the organisation’s go-to security expert — bringing the technical depth to build and operate controls directly, and the strategic judgement to shape how security is governed and prioritised across the business. As the function and the organisation around it mature, there is genuine scope for progression for the right person.
Key Responsibilities
Security Engineering & Architecture
• Own and actively maintain the organisation’s security architecture, covering cloud, application, network, and data security — producing real, usable artefacts rather than documentation that lives on a shelf.
• Work with DevOps to embed security into CI/CD pipelines — defining requirements together for SAST/DAST tooling, container security scanning, secrets detection, and IaC security checks, and getting hands-on with configuration where the team needs it.
• Lead security reviews for new projects, platforms, and third-party integrations — applying proportionate, risk-based judgement that keeps engineering teams moving rather than creating bottlenecks.
• Work closely with the DevOps function on AWS security posture — reviewing IAM policies, SCPs, and IaC configurations, advising on control design, and assisting with implementation where it makes sense. Own the security monitoring layer directly: Security Hub, GuardDuty, CloudTrail, and Config findings are yours to triage, prioritise, and drive to resolution.
• Set the standards for identity and access management, secrets management, encryption, and network segmentation. DevOps owns implementation in many of these areas — your role is to work with them to define what good looks like, review what gets built, and work alongside the team to close gaps.
• Own the Microsoft security stack day-to-day — configuring and tuning Microsoft Sentinel analytics rules, managing Defender for Endpoint and Defender for Office 365 policies, working with Purview for data classification and DLP, and ensuring Entra ID Conditional Access and identity protection controls are fit for purpose. Getting Sentinel to a functioning baseline is a priority.
• Define and own the organisation’s incident response capability — defining the IR process, building and maintaining response playbooks, and leading the response to significant security incidents end-to-end from detection through to post-incident review and remediation.
Governance & Risk
• Shape the security strategy that Ohme presents to its enterprise energy partners — translating posture and controls into the assurance evidence major customers require, including due diligence questionnaires and supplier compliance requirements.
• Apply ISO 27001 and related standards as a practical lens for risk management and policy — making controls real and enforceable rather than documented and ignored.
• Conduct risk assessments and threat modelling across the technology estate, translating findings into prioritised remediation work that the team can actually execute.
• Own the security risk register, feeding into the organisational risk register — tracking posture, remediation progress, and reporting to the CIO with clarity and without unnecessary noise.
• Support audit and compliance activities where they arise, engaging with external assessors as needed.
Communication & Stakeholder Engagement
• Communicate security risk and decisions clearly to both technical and non-technical colleagues — influencing without authority and making the case for good security practice in terms the business understands.
• Build strong relationships with engineering, product, and operations teams to ensure security is seen as an enabler, not a blocker.
• Provide clear, concise reporting on security posture and risk to the CIO and leadership team when it matters — not as a bureaucratic exercise but as a tool for decision-making.
• Stay current with the evolving threat landscape and emerging security technologies, sharing relevant insight across the organisation.
AI Security & Governance
• Define and maintain a pragmatic AI security governance framework covering the adoption of large language model (LLM) services from providers such as Anthropic and OpenAI, AI-powered tooling, and agentic workflow platforms.
•…
Skills asked for
- devops
- go
- ci/cd
- aws
- llm
Similar jobs
- Security Operations LeadBeam Up · London
- Embedded Security Team LeadSibylline Ltd · London
- Lead Security Engineer (DevSecOps & CISO)Smarkets · London
- Team Lead - Security ConsultancyRamboll · London
- Security Lead - Member of Technical StaffCallosum · London
- Security Engineering LeadAttio · London
- Lead Identity & Security Engineer (12 Month FTC)AND Digital · London
- Lead Security Operations EngineerPleo · London
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.