Principal Security Engineer (12 Month FTC)
Any of our offices • Permanent • Competitive
Back to Job Search

Principal Security Engineer (12 Month FTC)

New Easy Apply
Any of our offices On-site Permanent 27 Applications
Competitive
Full-time
Posted 06 Oct 2026
Expires 05 Nov 2026

Job description

Role OVO-View

Team: Attack Surface Management

Location: Hub Based - Hybrid for all

Salary banding: £105,000 - £150,000 / 12 month FTC

Experience: Expert

Working pattern: Full-Time

Reporting to: Deputy CISO

Sponsorship: Unfortunately we are unable to offer sponsorship for this role.

This role in 3 words: Pragmatic, Proactive, Engineer

Top 3 qualities for this role: Data-driven, Communication, Automator

Where you’ll work:

Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person.

You’ll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life.

Everyone belongs at OVO:

At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us.

Teamworking for the planet:

Everything we do here spins around Plan Zero. So, naturally, the team you’ll be joining plays a gigantic role in making that happen. Here’s how:

In this individual contributor role, you will be on the frontline of OVO's security. You'll lead the reduction of our attack surface through technical leadership of a consolidated identity and access roadmap and highly automated amplification loops for security exposure management. This work is pivotal to maintaining a proactive and resilient posture, collaborating closely with engineering, procurement, risk and security teams across OVO to build better observability, and deterministic and non-deterministic workflows to better defend our mission to transition to a zero-carbon future.

This role in a nutshell:

As a Principal Security Engineer (Attack Surface Management) at OVO, you will be the key technical leader responsible for shaping the enterprise-wide strategy for zero trust access, attack surface observability and security weakness amplification workflows. This involves deep hands-on expertise, driving the innovation of exposure management practices, guiding architectural decisions for zero trust access and data loss prevention controls, and leading the way in solving complex, emerging security challenges. You will ensure OVO maintains a proactive and automated defence posture, setting the direction for critical security initiatives, and championing the integration of security standards embedded in configs and code and near miss retros to improve our resilience. You will be recognised as a trusted authority in your field, particularly in building automated, AI-enabled attack surface reduction workflows, leading critical vulnerability remediation incidents and leading complex control improvement initiatives.

Your key outcomes will be:

  • Weakness management:
    • Lead and execute security defect discovery operations, vulnerability management (VM), remediation governance, and recurrence prevention across the enterprise with the aim of continuously improving compliance with policies, procedures, and guidelines.
    • Drive organisational and technical change by defining and implementing changes where required to internal processes & tooling to enhance proactive security controls.
  • Identity-focused access security:
    • Lead the development, revision, implementation and monitoring of security IAM policies, processes and related tooling across OVO.
    • The principal SME and strategic leader for IAM, defining and developing policy, influencing major strategic tech decisions, governs implementation of those solutions.
    • Defines enterprise identity and access management and governance strategy.
  • Supply chain security:
    • Champions and is a catalyst for improving secure supply chain management controls.
    • Minimises the cost of meeting third party risk management compliance while developing strategies to measure and reduce supply chain risk reduction.
    • Utilises principal-level expertise and perspectives to influence vendor relationships and security of third-party contracts.
  • Security risk treatment prioritisation:
    • Serve as a trusted challenger and SME, including to senior stakeholders, on trade-offs that appear in designing enterprise-level security systems that carefully balance risk appetite and conflicting priorities (e.g. cost, speed, rigour).
    • Able to innovate with more efficient and effective ways to protect, detect, respond and recover from security threats.
    • Coaches others in security architecture.
    • Defines attack path mapping frameworks that scale and can align organisational risks and mitigation priorities.
    • Directly influence OVO’s core model architecture with security best-practice in mind, utilising engineering-first approaches to solve complex security problems.
  • Mentor Senior Technical Staff & Elevate Practice:
    • Mentor staff and senior engineers across OVO in advanced security disciplines, strategic thinking, architecture, and technical leadership.
    • Actively contribute to internal communities of practice, develop training for senior staff, and elevate the overall security engineering practice at OVO.
  • Community of Practice:
    • Drive the Community of Practice (CoP) for your role by actively leading, cultivating and growing the CoP as a result of your industry engagement and thought leadership.
    • Create content, engage in knowledge exchange / cross-pollination to further your craft
    • Mentor and coach individuals in the role-based competencies associated with a CoP
    • Input to upskilling and learning pathways based on the CoP that will aid individuals' career progression

You’ll be successful in this role if you…

  • Inspire and lead cross-functional teams, driving a culture of excellence and collaboration.
  • Think critically and strategically to align security initiatives with business goals.
  • Demonstrate excellent verbal and written communication skills, effectively conveying complex security concepts to non-technical stakeholders.
  • Demonstrate strong influencing skills to drive security adoption and change across the organisation.
  • Apply advanced problem-solving and analytical skills to address complex security challenges.
  • Anticipate and adapt to changes in the internal and external business context and evolving security landscapes and emerging threats.
  • Dedicate time and thought to mentoring and developing other senior security professionals and technical leaders.
  • Exhibit a drive to find novel, effective, and potentially unconventional solutions to hard security problems.
  • Are recognised internally and potentially externally as an expert and forward-thinker, contributing to security communities or publications.
  • Are able to balance security ideals with practical business/engineering realities to achieve tangible outcomes.
  • Demonstrate a keen understanding of how security enables and impacts broader business objectives, strategy, and risk management.

Let’s talk about what’s in it for you:

We’ll pay you between £105,000 and £150,000, depending on your specific skills and experience.

We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission.

You’ll be eligible for an on-target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal.

We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO…and there’s flex pay. We'll give you 9% Flex Pay on top of your salary – 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash.

Here’s a taster of what’s on offer:

For starters, you’ll get 34 days of holiday (including bank holidays).

For your health
With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more

For your wellbeing
With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more

For your lifestyle
With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give-as-you-earn donations

For your home
Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers

For your commute
Nab a great deal on ultra-low emission car leasing, plus our cycle to work scheme and public transport season ticket loans

Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know.

For your Belonging

To find better ways to support our people, we need to listen to each other’s experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you.

Oh, and one last thing...

We’d be thrilled if you tick off all our boxes, yet we also believe it’s just as important we tick off all of yours. And if you think you have most of what we’re looking for but not every single thing, go ahead and hit apply. We’d still love to hear from you!

If you have any additional requirements, there’s a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.

Is there something wrong with this job listing? Let us know.