Skip to content

Lead Security Engineer

The company 

Evolution Funding is the UK’s market-leading provider of motor finance and technology solutions, recognised as the UK’s best broker at the Car Finance Awards 2025 for the tenth year in a row. 

Our scope and capabilities go far beyond that of a traditional broker. Evolution Funding is at the forefront of digital finance journeys, with our technology powering a broad range of customer experiences in the automotive finance industry.

The role

This is an exciting opportunity to play a key role in shaping the overall direction of the Security function at Evolution Funding and across the Group. Reporting to the Business Technology Systems Manager and working closely with development teams and stakeholders across the business, you will lead a direct report in the successful implementation of the security strategy at Evolution Funding and implementation across the group entities.

The role holder will enjoy working with a high degree of autonomy and creative freedom utilising their skills, knowledge and experience to contribute towards security strategy, manage key stakeholder relationships and lead a team to deliver the best responses to cyber incidents across an ever-changing technology platform. 

Key responsibilities

  • Lead the delivery and ongoing ownership of enterprise security platforms and controls across endpoint, cloud, network and security monitoring.
  • Own the security technology roadmap ensuring tooling investment aligns with business strategy.
  • Own and oversee vulnerability management across the Group, including threat intelligence, penetration testing coordination.
  • Own patch management, including the policy, prioritisation and making sure remediation is achieved.
  • Take the lead on major security incidents owning the process.
  • Oversee day to day incident response managing the team and stakeholder relationships
  • Lead, coach and develop the security engineering team, acting as the primary escalation point for issues.
  • Lead the security input into ISO 27001 audits

Essential experience required

  • Experience owning and delivering security programmes such as vulnerability management, patch management and incident response at an enterprise level.
  • Proven experience in security engineering or security operations roles at a senior or lead level.
  • Strong knowledge of information security risk management tools, controls, frameworks and the evolving threat landscape.

Essential technical skills

  • Security and Incident Management – SIEM Sentinel & Defender
  • Ms AzureDefender for cloud
  • NetworkingWAF Policy, DDoS protection, and ideally FortiClient
  • Dev Ops – OAuth / MFA / AAD / PIM / PAM
  • Microsoft Entra Conditional access
  • Identity governance
  • 2 Factor Authentication (2FA)
  • RBAC, ISMS, PCI DSS

Personal qualities

  • Excellent communication skills, with the ability to translate complex security topics for both technical and non-technical audiences including senior stakeholders.
  • A balanced and commercially minded approach to decision making.
  • Ability to balance operational delivery, risk management and long-term security considerations.
  • Ability to lead effectively in a fast paced and at times pressured environment.