
Security & Resilience Lead
Job description
Security & Resilience Lead at Street Group.
About the role
You will partner with the Head Of Security to own the security strategy and day-to-day execution for Street Group, ensuring the security function operates effectively and continually improves as the business scales. You will review the security impact of technology changes, verify that security controls are met, and oversee technical change so access and data are handled appropriately across the full lifecycle. You will monitor threat intelligence for company exposure, lead the response to security incidents, coordinate investigations, and produce clear and accurate reports for both internal and external stakeholders. There is no team to inherit and no existing playbook to follow; you will build the security and resilience foundations from scratch while promoting secure development practices and embedding security into how developers build products. You will own our security monitoring capability, manage the penetration testing and vulnerability management programme, test security alerts, validate backup integrity, and coordinate business continuity and disaster recovery testing to build organisational resilience.
Key facts
What you'll do
- Review the security impact of technology changes and ensure security controls are satisfied before production releases are deployed.
- Configure environments securely, verify controls, and oversee technical change so access and data are managed appropriately.
- Monitor threat intelligence for company exposure, review emerging threats, and share relevant intelligence with stakeholders across the business.
- Lead the response to security incidents, coordinating investigations and root cause analysis, and producing clear and accurate reports for internal and external stakeholders.
- Own the security monitoring capability, ensuring effective logging across key platforms and improving detection while preventing alert storms and false positives.
- Own the penetration testing and vulnerability management programme, risk-assessing discovered vulnerabilities, deciding what must be fixed, and working with technical teams on remediation.
- Promote secure development practices by working closely with developers to embed security into how they build, rather than dictating standards from a distance.
- Test security alerts, validate backup integrity, and coordinate business continuity and disaster recovery testing to build organisational resilience.
- Collaborate with the Head Of Security to decide on tools, processes, and controls, and lead the configuration and maintenance of those tools to shape security across the product lifecycle.
- Support customer onboarding and offboarding processes to ensure security practices are applied consistently and data is handled appropriately.
- Contribute to ISO certification efforts by documenting security practices and demonstrating compliance through auditable evidence.
- Act as the security SME for the business, providing day-to-day guidance and hands-on support to technical stakeholders during implementation and delivery.
- Prioritise security activities based on business risk, balancing speed of delivery with the need for robust controls and measurable outcomes.
- Maintain and evolve security playbooks, runbooks, and standard operating procedures to ensure clarity, consistency, and continuous improvement.
- Challenge the status quo and drive iterative improvements to security tooling, detection logic, and resilience testing cadence.
Requirements
- You have hands-on experience running a vulnerability management and penetration testing programme, including risk assessment, remediation planning, and working with engineering teams to close gaps.
- You have strong knowledge of logging, monitoring, and threat detection, and you enjoy tuning and configuring security tooling to reduce noise and improve signal.
- You can communicate risk effectively to non-technical stakeholders and present confidently to stakeholders at every level of the organisation.
- You are capable of being a security subject matter expert alongside the Head Of Security, providing direct support to technical teams without needing close day-to-day oversight.
- You have practical experience with secure development practices and understand how to embed security into engineering workflows rather than enforcing rules from afar.
- You are pragmatic and commercially aware, calm under pressure, highly organised, decisive, collaborative, curious, and focused on continuous improvement with a high level of integrity.
- You have a strong track record leading cyber security in a scale-up or startup environment with software or SaaS experience, rather than a large, established enterprise.
- You are comfortable performing continual configuration of existing toolsets and assessing new tooling to determine fit for purpose and operational effectiveness.
Nice to have
- Experience contributing to ISO certification efforts and aligning security controls with recognised frameworks.
- Exposure to regulated industries or customers where compliance and audit expectations are heightened.
- A background in promoting secure development practices within engineering teams and influencing through technical leadership.
Practical notes
- Hybrid working model with up to 4 days per week remote work available.
- This role requires hands-on delivery alongside strategic thinking; applicants should be prepared to contribute at the technical and operational level.