Security & Resilience Lead
Streetgroup
| Company | Streetgroup |
| Category | Security |
| Location | Manchester |
| Remote | Hybrid |
| Employment | Not stated |
| Level | Lead |
| Salary | GBP 50k–70k |
| Posted | 10 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
Security & Resilience Lead
📍 Manchester (Hybrid, up to 4 days WFH)
💰 £50k-£70k (negotiable)
Street Group is one of the fastest-growing PropTech companies in the UK. We want to be the leading creator of delightful experiences for everybody involved in buying, selling, renting and letting property, regardless of their involvement, to improve the industry for everybody by elevating UK Estate Agencies through world-class technology.
This role exists because we're growing fast, working towards ISO certification, and taking on bigger, more regulated customers. All of which means the security practices we handle today need to be documented and independently owned. We're now looking for a Security & Resilience Lead - who'll ensure Street Group's security function operates effectively and continually improves.
You'll work with the Head Of Security to decide what tools, processes and controls should be used, and lead with the ongoing configuration and maintenance of those tools to shape how security is embedded across the business - from development through to customer onboarding and off boarding. There's no team to inherit and no existing playbook to follow: just the opportunity to build one.
Here's what you can expect to be working on as our Security & Resilience Lead
- Working with technical teams review the security impact of technology changes and ensure security controls are met before production releases.
- Make sure environments are configured securely, verify controls and oversee technical change so access and data are handled appropriately.
- Monitor threat intelligence for company exposure, review emerging threats, and share relevant intelligence with stakeholders.
- Lead the response to security incidents, coordinating investigations and root cause analysis, and producing clear and accurate reports for internal and external stakeholders.
- Own our security monitoring capability, ensuring effective logging across key platforms and improving detection while preventing alert storms and false positives.
- Own the penetration testing and vulnerability management programme - not just detecting vulnerabilities, but risk-assessing them, deciding what needs fixing and working with the tech teams on solutions to close them down.
- Promote secure development practices, working closely with developers to embed security into how they build rather than simply dictating standards from a distance.
- Test security alerts, validate backup integrity, and coordinate business continuity and disaster recovery testing to build organisational resilience.
Why you should (and shouldn't) apply
You should apply if:
- You're just as comfortable running a penetration testing and vulnerability management programme as you are talking to developers or leading an incident response.
- You have a strong knowledge of logging, monitoring and threat detection, and enjoy tuning and configuring security tooling.
- You can communicate risk with non technical stakeholders, and communicate confidently with stakeholders at every level.
You probably shouldn't apply if:
- You don't have hands-on experience with vulnerability management, penetration testing, logging, monitoring or threat detection - these are the two must-have areas for this role.
- You need close oversight day-to-day; for now, you should be capable of being a security SME in the business alongside the Head Of Security and providing support to technical stakeholders.
- You want a purely strategic seat with no hands-on delivery - at this stage, it's very much both.
A bit about you
- A strong track record leading cyber security, ideally built in a scale-up or startup with software experience (SaaS or otherwise) rather than a large, established enterprise - B2B or B2C doesn't matter to us.
- Hands-on experience owning a vulnerability management and penetration testing programme - not just finding vulnerabilities, but risk-assessing
986,449 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →