Product Security Engineer
- Location
- Manchester, England, United Kingdom
dependencies, build pipelines, and CI providers. You'll engineer the systems that make our supply chain defensible: provenance and integrity for what we build (SLSA, sigstore patterns, signed artifacts), dependency trust as a real control rather than a manifest scan, build-pipeline isolation, third-party risk as runtime telemetry. When … people around you Desirable Detection engineering at production scale: runtime detection, anomaly detection, alert tuning (Sigma, OSQuery, Falco, or equivalent) Supply-chain security: SLSA, sigstore/cosign, in-toto, SBOM tooling used as a real control Cloud-native attack patterns on AWS: IAM privilege analysis, IMDS exploitation, cross-account paths ...