locally based skills and technical expertise to drive innovation and adoption of new technology. Your role and responsibilities We are seeking a Cybersecurity Architect to join our Data and ApplicationSecurity team. Our Data Security services cover a wide range of areas, including Cloud Access Security Brokers (CASB), Data Access Governance (DAG), PKI (Public Key Infrastructure … modelling workshops with cross-functional teams to identify potential security risks early in the software development lifecycle and recommending effective mitigation strategies. Designing and implementingsecurity testing (SCA, SAST, DAST) as part of the DevSecOps pipeline to identify and remediate vulnerabilities at every stage of the development process. Designing and implementing IaC security solutions to ensure secure provisioning … the software development lifecycle, automating security practices intoCI/CD pipelines, and ensuring seamless collaboration between security and development teams. Experience with automated SCA (Software Composition Analysis), SAST (StaticApplicationSecurityTesting), and DAST (Dynamic ApplicationSecurityTesting) to identify vulnerabilities early and throughout development. ApplicationSecurity: Proficiency in More ❯
Senior Security Engineer (Product Security) Technology London New Senior Security Engineer (Product Security) London Ebury is a global fintech firm dedicated to empowering businesses to expand internationally through tailored and forward-thinking financial solutions. Since our founding in 2009, we've grown to a diverse team of over 1,700 professionals across 40+ offices and 29+ … contributions are valued. You'll play a key role in shaping the future of cross-border finance, while advancing your own career in a dynamic, high-growth industry. Senior Security Engineer London Office - Hybrid: 4 days in the office, 1 day working from home Role Overview We are seeking a Senior Security Engineer to embed security throughout … security architecture patterns and reference implementations Security Code Reviews & Testing Conduct in-depth security code reviews for critical features Implement automated securitytesting (SAST, DAST, IAST, SCA) Configure and tune security scanning tools (Aquasec, Trivy, Dependabot, etc) Review cryptographic implementations against industry standards Validate authentication and authorization implementations Ensure compliance with OWASP ASVS More ❯
About this role WRITER is seeking an ApplicationSecurity Engineer with deep expertise in AppSec, DevSecOps automation, and red team operations to secure our AI and AGI applications. At WRITER, security is woven into the heart of our innovation. As we continue to push the boundaries of AI, we need a seasoned security engineer who can … applications, APIs, and model endpoints, simulating adversarial attacks to validate controls. Automate securitytesting at scale - Develop scripts, tools, and frameworks for continuous security assessment, including SAST, DAST, and SCA integration. Lead application-layer red team exercises - Plan and execute engagements that mimic sophisticated adversary techniques targeting AI systems. Hunt and validate vulnerabilities - Discover, reproduce, and … web application and API security, including cloud-native architectures. Technical Expertise Proficient with penetration testing tools (e.g., Burp Suite, OWASP ZAP, custom scripts). Skilled in SAST, DAST, and SCA tools. Strong understanding of application-layer attack techniques and exploitation. Experience with supply chain security and build pipeline hardening. Execution & Impact Demonstrated ability to identify More ❯
source solutions, and embracing enterprise agile methodology. We encourage professional development to ensure you bring innovative ideas to our products while satisfying your own intellectual curiosity. Our Global Information Security team's mission is to ensure the development, implementation, and management of a comprehensive program that effectively protects the confidentiality, integrity, and availability of Point72 information assets. Our team … is comprised of security professionals with expertise in a diverse portfolio of security disciplines. What you'll do Collaborate with the DevOps team to design, implement, and manage a robust DevSecOps framework for our software development pipeline, integrating security tools and processes into our CI/CD workflows to enhance the developer experience Champion a security … progress and identify outliers Implement and manage securitytesting tools and processes within the CI/CD pipeline, including staticapplicationsecuritytesting (SAST), dynamic applicationsecuritytesting (DAST), software composition analysis (SCA), and open source security (OSS) Work together with the DevOps team to automate security controls and More ❯
Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008. We're seeking a Product Security Engineer to support secure development across our engineering teams. In this hands-on role, you'll help identify and mitigate product risks by participating in security reviews, improving … tooling, and supporting vulnerability remediation. You'll work closely with senior security engineers and cross-functional teams to build security into our software development lifecycle. This is a great opportunity for a security-minded engineer who wants to grow their technical breadth while making meaningful impact in a cloud-first, DevOps-centric environment. You must be comfortable … Reviews: Conduct structured threat modeling and security assessments for new features, architectures, and services. Vulnerability Management & Remediation: Work closely with engineering teams to identify and remediate vulnerabilities from SAST, DAST, SCA, container security, and cloud security scans. Code & Architecture Review: Conduct secure code reviews and architectural security assessments to identify risks early in the development process. More ❯
Career progression with excellent training and development. Company events - Pub nights, sporting events, seasonal parties, socials Overview of the role IFX Payments is seeking a technically skilled and proactive ApplicationSecurity Engineer to embed secure development practices across its software delivery lifecycle. This role is critical in reducing application-layer risks, implementing secure coding standards, and ensuring … drive continuous improvement in applicationsecurity posture. Responsibilities Secure Development Lifecycle (SDLC) Embed security controls into CI/CD pipelines and development workflows. Implement and manage SAST, DAST, and SCA tools to detect vulnerabilities early in the lifecycle Conduct secure code reviews and support developers in remediating findings. Threat Modelling & Architecture Review Lead threat modelling sessions using … experience in applicationsecurity or secure software development. Strong understanding of OWASP Top 10, secure coding techniques, and threat modelling. Experience with security tools such as SAST, DAST, SCA, and vulnerability scanners. Familiarity with cloud platforms (Azure or AWS), CI/CD pipelines, and DevOps practices. Knowledge of regulatory frameworks (ISO 27001, FCA, NIST). Excellent communication More ❯
places! This is where you come in. The Opportunity As IAG Loyalty evolves into a Platform as a Service business, we're looking for a talented and passionate Senior ApplicationSecurity Engineer to join our security engineering team. You'll have a background in software engineering and a deep interest in application and API security. You … our CI/CD pipelines, facilitate threat modelling sessions, and review security-sensitive design decisions around authentication, cryptography, and logging. You'll also ensure that tools such as SAST, DAST, and SCA are effective and efficient, and that testing programmes - including pen testing, vulnerability scanning, and bug bounty - are delivering value. You'll triage vulnerabilities, support engineering … vulnerabilities, including the OWASP Top 10 Proficient in coding, scripting (e.g. Python, Bash), and automating security in CI/CD Hands-on experience with security tools like SAST, DAST, and SCA Familiar with cloud environments (especially AWS), containers, and microservices Comfortable reviewing technical designs, performing threat modelling, and advising on secure architecture Strong communicator who collaborates well with More ❯
Wembley, London, United Kingdom Hybrid / WFH Options
Football Association Limited
manager, engineer, quality assurance, mentor, problem solver, and collaborative team member-ensuring both technical excellence and alignment with business goals. What will you be doing? Collaborate with solution architects, application architects and data engineers to develop solutions meeting delivery goals. Identifying and capturing work that needs to be done, including dependencies external to the team. Responsible for onboarding new … ensuring compliance with FA development standards and processes. Optimise the developer experience to make the development process easier and help the team to become more productive. Ensure that production application services and applications are monitored and observed proactively - spotting potential issues early. Continuously stretch engineers with meaningful challenges and provide honest, constructive feedback to accelerate their development. Monitor and … delivery. Experience of providing technical leadership and oversight with offshore and/or third-party delivery teams. Experience with unit testing, TDD and BDD. Experience with working with SAST (StaticApplicationSecurityTesting) and SCA (Software Composition Analysis) tools e.g. Sonar. Experience with design and development of n-tier architectures. Knowledge of common software design More ❯
Wembley, London, United Kingdom Hybrid / WFH Options
Football Association Limited
technical excellence and alignment with business goals. The role is a 12-month Fixed-Term Contract based at Wembley Stadium. What will you be doing? Collaborate with solution architects, application architects and data engineers to develop solutions meeting delivery goals Identifying and capturing work that needs to be done, including dependencies external to the team Responsible for onboarding new … ensuring compliance with FA development standards and processes. Optimise the developer experience to make the development process easier and help the team to become more productive. Ensure that production application services and applications are monitored and observed proactively - spotting potential issues early. Continuously stretch engineers with meaningful challenges and provide honest, constructive feedback to accelerate their development. Monitor and … delivery Experience of providing technical leadership and oversight with offshore and/or third-party delivery teams Experience with unit testing, TDD and BDD Experience with working with SAST (StaticApplicationSecurityTesting) and SCA (Software Composition Analysis) tools e.g. Sonar. Experience with design and development of n-tier architectures Knowledge of common software design More ❯
challenges. We are dedicated to consistently updating our job descriptions to ensure we continue to lead in banking innovation. How you will contribute and key responsibilities: As a Senior Security Engineer, you will be instrumental in designing and implementing security measures for our mobile applications, services, and websites to meet the highest security standards. Your expertise will … help us continuously analyse and improve our security systems, ensuring that our products and services are not only secure by design but also comply with internal and external regulatory requirements. Other responsibilities include: Security Analysis and Improvement: Continuously analyse our security systems for potential improvements, ensuring that our defences remain at the forefront of cybersecurity practices. Vulnerability … Event driven streaming technologies, Logging and monitoring, networks, firewalls, load balancers, DNS, CDNs, Working knowledge of agile DevSecOps environments, and CI/CD (Git, Concourse, Terraform), Working knowledge of SAST, DAST, RASP, and IAST tools and building security into existing SDLC processes, Knowledge of cloud Security Architecture of public clouds (such as AWS or GCP), Security certification More ❯
Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008. We're seeking a Product Security Engineer to support secure development across our engineering teams. In this hands-on role, you'll help identify and mitigate product risks by participating in security reviews, improving … design reviews and backlog grooming. Threat Modelling : Participate in structured threat modelling exercises with guidance from senior team members. Vulnerability Triage : Work with engineering teams to review findings from SAST, SCA, DAST, and container scans and track remediation progress. Code & Config Review : Conduct basic secure code and configuration reviews, escalating high-risk findings as needed. Security Tooling & Automation : Help … e.g., Python, Java, JavaScript, Go, or C#). Familiarity with cloud platforms (AWS, Azure, or GCP) and container technologies (Docker, Kubernetes). Exposure to security tooling such as SAST, SCA, or DAST scanners (e.g., Semgrep, Endor, Burp). Basic understanding of identity and access controls (OAuth, SAML, API tokens). Strong collaboration and communication skills, with a willingness to More ❯
65k - £78K + bonus, benefits) We are working with a globally renowned and industry leading UK brand who are going through an exciting phase of growth across their wider Security function, resulting in the need for a DevSecOps Engineer. As a DevSecOps Engineer, you will work within a newly established team in a role that sees you provide hands … on ApplicationSecurity and DevSecOps responsibilities, as well as being involved in various strategic activities. Your duties would include setting-up, securing and enhancing pipelines, scripting and automation, as well as looking at how things are done, what improvements can be made, supporting cyber change initiatives and driving security awareness/practices as necessary. This role will … most companies of a similar size, who also offer some of the best perks & benefits available! Key skills and experience required: DevSecOps experience ApplicationSecurity expertise across SAST, DAST & SCA Background and experience in Software Development/Scripting/Automation Ability to work in a fast-paced environment Ability to work on-site for key strategic/important More ❯
future states of the organisation and make faster, more informed decisions. The company is headquartered in London, with offices in Philadelphia, The Hague, Toronto, and Sydney. Role The Principal Security Engineer is a strategic, hands-on leader responsible for evaluating, evolving, and executing Orgvue's security engineering strategy across our entire application development and cloud-hosting estate. … Partnering closely with Information Security, Engineering, and Product teams, you will embed secure-by-design principles throughout the software-development lifecycle (SDLC), champion modern DevSecOps practices, and ensure that security is a first-class citizen in everything we build and operate. This role reports directly to the Chief Technology Officer (CTO) and maintains a dotted-line relationship with … Threat Modeling & Risk Assessment - Conduct regular architecture and code-level reviews, drive remediation plans, and present risk posture to leadership. Tooling & Automation - Evaluate, select, and integrate security tooling (SAST, DAST, SCA, container scanners, CSPM, CWPP) and champion IaC/Terraform modules for reusable controls. Collaboration & Mentorship - Act as a trusted advisor to engineering squads, provide security training, and More ❯
an outsized impact, you'll thrive here at Zopa, so join us, and make it count.Want to see us in action? Follow us on The team: Zopa's Product Security team ensures security is baked into our products from the very start of their lifecycles, all the way to the end. We provide the more pre-emptive, design … team of 18. Our current projects include ongoing security assessments and threat models of new, in-house created AI-based systems, improving our security tools - such as SAST and SCA, refining a SLSA strategy, helping to roll out an upcoming bounty program and more! We pride ourselves in being able to collaborate and integrate seamlessly with an engineering … avoid Integrating security tooling, stitching together CI steps, scripts, and small tools to automate security controls and visualise their results in a helpful manner. This could include SAST, SCA, DAST, secrets scanning, vulnerability scanning, or other tooling Being guardians of our Secure Development Lifecycle, ensuring security controls are baked in and "pushed left" as much as reasonably More ❯
Senior Security Engineer - Build, Secure, and Scale in a Cloud-Native Environment Location: Hybrid (UK-based) Salary: Competitive + Excellent Benefits Employment Type: Full-time, Permanent Are you a seasoned Security Engineer with a passion for protecting infrastructure at scale? A rapidly growing technology-driven organisation is looking for a Senior Security Engineer to play a pivotal … You'll join a high-performing Platform Engineering team, working alongside cloud specialists, DevOps professionals, and software engineers to build secure, scalable platforms. This is more than a pure security role - it's an opportunity to be hands-on in architecture, engineering, and compliance, while leading the charge on modern, cloud-first security strategy. Responsibilties: Designing and implementing … Hands-on expertise in cloud security (preferably AWS), including securing hybrid and multi-region architectures. Practical knowledge of security tooling: IDS/IPS, SIEM, vulnerability scanners, encryption, SAST/DAST tools, OWASP ZAP, etc. Strong understanding of network security protocols and best practices. Scripting and automation experience (e.g. Python). Proven experience with incident response and threat More ❯
we're enabling the fully automated enterprise-but innovation must be secure to be transformative. That's where you come in. We're looking for a Field Chief Information Security Officer (Field CISO) to serve as a strategic security advisor to our customers and partners, guiding them through the complex landscape of compliance, governance, and secure development of … Automations and Agentic AI. You'll work at the intersection of customer success, product innovation, and cybersecurity thought leadership-translating strategic security insights into real-world impact. What you'll do Act as the primary security advisor for clients, assessing their needs, and providing strategic recommendations. Conduct security risk assessments and design tailored strategies that align with … knowledge of security frameworks (e.g., NIST, ISO 27001) and compliance standards (e.g., GDPR, HIPAA, PCI-DSS). Strong expertise in secure SDLC, and applicationsecurity tooling (SAST, DAST, SCA). Excellent communication skills with the ability to influence executive and technical stakeholders. Experience advising on or implementing security strategies in enterprise environments. Familiarity with software development More ❯
where you will be making an impact on the financial lives of thousands of savers. We're regulated by the Financial Conduct Authority in the UK. As a Senior Security Engineer, you will play a key role in protecting our systems, networks, and data while ensuring compliance with industry leading security standards such as ISO 27001. Your contributions … will be essential in maintaining customer trust and safeguarding critical information assets. This role sits within thePlatform Engineering Teamand requires a strong technical background, hands-on experience with security tools, and a collaborative mindset to work effectively across teams. The role will involveplatform engineering activities, contributing to the design, implementation, and optimisation of scalable infrastructure. If you're motivated … technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM, antivirus solutions, encryption mechanisms, and vulnerability assessment tools. Hands-on experience in security tools (e.g., SAST, DAST, OWASP ZAP). Relevant security certifications, such as Security+, IAT II/III level, or equivalent. Strong capability in risk assessment, vulnerability management, and data informed decision-making. More ❯
the firm managed approximately US$122 billion on behalf of major pension funds, endowments, foundations, governments and other investors based in the U.S. and abroad.Position Overview:The Senior Security Engineer, reporting to the Director of Information Assurance, is responsible for cloud platform and DevOps security. This senior role will call upon the candidate's DevSecOps experience to help Acadian … Shift Left, injecting security directly into our Software … Development Lifecycle and consistently governing our AWS Platform-as-a-Service (PaaS) infrastructure. We are looking for candidates with deep experience and understanding of continuous delivery, container security, SAST/DAST, secrets management, Identity and Access Management (IAM) governance, privilege management, encryption and key management, threat detection, logging, cloud infrastructure security and policy-as-code.What You'll Do More ❯
tougher times. What we're looking for We're hiring at both Level 3 (Senior) and Level 4 (Lead) . For calibration, candidates typically bring 5+ years of deep security engineering experience in high-growth, cloud-native SaaS environments - but we care more about impact than years. You'll be the first dedicated security specialist on the team … partnering with product engineers, GTM, and leadership to make Omnea the industry benchmark for security and trust. What You'll Do Make our … security posture airtight. Design and implement security controls across architecture, infrastructure and code (AWS Serverless, CDK/SST, React/TypeScript). Shift security left. Embed SAST/DAST, IaC scanning, secure coding standards and threat-modeling into every stage of our CI/CD pipeline. Own compliance & audits. Run our Vanta instance end-to-end (SOC More ❯
tougher times. What we're looking for We're hiring at both Level 3 (Senior) and Level 4 (Lead) . For calibration, candidates typically bring 5+ years of deep security engineering experience in high-growth, cloud-native SaaS environments - but we care more about impact than years. You'll be the first dedicated security specialist on the team … partnering with product engineers, GTM, and leadership to make Omnea the industry benchmark for security and trust. What You'll Do Make our … security posture airtight. Design and implement security controls across architecture, infrastructure and code (AWS Serverless, CDK/SST, React/TypeScript). Shift security left. Embed SAST/DAST, IaC scanning, secure coding standards and threat-modeling into every stage of our CI/CD pipeline. Own compliance & audits. Run our Vanta instance end-to-end (SOC More ❯
The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services. You will be an individual contributor on … the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident. You … Code Review, Exploit writing, etc. Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed. Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues. Work on DAST tools and related automation for auto-assessment and defect filing. Maintain the automation More ❯
cloud landing zones (Azure/AWS) with environment segregation (dev, test, UAT, prod). - Automate infrastructure using Infrastructure as Code (Terraform, ARM, CloudFormation) - Embed security and compliance controls (SAST/DAST/IaC/SBOM). - Enable observability (logging, metrics, tracing, alerting) and support SRE/incident management practices. - Partner with client stakeholders to align DevOps with FCA/… operational resilience and Lloyd's standards. - Support disaster recovery and business continuity planning, including resilience testing. - Mentor client teams in DevOps best practices and drive shift-left adoption of testing, security, and compliance. Skills & Experience: - Proven expertise with CI/CD tooling (Azure DevOps, GitHub Actions, Jenkins, GitLab). - Strong knowledge of infrastructure automation (Terraform, Ansible, Puppet, Chef … . - Hands-on experience with Azure and/or AWS in enterprise or hybrid environments. - Familiarity with containerisation & orchestration (Docker, Kubernetes). - Solid understanding of security controls and compliance in financial services. - Experience with observability tools (Prometheus, Grafana, ELK, Splunk, AppDynamics, etc.). - Awareness of UK/EU financial regulations (GDPR, PRA/FCA, Lloyd's). - Consulting experience More ❯
Employment Type: Permanent
Salary: £75000 - £100000/annum Bonus + Full Benefits
Press Tab to Move to Skip to Content Link Job Title: Principal Software Engineer - Security Engineer Job Reference: Band: BAND D Salary: £80,000-£90,000k depending on relevant skills, knowledge and experience. The expected salary range for this role reflects internal benchmarking and external market insights. Contract type: Permanent role Location: This is a hybrid role, and the … guidance. Promote secure SDLC practices across engineering teams, collaborating with InfoSec on shared tooling, templates and enablement. Help teams adopt secure coding standards and integrate automated security checks (SAST, DAST, dependency scanning) into CI/CD pipelines. Participate in threat modelling using InfoSec-led methodologies and coordinate validation and review workflows. Review technical designs, proposals and code for alignment … and common secure design patterns. You've helped teams adopt secure SDLC practices, working closely with central security or architecture groups. You know how to embed tools like SAST, DAST, secrets detection and dependency scanning into CI/CD pipelines, and have the scars to prove it. You've worked with complex, multi-tenant cloud platforms - ideally on AWS More ❯
This is a huge opportunity for an experienced and driven Platform Security Engineer to join a rapidly growing fintech team! As a Platform Security Engineer, you will play a key role in protecting our clients systems, networks, and data while ensuring compliance with industry leading security standards such as ISO 27001. This role sits within the Platform … Engineering Team and requires a strong technical background, hands-on experience with security tools, and a collaborative mindset to work effectively across teams. What you'll do: Develop and implement proactive security strategies, policies, and procedures to protect our systems, networks, and data assets. Lead regular security assessments, including vulnerability scans and penetration tests, identifying risks and … technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM, antivirus solutions, encryption mechanisms, and vulnerability assessment tools. Hands-on experience in security tools (e.g., SAST, DAST, OWASP ZAP). Relevant security certifications, such as Security+, IAT II/III level, or equivalent. Strong capability in risk assessment, vulnerability management, and data informed decision -making. More ❯
Months IR35 Status: Inside IR35 Our client, a leading investment bank, is seeking an experienced DevSecOps SME to join their team. This role will lead and advise on integrating security practices into DevOps pipelines. The ideal candidate will have deep expertise across development, security, and operations, with a strong focus on automation, CI/CD, and secure software … development lifecycle (SDLC) practices. Key Responsibilities Lead the integration of security into CI/CD pipelines. Advise on secure coding and deployment practices across teams. Implement and enforce security policies, standards, and best practices. Conduct threat modeling, risk assessments, and vulnerability management. Mentor and train teams on DevSecOps … principles and tools. Skills & Experience Required CI/CD Security Engineering: Proven experience designing and maintaining secure CI/CD pipelines. DevSecOps Tool Integration: Hands-on experience with SAST, DAST, SCA, and secrets management tools. Cross-Functional Collaboration: Ability to work closely with development, operations, and security teams. Threat Modeling & Risk Assessment: Strong knowledge of security risk More ❯