1 to 25 of 37 Permanent SBOM Jobs in England

Application Security Engineer

Location
Windsor, Berkshire, United Kingdom
bring security into delivery without slowing everyone down. Practical experience with security tooling and practices including SAST, DAST, SCA, container scanning, vulnerability management, SBOM tooling such as CycloneDX, IaC security across Terraform, Bicep, Ansible and tools such as Trivy, plus Policy as Code and threat modelling. A proactive, curious ...

Senior Platform Engineer Cheltenham

Location
Cheltenham, England, United Kingdom
Experience with Kubernetes platform engineering and cluster lifecycle management. AWS Certifications at Associate level or above. Experience with security tooling such as SAST, DAST, SBOM generation, vulnerability scanning or policy-as-code. Experience working in high-security or regulated environments. Experience contributing to open-source projects. Experience of using ...

DevSecOps Engineer

Hiring Organisation
Oscar Associates (UK) Limited
Location
Surrey, South East, United Kingdom
Employment Type
Permanent
Salary
£80,000
vulnerabilities against OWASP Top 10 and CVSS principles Implementing secrets detection, credential rotation and secure Key Vault practices Strengthening software supply-chain security through SBOM generation, dependency scanning and artefact signing Supporting API security testing, threat modelling and third-party penetration tests Configuring Azure-native security tooling, including Defender ...

Lead Security Engineer

Location
West of England, England, United Kingdom
misconfiguration, identity exposure, and attack-path analysis using cloud-native tooling (AWS Inspector, GuardDuty, Security Hub, or equivalents). Experience securing software supply chains — SBOM generation, dependency provenance, artifact signing — and integrating this into build pipelines rather than a standalone assurance process. Experience building or shaping security engineering capability within ...

Product Security Engineer

Location
Manchester, England, United Kingdom
engineering at production scale: runtime detection, anomaly detection, alert tuning (Sigma, OSQuery, Falco, or equivalent) Supply-chain security: SLSA, sigstore/cosign, in-toto, SBOM tooling used as a real control Cloud-native attack patterns on AWS: IAM privilege analysis, IMDS exploitation, cross-account paths, KMS misuse, and the defences ...

Staff Cybersecurity Software & Systems Engineer (F/M/D)

Hiring Organisation
TE connectivity
Location
Cambridge, Cambridgeshire, UK
Employment Type
Full-time
risk tracking through the security case and register. Secure Development & DevSecOpsIntegrate security into CI/CD pipelines (SAST, DAST, SCA, container/IaC scans, SBOM) and define release gates. Maintain security workflows and coach engineers on secure coding and threat‐driven design. Validation & Supplier EngagementSupport V&V, penetration testing ...

Staff Cybersecurity Software & Systems Engineer (F/M/D)

Hiring Organisation
TE Connectivity
Location
Cambridgeshire, United Kingdom
Employment Type
Full Time
tracking through the security case and register. Secure Development & DevSecOps Integrate security into CI/CD pipelines (SAST, DAST, SCA, container/IaC scans, SBOM) and define release gates. Maintain security workflows and coach engineers on secure coding and threat‐driven design. Validation & Supplier Engagement Support V&V, penetration testing ...

Solutions Engineer

Location
Greater London, England, United Kingdom
Kubernetes, CI/CD, git integrations and build tools Hands-on experience with AppSec tools (part or all) such as: SCA/SAST/SBOM Management/Container Security Ability to build software pipelines with various DevOps tools Hands-on experience with cloud infrastructures - AWS/Azure/GCP - Mandatory ...

Platform Engineer

Hiring Organisation
Richmond Square Consulting Limited
Location
Cheltenham, Gloucestershire, South West, United Kingdom
Employment Type
Permanent, Work From Home
delivery Experience building Internal Developer Platforms (IDPs) or developer enablement platforms would be particularly interesting. Exposure to tools or concepts including Coder, SAST, DAST, SBOM generation, vulnerability scanning or policy-as-code would also be advantageous. AWS certification at Associate level or above would be beneficial but is not essential ...

Platform Engineer

Hiring Organisation
Richmond Square Consulting Limited
Location
Salford, Greater Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
delivery Experience building Internal Developer Platforms (IDPs) or developer enablement platforms would be particularly interesting. Exposure to tools or concepts including Coder, SAST, DAST, SBOM generation, vulnerability scanning or policy-as-code would also be advantageous. AWS certification at Associate level or above would be beneficial but is not essential ...

Senior Platform Engineer

Location
Reigate, England, United Kingdom
cloud and SaaS security best practices: least privilege, managed identities, secret management, network security, private endpoints, and secure software supply chain practices (image scanning, SBOM, dependency governance). Awareness of compliance, data residency and multi‐region considerations in multi‐tenant Azure environments. Technical leadership and communication Ability to run proofs ...

Infrastructure Security Engineer

Location
Greater London, England, United Kingdom
products in production Design and implement supply chain security controls across build and deployment pipelines, including artefact signing, provenance, dynamic admission controls and SBOM generation Requirements Strong engineering background, with experience building and shipping production systems Proven track record of building and scaling security programs Fluency in at least ...

Senior TypeScript CI/CD Automation Engineer

Hiring Organisation
Luxoft
Location
London, UK
Employment Type
Full-time
Tekton a plusCloud (K8s and/or GCP) expertiseNice to haveUnderstanding of security concerns and frameworks such as SLSA and ensuring provenance of the SBOM a plusProven communication and influencing skills, experience coaching and mentoring a plusOtherLanguagesEnglish: B2 Upper IntermediateSeniorityLeadLondon, United Kingdom of Great Britain and Northern IrelandReq. VR-124421Other ...

Platform Engineer

Location
Leeds, England, United Kingdom
with Docker and Kubernetes Understanding of SQL Server and NoSQL technologies such as Cosmos DB or RavenDB Exposure to secure development practices including SAST, SBOM generation and vulnerability scanning Why join System C? At System C, you'll work alongside talented people who care deeply about making a difference. ...

Platform Engineer

Location
Oxford, England, United Kingdom
with Docker and Kubernetes Understanding of SQL Server and NoSQL technologies such as Cosmos DB or RavenDB Exposure to secure development practices including SAST, SBOM generation and vulnerability scanning At System C, you'll work alongside talented people who care deeply about making a difference. We foster a supportive environment ...

Senior DevSecOps Architect

Location
Greater London, England, United Kingdom
Join us to directly influence the future of technology at JPMorganChase. As a Senior DevSecOps Architect, you’ll collaborate with top cybersecurity and engineering talent, solving complex challenges and enabling safe, secure innovation. Your passion ...

Senior DevSecOps Architect

Hiring Organisation
JP Morgan Chase
Location
London, UK
Employment Type
Full-time
Join us to directly influence the future of technology at JPMorganChase. As a Senior DevSecOps Architect, you'll collaborate with top cybersecurity and engineering talent, solving complex challenges and enabling safe, secure innovation. Your passion ...

Senior DevSecOps Architect

Location
Greater London, England, United Kingdom
Join us to directly influence the future of technology at JPMorganChase. As a Senior DevSecOps Architect, you’ll collaborate with top cybersecurity and engineering talent, solving complex challenges and enabling safe, secure innovation. Your passion ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
JP Morgan Chase
Location
London, UK
Employment Type
Full-time
advanced SIEM correlation rules, custom data parsers, and detection logic to significantly minimize alert fatigue for the SOC team. Architect the end-to-end SBOM lifecycle to continuously track, analyze, and mitigate open-source and third-party software supply chain risks. Design a risk-based vulnerability management platform that automatically ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
advanced SIEM correlation rules, custom data parsers, and detection logic to significantly minimize alert fatigue for the SOC team. Architect the end-to-end SBOM lifecycle to continuously track, analyze, and mitigate open-source and third-party software supply chain risks. Design a risk-based vulnerability management platform that automatically ...

Application & Development Security Lead

Hiring Organisation
WPP
Location
London, UK
Employment Type
Full-time
helping build secure, resilient products and platforms for the future. What you'll be doing: Defineandevolvesecuresoftwaredevelopmentstandards,guardrailsandgovernancepractices. Partnerwithengineeringandproductteamstoembedsecurityintodevelopmentlifecyclesanddeliveryprocesses. Improvevisibilityandmanagementofsoftwaresecurityrisks,includingvulnerabilities,insecurecodingtrendsanddependencyrisks. Strengthengovernanceofsoftwaresupplychains,open-sourcedependenciesandSoftwareBillofMaterials(SBOM)practices. SupportthedevelopmentofsecureCI/CDpipelinesthroughcontrolssuchascodescanning,secretsdetectionandreleasegovernance. HelpshapeWPP'sapproachtosecuringAI-enabledapplications,includingareassuchaspromptinjectionresilience,agentcontrolsanddataprotection. Provideinsight,reportingandchallengetoensuresoftwaresecurityrisksareunderstood,prioritisedandeffectivelymanaged. Drivecontinuousimprovementsinsoftwaresecuritymaturityacrosstheorganisation. What you'll need: Experienceinapplicationsecurity,softwaresecurity,DevSecOps,softwareassuranceortechnicalsecuritygovernance. StrongunderstandingofSecureSDLC,applicationsecurityandmodernsoftwaredevelopmentpractices. KnowledgeofCI ...

AI Staff Security Engineer

Hiring Organisation
Matchtech
Location
London, UK
Employment Type
Full-time
protect them from advanced threats. Key ResponsibilitiesAugment the complete vulnerability management lifecycle to prioritize AI-centric risks, including supply chain attacks using tools for SBOM tracking, and targeting critical unpatched legacy infrastructure. Design, deploy, and operationalize AI Detection and Response (AIDR) solutions to protect proprietary models and systems from novel ...

Cybersecurity Governance & Assurance Specialist

Location
Greater London, England, United Kingdom
safety relationship is a plus Understanding of embedded product environments including ECUs, CAN, J1939, and diagnostics such as UDS is a plus Familiarity with SBOM concepts and their role in vulnerability monitoring and compliance evidence is a plus Self‐motivated, analytical, and pragmatic, with strong interpersonal skills and a collaborative ...

Release Engineer

Location
Greater London, England, United Kingdom
into environments with zero internet connectivity. Enforce Software Supply Chain Security: Implement cryptographic signing (e.g., Sigstore/Cosign, SLSA provenance), Software Bill of Materials (SBOM) generation, and automated vulnerability gating across all build pipelines. Automate Infrastructure-as-Code (IaC): Maintain release-side IaC and GitOps delivery frameworks (ArgoCD, Flux, Terraform … premise, edge, or air-gapped systems). Supply Chain Security Fluency: Solid understanding of build integrity concepts, artifact signing, provenance tracking, vulnerability scanning, and SBOM standards. CI/CD & GitOps Mastery: Proven experience designing enterprise pipelines (GitHub Actions, GitLab CI, Tekton, ArgoCD) with robust testing, canary/blue-green strategies ...

Information Security Engineer - Vulnerability Management

Location
Greater London, England, United Kingdom
Endpoint vulnerability scanning, vulnerability intelligence, AppSec vulnerability management, vulnerability management of cloud native workloads, external attack surface management Experience with Software Bill of Materials (SBOM) management, specifically ingesting and correlating standard formats Benefits 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra ...