5 of 5 Permanent SLSA Jobs in the UK excluding London

Senior Application Security Engineer

Hiring Organisation
Cloudsmith
Location
Belfast, Down, United Kingdom
Salary
£ 60 K
immutable blobs, mutable metadata, package identity, checksums, upstream proxying, private repos, access control, caching, and promotion.Provenance and trust mechanisms such as SBOMs, signing, attestations, SLSA, Sigstore, in-toto, trusted publishing, and zero-trust software delivery.Bonus PointsExperience securing artifact management, package registry, container registry, CI/CD, DevOps, developer tooling ...

Senior Application Security Engineer

Hiring Organisation
Cloudsmith
Location
Belfast, UK
Employment Type
Full-time
blobs, mutable metadata, package identity, checksums, upstream proxying, private repos, access control, caching, and promotion. Provenance and trust mechanisms such as SBOMs, signing, attestations, SLSA, Sigstore, in-toto, trusted publishing, and zero-trust software delivery. Bonus PointsExperience securing artifact management, package registry, container registry, CI/CD, DevOps, developer tooling ...

Principal Software Engineer - Platform Engineering - Accelerator Business

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
technical leaders on safe scaling patterns and reuse. Preferred qualifications, capabilities, and skills Advanced knowledge ofCI/CD, application resiliency, and secure delivery (e.g., SLSA framework and GitOps). Deep experience with Observability and Monitoring tools (e.g., Prometheus, Grafana, OTEL). Expertise in performance optimisation of distributed systems (e.g., caching ...

Staff Software Engineer (Provenance)

Hiring Organisation
Cloudsmith
Location
Belfast, Down, United Kingdom
Salary
£ 60 K
accepting provenance and attestation payloads from CI/CD systems, public registries, signed bundles, and customer-uploaded artifacts across a wide range of formats (SLSA, in-toto, SBOM attestations, Sigstore bundles etc).Store: Own the storage architecture for signed provenance metadata.Validate: Build the validation engine that verifies cryptographic integrity … evaluates attestation data against configurable customer trust policies — SLSA level requirements, allowed builder identities, key material, and more.Expose: Deliver clean, well-documented APIs that make provenance data useful to customers and to other parts of the platform — queryable, auditable, and reliable.Collaborate: Work closely with product, customer success, and the wider ...

Product Security Engineer

Location
Manchester, England, United Kingdom
dependencies, build pipelines, and CI providers. You'll engineer the systems that make our supply chain defensible: provenance and integrity for what we build (SLSA, sigstore patterns, signed artifacts), dependency trust as a real control rather than a manifest scan, build-pipeline isolation, third-party risk as runtime telemetry. When … people around you Desirable Detection engineering at production scale: runtime detection, anomaly detection, alert tuning (Sigma, OSQuery, Falco, or equivalent) Supply-chain security: SLSA, sigstore/cosign, in-toto, SBOM tooling used as a real control Cloud-native attack patterns on AWS: IAM privilege analysis, IMDS exploitation, cross-account paths ...