Product Security Engineer
- Location
- Manchester, England, United Kingdom
provenance and integrity for what we build (SLSA, sigstore patterns, signed artifacts), dependency trust as a real control rather than a manifest scan, build-pipeline isolation, third-party risk as runtime telemetry. When the next big supply-chain incident lands, we should know within hours whether it touches us. … Security as your specialism, with a track record of defence systems you've shipped: detections that fired on real attacks, supply-chain or build-pipeline hardening, hardened product surfaces, IR automation that contained an incident. Be ready to talk about one in depth. Adversarial instincts. You follow supply-chain ...