26 to 50 of 57 SBOM Jobs in the UK

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
JP Morgan Chase
Location
London, UK
Employment Type
Full-time
advanced SIEM correlation rules, custom data parsers, and detection logic to significantly minimize alert fatigue for the SOC team. Architect the end-to-end SBOM lifecycle to continuously track, analyze, and mitigate open-source and third-party software supply chain risks. Design a risk-based vulnerability management platform that automatically ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
advanced SIEM correlation rules, custom data parsers, and detection logic to significantly minimize alert fatigue for the SOC team. Architect the end-to-end SBOM lifecycle to continuously track, analyze, and mitigate open-source and third-party software supply chain risks. Design a risk-based vulnerability management platform that automatically ...

Application & Development Security Lead

Hiring Organisation
WPP
Location
London, UK
Employment Type
Full-time
helping build secure, resilient products and platforms for the future. What you'll be doing: Defineandevolvesecuresoftwaredevelopmentstandards,guardrailsandgovernancepractices. Partnerwithengineeringandproductteamstoembedsecurityintodevelopmentlifecyclesanddeliveryprocesses. Improvevisibilityandmanagementofsoftwaresecurityrisks,includingvulnerabilities,insecurecodingtrendsanddependencyrisks. Strengthengovernanceofsoftwaresupplychains,open-sourcedependenciesandSoftwareBillofMaterials(SBOM)practices. SupportthedevelopmentofsecureCI/CDpipelinesthroughcontrolssuchascodescanning,secretsdetectionandreleasegovernance. HelpshapeWPP'sapproachtosecuringAI-enabledapplications,includingareassuchaspromptinjectionresilience,agentcontrolsanddataprotection. Provideinsight,reportingandchallengetoensuresoftwaresecurityrisksareunderstood,prioritisedandeffectivelymanaged. Drivecontinuousimprovementsinsoftwaresecuritymaturityacrosstheorganisation. What you'll need: Experienceinapplicationsecurity,softwaresecurity,DevSecOps,softwareassuranceortechnicalsecuritygovernance. StrongunderstandingofSecureSDLC,applicationsecurityandmodernsoftwaredevelopmentpractices. KnowledgeofCI ...

AI Staff Security Engineer

Hiring Organisation
Matchtech
Location
London, UK
Employment Type
Full-time
protect them from advanced threats. Key ResponsibilitiesAugment the complete vulnerability management lifecycle to prioritize AI-centric risks, including supply chain attacks using tools for SBOM tracking, and targeting critical unpatched legacy infrastructure. Design, deploy, and operationalize AI Detection and Response (AIDR) solutions to protect proprietary models and systems from novel ...

Cybersecurity Governance & Assurance Specialist

Location
Greater London, England, United Kingdom
safety relationship is a plus Understanding of embedded product environments including ECUs, CAN, J1939, and diagnostics such as UDS is a plus Familiarity with SBOM concepts and their role in vulnerability monitoring and compliance evidence is a plus Self‐motivated, analytical, and pragmatic, with strong interpersonal skills and a collaborative ...

Senior Application Security Engineer

Hiring Organisation
Cloudsmith
Location
Belfast, UK
Employment Type
Full-time
TL;DR: We're looking for a deeply technical Application Security Engineer to embed inside engineering and help secure Cloudsmith 2.0, the operating system for the modern software supply chain. The ideal person is a ...

Release Engineer

Location
Greater London, England, United Kingdom
into environments with zero internet connectivity. Enforce Software Supply Chain Security: Implement cryptographic signing (e.g., Sigstore/Cosign, SLSA provenance), Software Bill of Materials (SBOM) generation, and automated vulnerability gating across all build pipelines. Automate Infrastructure-as-Code (IaC): Maintain release-side IaC and GitOps delivery frameworks (ArgoCD, Flux, Terraform … premise, edge, or air-gapped systems). Supply Chain Security Fluency: Solid understanding of build integrity concepts, artifact signing, provenance tracking, vulnerability scanning, and SBOM standards. CI/CD & GitOps Mastery: Proven experience designing enterprise pipelines (GitHub Actions, GitLab CI, Tekton, ArgoCD) with robust testing, canary/blue-green strategies ...

Information Security Engineer - Vulnerability Management

Location
Greater London, England, United Kingdom
Endpoint vulnerability scanning, vulnerability intelligence, AppSec vulnerability management, vulnerability management of cloud native workloads, external attack surface management Experience with Software Bill of Materials (SBOM) management, specifically ingesting and correlating standard formats Benefits 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra ...

Principal Engineer – Product Cybersecurity Compliance

Location
Rocester, England, United Kingdom
supplier cybersecurity assurance practices. You are familiar with Cyber Resilience Act requirements and product security reporting obligations. You have experience working with Software Bill of Materials (SBOMs) and vulnerability monitoring processes. You have strong technical writing skills and are comfortable producing governance, assurance and compliance documentation. This role offers ...

Senior DevSecOps Engineer

Hiring Organisation
Sanderson Recruitment
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£600 - £650 per day
/CD delivery pipelines Implementing container, IaC, secrets and software composition scanning Building software supply chain security controls including image signing, verification and SBOM generation Developing Policy-as-Code controls using OPA, Rego, Kyverno or similar technologies Securing and hardening EKS environments through RBAC, Network Policies and Admission Controllers Supporting … Service Mesh security AWS Private CA and IAM Roles Anywhere Harness CI/CD OPA, Gatekeeper, Kyverno or OSCAL Sigstore, Cosign, SLSA and SBOM tooling Internal Developer Platform (IDP) security AWS Security Specialty, CKS, CISSP or equivalent certifications Experience within regulated financial services environments Why Apply? This is an opportunity ...

Senior DevSecOps Engineer

Hiring Organisation
Sanderson
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£600.00 - £650.00 per day
/CD delivery pipelines Implementing container, IaC, secrets and software composition scanning Building software supply chain security controls including image signing, verification and SBOM generation Developing Policy-as-Code controls using OPA, Rego, Kyverno or similar technologies Securing and hardening EKS environments through RBAC, Network Policies and Admission Controllers Supporting … Service Mesh security AWS Private CA and IAM Roles Anywhere Harness CI/CD OPA, Gatekeeper, Kyverno or OSCAL Sigstore, Cosign, SLSA and SBOM tooling Internal Developer Platform (IDP) security AWS Security Specialty, CKS, CISSP or equivalent certifications Experience within regulated financial services environments Why Apply? This is an opportunity ...

Principal Machine Learning Engineer – Production Systems

Location
Bristol, England, United Kingdom
REST for cross-language integration. Performance Optimization : GPU acceleration (CUDA/cuDNN), mixed precision, XLA, profiling. Observability : Metrics, tracing, structured logging, dashboards. Security : SBOM, image signing, role-based access, vulnerability scanning. Preferred Qualifications Experience with ONNX Runtime Training, PyTorch, or hybrid ML architectures. Familiarity with distributed training strategies and multi ...

Senior Software Engineer – DevX SCAnS

Location
London, England, United Kingdom
prevent malware from entering the network, which provides us a unique opportunity to help build this inventory. Our team is responsible for: Providing SBOM tooling and helping integrate it into our supply chain Working across ecosystems to optimize our tooling for the best quality results Controlling and tracking the ingress ...

Platform Engineer III - (Pipelines & Developer Experience)

Location
Leeds, England, United Kingdom
Senior Engineer, Platform - (Pipelines & Developer Experience) United Kingdom (Remote) Job Description Senior Engineer, Platform - (Pipelines & Developer Experience) Overview As Fanatics Betting & Gaming (FBG) accelerates Fanatics' mission to build the ultimate digital sports platform, the Platform ...

Remote SQA Engineer for Battery Systems & Embedded C

Location
Gateshead, England, United Kingdom
Quality Assurance Engineer to develop and validate a comprehensive SQA test suite for High Voltage Battery projects. The role requires static and dynamic analysis, SBOM creation, and vulnerability assessment, with integration into CI processes. You will coordinate with suppliers and work with cross-functional teams to ensure compliance with safety ...

DevX Build Pipeline/ DevOps Engineer CGEMJP00349975

Hiring Organisation
Experis
Location
Sheffield, South Yorkshire, Yorkshire, United Kingdom
Employment Type
Contract
Shared Library powering multi-language builds (Java/Maven, Node/NPM, Python, Helm, Terraform, containers). Deliver fast, secure, provenance-rich pipelines (SLSA, SBOM, digests) and strengthen supplychain integrity across teams. Core Responsibilities : Design and maintain Groovy pipeline steps (build, test, package, scan, deploy). Extend Python tooling … SLSA provenance, SBOM generation, hash/digest accuracy, and security scan aggregation (SonarQube, Sonatype IQ, SAST/Container). Optimize performance (parallel builds, caching, scope-reduced BOMs, dependency prefetch). Ensure artifact integrity (correct SHA1/SHA256 mapping, reproducible inputs, evidence modeling). Refactor legacy scripts (remove global state, consolidate ...

Lead Security Engineer

Location
Greater London, England, United Kingdom
scalable security capabilities integrated into engineering workflows Embed security into the software development lifecycle by implementing automated controls Improve software supply chain security through SBOM generation and dependency visibility Analyze and enrich vulnerability data with contextual information for effective remediation Provide actionable insights and guidance to engineering teams to address … security, DevSecOps, or engineering‐led security teams Familiarity with security tools such as Snyk and Wiz Knowledge of software supply chain security concepts, including SBOM, SLSA, and dependency management Cloud certifications, preferably GCP (e.g., Professional Cloud Architect, Professional DevOps Engineer) Experience operating in large‐scale enterprise environments within regulated industries ...

Lead Security Engineer

Hiring Organisation
JP Morgan Chase
Location
London, UK
Employment Type
Full-time
operate scalable security capabilities integrated into engineering workflowsEmbed security into the software development lifecycle by implementing automated controlsImprove software supply chain security through SBOM generation and dependency visibilityAnalyze and enrich vulnerability data with contextual information for effective remediationProvide actionable insights and guidance to engineering teams to address security issuesCollaborate with … platform security, DevSecOps, or engineering-led security teamsFamiliarity with security tools such as Snyk and WizKnowledge of software supply chain security concepts, including SBOM, SLSA, and dependency managementCloud certifications, preferably GCP (e.g., Professional Cloud Architect, Professional DevOps Engineer)Experience operating in large-scale enterprise environments within regulated industriesAbility to communicate ...

Vulnerability Management Engineer

Hiring Organisation
McCabe & Barton
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
Up to £800 per day
security outcomes. Responsibilities Vulnerability Discovery & Triage Scan Azure and GCP infrastructure for known vulnerabilities using Datadog, Sentinel, or equivalent tooling. Integrate with SCA/SBOM tools such as Snyk for dependency scanning. Prioritise vulnerabilities based on CVSS score, exploitability, and business impact. Maintain a live vulnerability register and risk dashboard. … container security and vulnerability scanning. Security & Compliance Knowledge of DORA, FCA, and SOC2 requirements. Understanding of patch management and change control processes. Experience with SBOM and Software Composition Analysis (SCA) tooling. Comfortable working in a fast-paced, regulated environment. ...

Staff Software Engineer (Provenance)

Hiring Organisation
Cloudsmith
Location
Belfast, UK
Employment Type
Full-time
attestation payloads from CI/CD systems, public registries, signed bundles, and customer-uploaded artifacts across a wide range of formats (SLSA, in-toto, SBOM attestations, Sigstore bundles etc).Store: Own the storage architecture for signed provenance metadata. Validate: Build the validation engine that verifies cryptographic integrity and evaluates attestation … their output. Cryptographic Foundations: Comfortable with signing and verification: key material, ECDSA/RSA, certificate chains, OIDC-based keyless signing flows, and transparency logs. SBOM Formats: Familiarity with CycloneDX and SPDX, and how they are packaged as attestation artifacts. Backend & Platform EngineeringExperience: 5+ years of production backend engineering, with real ...

DevSecOps & Governance Architect

Hiring Organisation
Develop
Location
London, United Kingdom
Employment Type
Contract
DevSecOps & Governance - Outside IR35 - rate negotiable - remote UK - Start date mid October - Must have active SC clearance An opportunity has arisen for an experienced DevSecOps & Governance Architect to play a key role in shaping secure ...

Cybersecurity Compliance Advisor

Location
Farnborough, England, United Kingdom
* United Kingdom - Hampshire - Farnborough Why Work at Lenovo We are Lenovo. We do what we say. We own what we do. We WOW our customers. Lenovo is a US$83 billion revenue global technology powerhouse ...

Principal IVD Engineer, Clinical Software

Location
Wilmslow, England, United Kingdom
Overview Waters is seeking a Principal IVD Software Engineer to help shape the future of our LCMS Clinical and Diagnostic software portfolio. This is a highly influential individual contributor role suited to an experienced software ...

Staff Software Engineer (Provenance)

Location
United Kingdom
attestation payloads from CI/CD systems, public registries, signed bundles, and customer-uploaded artifacts across a wide range of formats (SLSA, in-toto, SBOM attestations, Sigstore bundles etc). Store: Own the storage architecture for signed provenance metadata. Validate: Build the validation engine that verifies cryptographic integrity and evaluates … their output. Cryptographic Foundations: Comfortable with signing and verification: key material, ECDSA/RSA, certificate chains, OIDC-based keyless signing flows, and transparency logs. SBOM Formats: Familiarity with CycloneDX and SPDX, and how they are packaged as attestation artifacts. Backend & Platform Engineering Experience: 5+ years of production backend engineering, with ...

Python Platform Engineer

Hiring Organisation
Develop
Location
South East London, London, United Kingdom
Employment Type
Contract
Outside IR35 - 6 month Contract - Rates Negotiable - Active SC Clearance required Our client is looking for a Python/Platform Engineer to build secure, reliable and easy-to-use platform capabilities for development teams. Youll ...