generation software products and architectures tailored for Post-Quantum Cryptography (PQC). In this leadership role, you will oversee the design, development, and optimisation of software solutions that secure and accelerate PQC algorithms, providing scalable and efficient cryptographic IP for software libraries and secure communication protocols. As part of the Engineering leadership team, you will work … latest security standards and regulations for post-quantum cryptography. Maintain and enforce robust secure software development lifecycle (SSDLC) principles, including side-channel attack resistance, securecoding practices, and cryptographic algorithm agility. Required Skills And Qualifications Required: Education: Phd, Bachelor's or Master's degree in Computer Science, Software Engineering, or a related field with a … Embedded Systems : Knowledge of secure software for embedded systems and IoT security. Software Security : Experience with software-based security solutions and an understanding of securecoding practices and vulnerability analysis. Secure Implementation: Understanding of the secure implementation of cryptography and systems which use cryptography. Knowledge of Implementation attacks such as Side More ❯
implement secure software development practices Integrate security gates into CI/CD pipelines following DevSecOps principles Establish security quality gates and acceptance criteria Develop securecoding standards based on OWASP guidelines Create security architecture patterns and reference implementations Security Code Reviews & Testing Conduct in-depth security code reviews for critical features Implement automated security testing … security linters and pre-commit hooks Create automated vulnerability tracking and remediation workflows Implement secret scanning and dependency checking Build security dashboards and metrics reporting Create securecoding guidelines for different technology stacks Develop a security champions program aligned with OWASP SAMM Conduct security training on platform-specific vulnerabilities Provide hands-on guidance during security incidents Build … years of application security experience Deep understanding of security vulnerabilities across web and mobile platforms Hands-on experience with security testing tools and methodologies Expertise in securecoding practices and design patterns Experience with modern development frameworks (React, Angular, ReactNative, Flutter) Security Domain Knowledge Expert knowledge of OWASP standards (Top 10, ASVS, SAMM, MASVS) Understanding of cryptographic More ❯
APIs, microservices, and web applications. Conduct detailed threat modeling workshops and architectural risk assessments, identifying vulnerabilities early and collaborating on risk mitigation strategies. Define and enforce securecoding standards and architectural best practices aligned with industry benchmarks such as OWASP Top 10 and API Security Top 10. Partner with cloud engineers and developers to embed security controls … based on business impact, exploitability, and regulatory implications, and work with engineering teams to implement timely fixes. Conduct regular security code reviews and support developers in securecoding practices to reduce vulnerabilities proactively. Governance, Compliance & Training Ensure that application security architecture and practices comply with relevant regulatory and industry standards such as PCI-DSS, SOC 2, ISO … SCA, and integrating these into automated build and deployment pipelines. Practical expertise with threat modeling methodologies such as STRIDE, PASTA, or Attack Trees. Strong knowledge of securecoding standards and common vulnerabilities (OWASP Top 10, API Security Top 10) and how to mitigate them. Familiarity with Google Cloud Platform (GCP) security features and best practices, including IAM More ❯
editorial standards, but also on the security, reliability and resilience of the systems behind every stream, story and service. In Engineering Enablement , we're the team that makes secure, high-velocity delivery possible. We build shared cloud platforms, developer tooling and guardrails that let hundreds of product teams ship confidently and sustainably. We're hiring a Principal Software … across the BBC. You'll work hands-on with engineering teams, applying InfoSec-led policies and architecture in delivery contexts. You'll support threat modelling, promote securecoding practices, and help scale Secure SDLC across the organisation - without reinventing governance or duplicating policy. It's a high-trust role with real impact: translating strategic security … security policy and architectural guidance. Promote secure SDLC practices across engineering teams, collaborating with InfoSec on shared tooling, templates and enablement. Help teams adopt securecoding standards and integrate automated security checks (SAST, DAST, dependency scanning) into CI/CD pipelines. Participate in threat modelling using InfoSec-led methodologies and coordinate validation and review workflows. More ❯
websites to meet the highest security standards. Your expertise will help us continuously analyse and improve our security systems, ensuring that our products and services are not only secure by design but also comply with internal and external regulatory requirements. Other responsibilities include: Security Analysis and Improvement: Continuously analyse our security systems for potential improvements, ensuring that our … well-considered recommendations to management. Development of Security Standards: Develop and maintain best practices and security standards for the organisation, guiding teams in the implementation of securecoding practices. Secure Design: Collaborate with development teams to ensure that web and mobile front-ends, as well as microservice architectures, are designed with robust security measures in … or application security. You should also have a proven experience and knowledge with any combination of the following: Threat modelling and risk assessments, Working knowledge of securecoding principles (OWASP and OWASP mobile, SANS ), Experience with designing and administering identity management (authentication and authorisation including policy enforcement points, token services, protocols such as OAuth2), Working knowledge of More ❯
Mentor and guide junior engineers, fostering continuous learning and growth Stay updated on industry trends and emerging technologies, contributing to internal tech communities Ensure adherence to securecoding standards to protect sensitive data and reduce vulnerabilities Develop and maintain robust unit tests to guarantee software reliability and maintainability Drive architectural decisions and long-term technology strategy aligned … to engage technical and non-technical stakeholders alike Confidence in navigating, integrating, and developing solutions across multiple systems Solid understanding of software architecture, design patterns, and securecoding best practices Hands-on experience with cloud platforms (AWS, Azure, Google Cloud) and CI/CD pipelines is a plus Familiarity with SQL/NoSQL databases and version control More ❯
Protect Granola's technology and users by building secure systems and fostering security culture We're looking for a security engineer who is passionate about application security to help us protect our users and build trust as we scale. In this role, you will be responsible for identifying and mitigating security vulnerabilities within Granola's applications, building security … to identify vulnerabilities in our applications Design and implement security tools, frameworks, and methodologies to protect against security threats Work closely with development teams to ensure securecoding practices are integrated throughout the SDLC Perform threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies Track, analyze, and manage vulnerabilities in applications, providing … threats, vulnerabilities, and technologies to enhance our security posture Your background looks something like: Extensive experience in application security, cybersecurity, or related fields Strong understanding of securecoding practices, threat modeling, risk assessments, and incident response Proficiency in programming languages such as TypeScript, Python, or similar Experience with security tools, security protocols, encryption methods, and application security More ❯
out new features Troubleshooting and fixing bugs in a structured and supportive environment Participating in code reviews and learning best practices from experienced team members Applying securecoding practices to protect our platform and data Contributing to documentation to support knowledge sharing across the team Required skills: We don't expect you to know everything, we're … collaborative mindset and a willingness to contribute to team discussions Useful skills to have: Exposure to CI/CD pipelines or automated testing An interest in securecoding, system performance, or scalable architecture Experience working on a live product or commercial software project Why you'll love working at Podfather: Podfather is a SaaS company helping logistics More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Anson McCade
UK SC clearance Are you ready to lead a high-impact security development and testing function? We’re looking for a Security Development and Test Director to oversee secure software development lifecycle, DevSecOps integration, and security testing at scale within a fast-growing security team. This is a unique opportunity to drive operational excellence and shape secure … Drive secure architecture standards and embed security controls into DevOps pipelines Oversee implementation and optimisation of security tooling (SAST, DAST, SCA, container security) Champion securecoding, threat modelling, and DevSecOps maturity improvements Manage budgets, profitability, and resource utilisation for your function Mentor and develop high-performing engineering and testing teams Key Responsibilities Support sales with … technical expertise and solution design Own service delivery quality and client satisfaction Define and enforce secure architecture and coding standards Lead DevSecOps integration with automated security testing in CI/CD Drive continuous process improvements and automation adoption Monitor and report on KPIs like vulnerability remediation, tool adoption, and training uptake Collaborate cross-functionally with architects, engineers More ❯
UK SC clearance Are you ready to lead a high-impact security development and testing function? We’re looking for a Security Development and Test Director to oversee secure software development lifecycle, DevSecOps integration, and security testing at scale within a fast-growing security team. This is a unique opportunity to drive operational excellence and shape secure … Drive secure architecture standards and embed security controls into DevOps pipelines Oversee implementation and optimisation of security tooling (SAST, DAST, SCA, container security) Champion securecoding, threat modelling, and DevSecOps maturity improvements Manage budgets, profitability, and resource utilisation for your function Mentor and develop high-performing engineering and testing teams Key Responsibilities Support sales with … technical expertise and solution design Own service delivery quality and client satisfaction Define and enforce secure architecture and coding standards Lead DevSecOps integration with automated security testing in CI/CD Drive continuous process improvements and automation adoption Monitor and report on KPIs like vulnerability remediation, tool adoption, and training uptake Collaborate cross-functionally with architects, engineers More ❯
Engineer to lead the security strategy and implementation across our connected hardware products. You will work closely with firmware, hardware, and cloud teams to ensure our devices are secure by design and resilient to emerging threats. Job Responsibilities Conduct threat modelling and risk assessments for IoT devices, firmware, and communication protocols. Design and implement secure boot … secure firmware updates (OTA), and hardware-level security controls (e.g., TPM, secure elements). Perform firmware and embedded software security assessments. Collaborate with hardware and embedded teams on secure product architecture. Monitor evolving IoT threat landscapes and update security policies accordingly. Contribute to internal security standards and assist in compliance with industry benchmarks (e.g. … IoT, embedded, or hardware security. Deep knowledge of embedded systems, firmware development, and relevant communication protocols. Experience with common IoT threat vectors and mitigations. Familiarity with securecoding practices in C/C++ or any other language and embedded environments. Hands-on experience with hardware debugging tools (e.g., JTAG, logic analyzers). Understanding of public key infrastructure More ❯
release monitoring and maintenance. Establish, enforce, and continuously evolve software engineering best practices (e.g., SOLID principles, domain-driven design, clean architecture, modular monoliths vs microservices). Drive consistency in coding standards, code review rigor, and software craftsmanship. Lead critical system architecture decisions, including technology stack evolution, refactoring legacy components, and designing future-state systems. Ensure integration patterns and service … contracts across internal and external APIs are robust, secure, and scalable. System Integration & Platform Ownership Oversee integration between business systems using APIs, middleware, and ETL pipelines, including Salesforce, Power Platform (PowerApps, PowerAutomate, LogicApps), SharePoint, and custom web applications. Lead optimization and governance around API design (RESTful services, rate limiting, versioning, monitoring, etc.). Ensure high data consistency, operational … the engineering of clean, reliable data sources and APIs. Security Engineering & Governance Partner with security engineers to integrate security throughout the software lifecycle (shift-left security, securecoding, threat modelling). Own the implementation of secure authentication/authorization practices, audit logging, encryption at rest/in transit, and other application security standards. Ensure software More ❯
release monitoring and maintenance. Establish, enforce, and continuously evolve software engineering best practices (eg, SOLID principles, domain-driven design, clean architecture, modular monoliths vs microservices). Drive consistency in coding standards, code review rigor, and software craftsmanship. Lead critical system architecture decisions, including technology stack evolution, refactoring Legacy components, and designing future-state systems. Ensure integration patterns and service … contracts across internal and external APIs are robust, secure, and scalable. System Integration & Platform Ownership Oversee integration between business systems using APIs, Middleware, and ETL pipelines, including Salesforce, Power Platform (PowerApps, PowerAutomate, LogicApps), SharePoint, and custom web applications. Lead optimization and governance around API design (RESTful services, rate limiting, versioning, monitoring, etc.). Ensure high data consistency, operational … engineering of clean, reliable data sources and APIs. Security Engineering & Governance Partner with security engineers to integrate security throughout the software life cycle (shift-left security, securecoding, threat modelling). Own the implementation of secure authentication/authorization practices, audit logging, encryption at rest/in transit, and other application security standards. Ensure software More ❯
or Cambridge Salary: £70,000 - £120,000 (depending on experience and clearance) We are looking for a Full Stack Developer to join a growing public sector team delivering secure, high-impact digital services across Defence & Security. This is a unique opportunity to use your development expertise to help solve real-world challenges for government and national security clients. … collaborative and supportive engineering team, working alongside technical leads, project managers, and stakeholders to deliver robust and scalable solutions. What you'll be doing: Designing, developing and deploying secure, high-performing web applications for government clients Working across the full software development lifecycle, from requirements through to production Building responsive user … interfaces using modern front-end technologies Developing scalable server-side functionality with appropriate frameworks and languages Creating and maintaining RESTful APIs for integration across platforms Following securecoding practices and supporting compliance with government security standards Conducting security reviews and supporting remediation of vulnerabilities Translating technical requirements into delivery plans and code Communicating effectively with both technical More ❯
or Cambridge Salary: £70,000 - £120,000 (depending on experience and clearance) We are looking for a Full Stack Developer to join a growing public sector team delivering secure, high-impact digital services across Defence & Security. This is a unique opportunity to use your development expertise to help solve real-world challenges for government and national security clients. … collaborative and supportive engineering team, working alongside technical leads, project managers, and stakeholders to deliver robust and scalable solutions. What you'll be doing: Designing, developing and deploying secure, high-performing web applications for government clients Working across the full software development lifecycle, from requirements through to production Building responsive user … interfaces using modern front-end technologies Developing scalable server-side functionality with appropriate frameworks and languages Creating and maintaining RESTful APIs for integration across platforms Following securecoding practices and supporting compliance with government security standards Conducting security reviews and supporting remediation of vulnerabilities Translating technical requirements into delivery plans and code Communicating effectively with both technical More ❯
or Cambridge Salary: £70,000 - £120,000 (depending on experience and clearance) We are looking for a Full Stack Developer to join a growing public sector team delivering secure, high-impact digital services across Defence & Security. This is a unique opportunity to use your development expertise to help solve real-world challenges for government and national security clients. … collaborative and supportive engineering team, working alongside technical leads, project managers, and stakeholders to deliver robust and scalable solutions. What you'll be doing: Designing, developing and deploying secure, high-performing web applications for government clients Working across the full software development lifecycle, from requirements through to production Building responsive user … interfaces using modern front-end technologies Developing scalable server-side functionality with appropriate frameworks and languages Creating and maintaining RESTful APIs for integration across platforms Following securecoding practices and supporting compliance with government security standards Conducting security reviews and supporting remediation of vulnerabilities Translating technical requirements into delivery plans and code Communicating effectively with both technical More ❯
Chester, Cheshire, United Kingdom Hybrid / WFH Options
Lloyds Bank plc
our 26 million customers by investing in cutting-edge technology and exceptional engineering talent. As a Backend Software Engineer, you'll play a key role in building scalable, secure, and resilient services that power our digital platforms. You'll work in a collaborative, agile environment where your ideas and expertise will shape the future of our backend systems. … Code (Terraform) and DevOps practices (CI/CD, Git, Jenkins). Work with SQL/NoSQL databases and Unix/Linux environments. Contribute to architectural decisions and ensure secure, scalable solutions. Mentor junior engineers and support community knowledge sharing. WHAT YOU'LL NEED We're looking for engineers who are technically strong, collaborative, and eager to grow. You … cloud platforms (GCP preferred) and IaC tools (Terraform). Proficiency in CI/CD tools and DevOps principles. Experience with TDD using JUnit and knowledge of securecoding practices. Any experience with the below would also be desirable: microservices, event-driven systems, and test automation (BDD, contract testing). ABOUT WORKING FOR US Our ambition is to More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Arc IT Recruitment
Senior Backend Developer (Node.js/TypeScript) – London (Hybrid working applies) Are you an experienced backend developer with a passion for building secure, high-performance systems in the cloud? We're looking for a Senior Node.js Engineer to help shape the future of embedded commerce experiences.You’ll be part of a small, high-impact engineering team building cloud-native … Node.js, and AWS services like Lambda, API Gateway, and DynamoDB. Ensuring continued PCI DSS compliance across the full development lifecycle, including patching, error tracing, and applying securecoding practices. Designing secure, well-documented service interfaces and abstractions over external APIs used by our clients. Participating in Agile ceremonies, collaborating closely with engineering, infrastructure, and external … hands-on experience with TypeScript and Node.js for backend development. Deep understanding of AWS serverless technologies. Working knowledge of Infrastructure-as-Code tools. Strong background in RESTful API development, secure authentication mechanisms, and API integration best practices. Experience working in regulated environments such as PCI DSS, or within other compliance-heavy systems. Familiarity with frontend frameworks like React More ❯
Senior Backend Developer (Node.js/TypeScript) - London (Hybrid working applies) Are you an experienced Back End developer with a passion for building secure, high-performance systems in the cloud? We're looking for a Senior Node.js Engineer to help shape the future of Embedded commerce experiences. You'll be part of a small, high-impact engineering team building … and AWS services like Lambda, API Gateway, and DynamoDB. Ensuring continued PCI DSS compliance across the full development life cycle, including patching, error tracing, and applying securecoding practices. Designing secure, well-documented service interfaces and abstractions over external APIs used by our clients. Participating in Agile ceremonies, collaborating closely with engineering, infrastructure, and external … on experience with TypeScript and Node.js for Back End development. Deep understanding of AWS serverless technologies. Working knowledge of Infrastructure-as-Code tools. Strong background in RESTful API development, secure authentication mechanisms, and API integration best practices. Experience working in regulated environments such as PCI DSS, or within other compliance-heavy systems. Familiarity with Front End frameworks like More ❯
a Lead Software Security Engineer to take our product security program to the next level. This is a high-impact, hands-on role where you'll guide the secure design and development of distributed systems, shape engineering and product roadmaps, and foster a security-first mindset across teams. WHAT YOU'LL DO Be a Security Champion Be a … trusted advisor and advocate for security across the development lifecycle, influencing architecture, design and implementation decisions. Embed securedevelopment practices into day-to-day workflows across engineering teams. Own the vulnerability management lifecycle: from discovery and triage to remediation tracking and coordinated disclosure. Build Secure Products by Design Conduct threat models, security architecture reviews and risk … strong understanding of security principles and engineering realities. Must-Have Experience Proven experience in application and product security, including secure design, threat modeling and securecoding practices. Strong knowledge of security issues in modern software stacks, such as Java, distributed systems, microservices, containers, etc. Experience integrating security tools into development pipelines (eg. static/dynamic More ❯
in C# .NET and/or Java Experience with Git, CI/CD tools, and database technologies (SQL/NoSQL) Excellent problem-solving and communication skills Securecoding and API architecture knowledge Desirable: Web development experience (React, TypeScript, JavaScript) Familiarity with AWS, containerisation, microservices, and serverless architecture Exposure to infrastructure as code (Terraform, CloudFormation) Benefits A highly More ❯
Essential Skills & Experience: Degree in Computer Science or relevant industry experience. Proven software development experience with C# .NET and/or Java . Solid understanding of securecoding practices and API architecture . Strong focus on software testing and quality assurance . Experience with git-based source control and CI/CD pipelines . Familiarity with both More ❯
tech providers, they're redefining how enterprise-grade security is built, deployed, and continuously improved. They're now seeking a Security Development and Test Director to lead their secure software engineering function, drive DevSecOps maturity, and embed security across the development lifecycle. This is a client-facing, commercially strategic position – ideal for a security leader who thrives at … the intersection of technical delivery and business growth. Why join? Shape and scale a modern secure-by-design function in a high-growth global firm Strategic autonomy to influence architecture standards, DevSecOps integration, and engineering culture Engage directly with major enterprise clients and shape security roadmaps that matter Be part of a company recognised for its DEI leadership … CI/CD workflows Owning security tooling strategy (SAST, DAST, SCA, container scanning) and driving adoption across development pipelines Building and mentoring high-performing teams in securecoding, DevSecOps, and threat modelling Leading engagements with major clients during pre-sales, delivery and review phases Managing financials, resource planning, and service maturity across the Secure SDLC More ❯
tech providers, they're redefining how enterprise-grade security is built, deployed, and continuously improved. They're now seeking a Security Development and Test Director to lead their secure software engineering function, drive DevSecOps maturity, and embed security across the development lifecycle. This is a client-facing, commercially strategic position - ideal for a security leader who thrives at … the intersection of technical delivery and business growth. Why join? Shape and scale a modern secure-by-design function in a high-growth global firm Strategic autonomy to influence architecture standards, DevSecOps integration, and engineering culture Engage directly with major enterprise clients and shape security roadmaps that matter Be part of a company recognised for its DEI leadership … CI/CD workflows Owning security tooling strategy (SAST, DAST, SCA, container scanning) and driving adoption across development pipelines Building and mentoring high-performing teams in securecoding, DevSecOps, and threat modelling Leading engagements with major clients during pre-sales, delivery and review phases Managing financials, resource planning, and service maturity across the Secure SDLC More ❯
delivery of a DevSecOps approach, and collaborating closely with our development teams. As one of our security engineers, you will drive continuous improvement across software applications, securecoding practices, and support the organisation's digital transformation initiatives. Who are the team? The role sits within an inclusive, diverse, respectful, and agile team of information security professionals responsible … to find and fix vulnerabilities. Conduct security assessments, support penetration testing, and address vulnerabilities. Transform technical requirements into an effective application development lifecycle within a DevSecOps toolchain. Ensure secure deployment strategies are scalable, repeatable, and highly available. Support technical and security teams in maintaining and securing the Azure cloud estate, providing coaching and mentoring. Improve and optimize processes … applications and solutions (Practitioner) Supporting and supporting security support methodologies (Expert) Process analysis and optimization (Practitioner) Risk-based decision making (Working) Modern development standards application (Practitioner) Software engineering: design, coding, testing (Practitioner) Prototyping and testing (Practitioner) Research and innovation in security (Working) Systems design and integration (Practitioner) Understanding security implications of transformation (Working) Experience: Integrating security practices into DevOps More ❯