Senior Product Security Engineer

Posted Aug 25

This is a fully remote position, open to applicants in United Kingdom.

📋 Description

• Facilitate STRIDE-based threat modeling sessions alongside product and engineering teams, focusing on clinical safety, potential abuses, and business logic vulnerabilities.

• Take ownership of and enhance the Secure by Design process, which includes self-evaluation screening, secure design reviews, threat modeling pathways, and automated tools.

• Convert threat models into actionable, prioritized controls that can be implemented by engineering teams.

• Advocate for security decisions to be made early in the development process to ensure fixes are incorporated from the outset rather than added later.

• Evaluate and secure production AI systems, encompassing LLM features, retrieval pipelines, agentic workflows, tool integrations, MCP, and API surfaces.

• Develop threat models and controls addressing agent-specific risks, including prompt injection, tool misuse, excessive agency, data exfiltration, unsafe autonomy, and supply chain vulnerabilities.

• Conduct automated penetration testing for applications and APIs across web platforms, mobile backends, GCP cloud-native services, internal tools, and AI functionalities.

• Lead third-party penetration testing engagements and collaborate with engineering on remediation efforts.

• Link findings into plausible attack paths to illustrate potential impacts.

• Integrate security into development pipelines through SAST, SCA, secrets detection, IaC scanning, container security, and maintaining dependency hygiene.

• Collaborate with platform and engineering teams to enhance authentication, authorization, secrets management, tenancy isolation, and monitoring and detection capabilities.

• Engage with the security community and contribute by publishing research, write-ups, or blog posts under your own name.

• Work alongside Engineering, Product, Clinical, Legal, and executive teams as part of the Cyber Security function.


⛳️ Requirements

• Extensive hands-on application security experience in a senior role within a product engineering setting.

• Proven experience in threat modeling practices.

• Practical offensive security skills with modern web and API frameworks.

• Relevant certifications or equivalent demonstrable experience, such as OSCP, OSWE, CREST, or Burp Suite Certified Practitioner.

• Capability to read and understand code in at least one production language and effectively review pull requests.

• Familiarity with cloud-native architectures and security models; GCP preferred, with AWS or Azure experience considered transferable.

• Experience in integrating security tools into CI/CD pipelines.

• Proven history of delivering security enhancements through collaboration with other teams.

• Experience in securing AI or agentic systems in a production environment.

• Practical experience in securing Kubernetes environments.

• Experience managing cloud security posture using CNAPP and CSPM solutions, primarily on GCP.

• Experience in regulated environments, such as healthcare or fintech, is advantageous.

• Exposure to detection engineering or incident response related to application attacks is a plus.

• Established presence in the community, such as presentations, published research, or maintained projects, is a bonus.


🏝️ Benefits

• Share options.

• 25 days of holiday, plus bank holidays, increasing to 30 days the longer you remain with Numan.

• Health insurance provided by Vitality.

• Electric car salary sacrifice scheme available through Octopus.

• Enhanced maternity and parental leave.

• A day off to celebrate your Birthday.

• Nursery benefits offered by YellowNest.

• Employee assistance program, including access to therapy, financial planning, and discounts.

• Generous pension contributions from both employee and employer.

• Flexible working arrangements, including a dog-friendly office in Farringdon.

• Personal training and development budget available via Learnerbly.

• Wellhub membership, granting access to over 2,000 locations across the UK.

• Cycle to work scheme.

• Season ticket loan available.

• Discounts on Numan products for friends and family.

• Paid volunteering days.

• Additional 2 weeks of leave after 5 years of service with Numan.

People also viewed

Cloudiax14 hours ago

Information Security, Compliance & IKS Manager – ISO 27001

DE flagGermany OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Cisco16 hours ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Cisco1 day ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagArizona, +10 more statesFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Skylight1 day ago

Senior Product Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$200k – $250k/year
ApplyView job
Sony Interactive Entertainment1 day ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads1 day ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers