
Senior Security Engineer
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in United Kingdom.
• Take ownership of the engineering implementation and ongoing enhancement of security controls that support SOC 2 Type II.
• Collaborate with the IT department on evidence gathering and external audits.
• Serve as the security partner during architecture and design evaluations.
• Establish secure-by-default patterns for new services, data flows, and integrations.
• Design and refine sandboxing and isolation models for AI-assisted and AI-generated code.
• Lead offensive security testing across applications, cloud environments, and infrastructure.
• Validate the remediation of both internal and third-party findings.
• Maintain and enhance the control posture for GDPR and PCI DSS.
• Work closely with Legal, Finance, Engineering, and Platform Engineering to ensure compliance and implement security controls.
• Optimize security tools and automation throughout the software development lifecycle (SDLC), including SAST, DAST, dependency and container scanning, IaC policy checks, and CI/CD gates.
• Direct threat modeling for high-risk services and AI features.
• Enhance detection and response capabilities through improved logging coverage, alerting, runbooks, and active participation in incident response.
• Assist in customer and prospect security reviews, questionnaires, and due diligence processes.
• Elevate the security baseline across engineering through guidance, tools, and enablement initiatives.
• Over 5 years of experience in security engineering, application security, or cloud security roles, with significant hands-on involvement rather than solely advisory duties.
• Direct experience in operating or contributing to SOC 2 Type II controls within a live environment, ensuring ongoing sustainability and evidence of controls.
• Practical skills in penetration testing: web application, API, and cloud infrastructure testing.
• Strong background in cloud security (AWS): IAM design, network segmentation, encryption, secrets management, and workload isolation.
• Familiarity with PCI DSS requirements and the ability to scope, segment, and evidence a cardholder-data environment.
• Solid understanding of GDPR as it pertains to engineering: lawful basis, data minimization, retention, subject rights, cross-border transfers, and sub-processor management.
• Experience in secure architecture and threat modeling across distributed, service-based systems.
• Strong hands-on engineering skills: ability to read application code, write scripts and automation, and integrate security checks into CI/CD processes.
• Experience in securing containerized workloads and infrastructure-as-code (Kubernetes, OpenTofu, or equivalents).
• Capability to influence engineers and product teams without direct authority and make practical risk trade-offs.
• Excellent written communication skills for control documentation, findings, and customer-facing security responses.
• Experience in securing AI/LLM systems, addressing prompt injection, tool-use and agent permissions, model and data exfiltration risks, RAG pipeline security, and evaluation of AI-generated code.
• Good to have: exposure to ISO 27001 or multi-framework compliance programs.
• Good to have: offensive security certifications (OSCP, OSWE, GWAPT) or equivalent demonstrable experience.
• Good to have: experience in detection engineering and SIEM.
• Good to have: familiarity with OWASP Top 10 for LLM Applications, NIST AI RMF, or ISO/IEC 42001.
• Good to have: experience in high-growth SaaS environments handling sensitive personal data at scale.
• Good to have: EdTech, accessibility, FERPA, or institutional procurement security review experience.
• Good to have: experience in controlled security experiments, incident simulations, chaos engineering, or similar activities.
• Good to have: previous involvement in incident response for actual production incidents.
• UK location/work authorization is assumed based on the specified UK remote location, although no explicit authorization requirement is detailed.
• 35 days of holiday per year (excluding public holidays!).
• A day off for your birthday.
• 12 scheduled company wellness Fridays off each year.
• Enhanced maternity and paternity leave allowances.
• Flexible working hours.
• Work-from-home allowance.
• Cycle-to-work scheme (UK).
• Life Insurance coverage up to 4 times your salary.
• Private health insurance.
• Annual eye test and up to £100 towards frames for glasses needed for DSE work.
Cummins Inc.
Tangible
GitLab
Tevora
Get handpicked remote jobs straight to your inbox weekly.