Senior Security Engineer

🔥 16 hours ago

🇬🇧 United Kingdom – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🇬🇧 UK Skilled Worker Visa Sponsor

infoinfo

👻 Ghost score 11%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of BibliU

BibliU

51 - 200 employees

📚 Education

☁️ SaaS

🤝 B2B

💰 Series B on 2022-09

Education • SaaS • B2B

BibliU is a company that empowers universities and colleges with a digital-first learning enablement platform. It provides solutions that automate learning content workflows, improve student outcomes, and offer digital textbooks, monographs, and courseware more cost-effectively. BibliU’s platform integrates data, automation, and affordability to deliver more engaging and interactive learning experiences. It collaborates with academic libraries to provide students access to a wide range of titles, from difficult-to-get publishers, staying within budget constraints. BibliU is dedicated to reducing student costs, enhancing learning engagement, and promoting equity and inclusion in education through its innovative solutions.

📋 Description

• Own the engineering implementation and continuous improvement of security controls supporting SOC 2 Type II • Work with IT on evidence collection and external audits • Act as the security partner in architecture and design reviews • Set secure-by-default patterns for new services, data flows, and integrations • Design and tune sandboxing and isolation models for AI-assisted and AI-generated code • Own offensive security testing across applications, cloud, and infrastructure • Validate remediation of internal and third-party findings • Maintain and extend GDPR and PCI DSS control posture • Collaborate with Legal, Finance, Engineering, and Platform Engineering on compliance and security controls • Tune security tooling and automation across the SDLC, including SAST, DAST, dependency and container scanning, IaC policy checks, and CI/CD gates • Lead threat modelling for high-risk services and AI features • Improve detection and response through logging coverage, alerting, runbooks, and incident response participation • Support customer and prospect security reviews, questionnaires, and due diligence • Raise the security baseline across engineering through guidance, tooling, and enablement

🎯 Requirements

• 5+ years in a security engineering, application security, or cloud security role, with meaningful time spent hands-on rather than purely advisory • Direct experience operating or contributing to SOC 2 Type II controls in a live environment, sustaining and evidencing controls over time • Practical penetration testing skills: web application, API, and cloud infrastructure testing • Strong cloud security background (AWS): IAM design, network segmentation, encryption, secrets management, and workload isolation • Working knowledge of PCI DSS requirements and how to scope, segment, and evidence a cardholder-data environment • Solid grasp of GDPR as it applies to engineering: lawful basis, data minimisation, retention, subject rights, cross-border transfers, and sub-processor management • Secure architecture and threat modelling experience across distributed, service-based systems • Strong hands-on engineering ability: reading application code, writing scripts and automation, and integrating security checks into CI/CD • Experience securing containerised workloads and infrastructure-as-code (Kubernetes, OpenTofu, or equivalents) • Ability to influence engineers and product teams without authority and make pragmatic risk trade-offs • Clear written communication for control documentation, findings, and customer-facing security responses • Experience securing AI/LLM systems, including prompt injection, tool-use and agent permissions, model and data exfiltration risks, RAG pipeline security, and evaluation of AI-generated code • Good to have: exposure to ISO 27001 or multi-framework compliance programmes • Good to have: offensive security certifications (OSCP, OSWE, GWAPT) or equivalent demonstrable experience • Good to have: detection engineering and SIEM experience • Good to have: familiarity with OWASP Top 10 for LLM Applications, NIST AI RMF, or ISO/IEC 42001 • Good to have: experience in high-growth SaaS handling sensitive personal data at scale • Good to have: EdTech, accessibility, FERPA, or institutional procurement security review experience • Good to have: controlled security experiments, incident simulations, chaos engineering, or similar experience • Good to have: prior involvement in incident response for a real production incident • UK location/work authorization is implied by the stated UK remote location, but no explicit authorization requirement is provided

🏖️ Benefits

• 35 days holiday per year (excluding public holidays!) • Your birthday off • 12 scheduled company wellness Fridays off per year • Enhanced maternity & paternity allowance • Flexible working hours • Work-from-home allowance • Cycle-to-work scheme (UK) • Life Insurance up to 4 x salary • Private health insurance • Annual eye test and up to £100 towards frames for glasses required for DSE work

Apply Now

Similar Jobs

🔥 21 hours ago

Tangible

11 - 50

💼 Consulting

📦 Logistics

📣 Marketing

Information Security Engineer securing Tangible’s private-markets technology for financial institutions. Owning AWS, SOC 2, regulatory compliance, customer reviews, and AI security on a CISO track.

🕒 4 days ago

Immersive Labs

201 - 500

🔒 Cybersecurity

📚 Education

☁️ SaaS

Cloud Security Engineer creating AWS, Azure and GCP security labs for Immersive’s cyber resilience platform. Designing practical, gamified content that teaches professionals to defend cloud environments.

🕒 5 days ago

PAYTER

11 - 50

🍽️ Food & Beverage

🏨 Hospitality

📦 Logistics

SOC Engineer building Payter’s security operations centre for global contactless payment technology. Monitoring cloud threats, leading incident response, and supporting PCI compliance.

🕒 October 1

Wood

10,000+ employees

💼 Consulting

🏗️ Construction

📦 Logistics

Cybersecurity Manager leading security teams, services, risk, suppliers and improvements. Protecting Wood’s global energy and materials consulting, engineering and operations business.

🕒 September 29

Mozilla

501 - 1000

👥 B2C

🔒 Cybersecurity

Senior Security Engineer protecting Mozilla’s open-source internet products through global incident response. Leading incident command, threat hunting, security automation, and 24/7 response workflows.