Search Remote Jobs

Senior Product Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

🇬🇧 United Kingdom – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 25%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Endure Capital

Endure Capital

1 - 10 employees

Founded 2015

🏥 Healthcare

💼 Consulting

📣 Marketing

Healthcare • Consulting • Marketing

Endure Capital is a healthcare provider that specializes in innovative treatments and personalized care for various health concerns including weight loss, low testosterone, sexual performance enhancement, hair health, and diagnostic services. Their approach includes access to expert clinicians, precise diagnostics through blood tests, and ongoing clinical support, ensuring that treatments are clinically proven and tailored to individual needs. With a focus on user-friendly experience, they also offer free discreet delivery and a comprehensive app for tracking health progress and managing treatments.

📋 Description

• Run STRIDE-based threat modelling sessions with product and engineering teams, considering clinical safety, abuse, and business-logic threats • Own and evolve the Secure by Design process, including self-evaluation screening, secure design review, threat modelling pathways, and automated tooling • Turn threat models into tracked, prioritised controls implemented by engineering teams • Push security decisions upstream so fixes are designed in rather than retrofitted • Assess and secure production AI systems, including LLM features, retrieval pipelines, agentic workflows, tool-calling integrations, MCP, and API surfaces • Build threat models and controls for agent-specific risks such as prompt injection, tool misuse, excessive agency, data exfiltration, unsafe autonomy, and supply-chain risk • Perform automated application and API penetration testing across web, mobile backends, GCP cloud-native services, internal tooling, and AI features • Lead third-party penetration engagements and work with engineering on remediation • Chain findings into realistic attack paths and demonstrate impact • Embed security into pipelines through SAST, SCA, secrets detection, IaC scanning, container security, and dependency hygiene • Work with platform and engineering teams to improve authentication, authorisation, secrets management, tenancy isolation, and logging and detection coverage • Participate in the security community and publish research, write-ups, or blog posts under your own name • Collaborate with Engineering, Product, Clinical, Legal, and executive teams as part of the Cyber Security function

🎯 Requirements

• Substantial hands-on application security experience in a product engineering environment at senior level • Demonstrable threat modelling practice • Practical offensive skills against modern web and API stacks • Appropriate certification or equivalent demonstrable experience, such as OSCP, OSWE, CREST, or Burp Suite Certified Practitioner • Ability to read and reason about code in at least one production language and meaningfully review pull requests • Working knowledge of cloud-native architecture and security models; GCP preferred, with AWS or Azure experience transferable • Experience integrating security tooling into CI/CD • Track record of shipping security improvements through other teams • Experience securing AI or agentic systems in production • Hands-on experience securing Kubernetes environments • Experience managing cloud security posture using CNAPP and CSPM solutions, primarily on GCP • Regulated environment experience, such as healthcare or fintech, is a bonus • Detection engineering or incident response exposure related to application attacks is a bonus • Existing community footprint, such as talks, published research, or maintained projects, is a bonus

🏖️ Benefits

• Share options • 25 days holiday, plus bank holidays, increasing to 30 the longer you stay with Numan • Health insurance with Vitality • Electric car salary sacrifice scheme with Octopus • Enhanced maternity and parental leave • A day off on your Birthday • Nursery benefit provided by YellowNest • Employee assistance programme, including access to therapy, financial planning and discounts • Generous pension, including employee and employer contributions • Flexible working options, including a dog-friendly office in Farringdon • Personal training and development budget via Learnerbly • Wellhub membership, giving access to over 2,000 locations in the UK • Cycle to work scheme • Season ticket loan • Discount on Numan products for friends and family • Paid volunteering days • Additional 2 weeks off after reaching 5 years with Numan

Apply Now

Similar Jobs

🔥 1 hour ago

Immersive Labs

201 - 500

🔒 Cybersecurity

📚 Education

☁️ SaaS

Senior Cyber Security Engineer creating red-team labs, ranges and AI penetration-testing content. Strengthening Immersive Labs’ global cyber resilience platform through realistic attack simulations.

🔥 3 hours ago

Ping Identity

1001 - 5000

💼 Consulting

🏥 Healthcare

📦 Logistics

Cyber Security Manager leading incident response, detection engineering, and security operations. Protecting Ping Identity’s cloud identity platform and enterprise systems.

🇬🇧 United Kingdom – Remote

💰 $35M Series F - Ping Identity on 2014-09

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🔥 7 hours ago

NEC Software Solutions

5001 - 10000

🏥 Healthcare

💼 Consulting

📦 Logistics

Cyber Security Manager securing NEC Software Solutions’ public-service technology. Delivering accreditations, vulnerability remediation, incident response and customer security assurance.

🕒 4 days ago

Wiz

201 - 500

🔒 Cybersecurity

Security Engineer securing Wiz’s cloud and AI security platform. Building cloud-native controls, vulnerability management, and detection capabilities across products and infrastructure.

🕒 4 days ago

Pencil

51 - 200

🤖 Artificial Intelligence

📣 Marketing

🤝 B2B

Security & Trust Specialist securing Pencil’s generative-AI advertising SaaS platform. Managing endpoints, identity, cloud security and compliance evidence while supporting practical IT issues.