
Principal Security Architect
Artificial Labs Ltd29 days ago
London, United KingdomStaff+
Responsibilities
- Provide practical, hands-on security advice to engineers throughout the development lifecycle.
- Own secure development and secure coding standards and coordinate penetration testing.
- Run threat modelling for high-risk work and establish training so engineering teams can perform it independently.
- Set cloud security standards and guardrails covering configuration, access, identity, encryption, and modern cloud architectures.
- Define vulnerability severity and remediation priorities for engineering teams.
- Design identity and privileged-access management, including strong authentication and controlled access elevation.
- Lead data security practices including classification, customer-data separation, and data-loss-prevention tooling.
- Provide security judgment for assessments of higher-risk suppliers.
- Train and coach engineers and collaborate across engineering, platform, product, and security teams.
Requirements
- Significant experience in a senior or principal security architecture or application security role, ideally in a rapidly growing cloud-based software company.
- Strong hands-on cloud security experience covering secure configuration, identity and access, encryption, guardrails, and cloud or serverless architectures.
- Solid secure software development knowledge, including threat modelling, secure coding, OWASP Top 10 risks, automated security testing, and penetration testing.
- Practical experience with vulnerability management, identity and privileged access, data security, and software supply-chain practices such as SBOMs.
- Pragmatic communication skills and the ability to turn security risks into practical decisions for technical and non-technical colleagues.
- Willingness to explore appropriate uses of AI for building and securing products.
- Experience in InsurTech, FinTech, or another regulated industry is preferred.
- Experience building an early-stage security function, embedding security into modern engineering delivery, or securing shared infrastructure and multi-customer data is preferred.
- Relevant certifications such as CISSP, CCSP, or an AWS security qualification are welcomed but not required.
Benefits
- Private medical, income protection, and life insurance.
- On-site gym and shower facilities, company social events, and parties.
- Enhanced maternity and paternity pay.
- Pension and nursery-fee salary exchange schemes.
- Access to Maji, YuLife employee benefits, an employee assistance program, and bereavement helplines.
- Company stock options managed through Ledgy.
- Milestone birthday bonus and Life Events leave policy.
- 28 days of holiday plus national holidays.
- Home office and equipment allowance and a company MacBook.
- Learning allowance and leave for conferences or exams.
- The company plants a tree through Ecologi Action for each new hire.
- London office amenities including an on-site coffee machine.
- Background checks may include criminal-record, credit-history, employment, and academic-qualification checks.