1 month ago
London, United KingdomStaff+
Responsibilities
- Define and evolve secure software development standards, guardrails, and governance practices.
- Partner with engineering and product teams to embed security into development lifecycles and delivery processes.
- Improve visibility and management of vulnerabilities, insecure coding trends, dependency risks, and software security risks.
- Strengthen governance of software supply chains, open-source dependencies, and SBOM practices.
- Support secure CI/CD pipelines through code scanning, secrets detection, and release governance controls.
- Help shape security practices for AI-enabled applications, including prompt injection resilience, agent controls, and data protection.
- Provide reporting, insight, and challenge to ensure software security risks are understood, prioritized, and managed.
- Drive continuous improvement in software security maturity across the organization.
Requirements
- Experience in application security, software security, DevSecOps, software assurance, or technical security governance.
- Strong understanding of Secure SDLC, application security, and modern software development practices.
- Knowledge of CI/CD security, cloud-native environments, and software supply-chain risk.
- Experience working closely with engineering teams to improve security outcomes.
- Strong stakeholder management and communication skills for technical and non-technical audiences.
- Pragmatic ability to balance security, risk, and delivery.
- Experience with AWS, Azure, or Google Cloud is preferred.
- Knowledge of SAST, DAST, SCA, or software security tools is preferred.
- Experience with AI-enabled applications and emerging software security challenges is preferred.
- CISSP, CSSLP, or equivalent security certification is preferred.
Benefits
- Hybrid work arrangement with teams generally in the office around four days per week, with accommodations or flexibility discussable during the interview process.
- Opportunity to influence software security governance at global scale and work on challenging, stimulating projects.
- Collaborative and inclusive culture focused on creativity, learning, belonging, and professional growth.
- Opportunity to work alongside security and engineering professionals across a large global technology and creative ecosystem.
