
Senior Security & Compliance Engineer
XYZ Reality17 days ago
London, United KingdomSenior
Responsibilities
- Own security architecture and technical security across the company’s technology environment.
- Assess security posture, vulnerabilities and control gaps, and develop remediation plans.
- Strengthen Azure cloud, Kubernetes, database and data-pipeline security, including IAM, RBAC, secrets management, pod security and encryption.
- Embed shift-left security practices and integrate SAST, DAST, dependency scanning and SCA into CI/CD pipelines.
- Partner with Engineering and Product on secure architecture, technical trade-offs and secure-by-design development.
- Run threat modeling and support secure coding across Node.js, React Native and C++ environments.
- Own vulnerability management, risk prioritization, remediation tracking and incident response where required.
- Improve security logging, monitoring and alerting, and assess AI-related threats and attack vectors.
- Strengthen SOC 2 Type II and ISO 27001 controls and support controls testing, evidence gathering and auditor coordination.
- Support GDPR, data residency and enterprise customer security requirements.
- Automate security controls and help establish the security function’s standards, tooling and operating model.
Requirements
- Demonstrable in-depth hands-on technical security experience spanning application, cloud and/or infrastructure security.
- Strong technical security capability with the ability to own security decisions end-to-end rather than working purely in an advisory or governance capacity.
- Strong cloud security experience, ideally with Azure; significant AWS or GCP experience with the ability to transition to Azure is also considered.
- Hands-on experience securing Kubernetes or containerized environments, including IAM, RBAC, network segmentation, secrets management, image scanning and pod security.
- Experience integrating SAST, DAST, SCA and dependency-scanning tools into CI/CD environments.
- Experience with infrastructure-as-code security and technologies such as Terraform, Helm or GitOps.
- Understanding of application and API security, including OAuth 2.0, JWT, mTLS and secure development practices.
- Experience identifying vulnerabilities, assessing technical risk and driving remediation.
- Ability to write automation using Python, Go, Bash or similar technologies.
- Practical experience with SOC 2 Type II and/or ISO 27001, including identifying gaps and strengthening controls.
- Current knowledge of cybersecurity and emerging threats, particularly AI-related threats.
- Strong communication skills and the ability to explain security requirements to technical and non-technical stakeholders.
- Experience building or scaling security capability in a high-growth or Series A/B technology business is particularly valuable.
- A technically strong, curious, proactive and pragmatic approach to collaborating with engineering teams.
Benefits
- Hybrid role based in the London office with a minimum of 3 days per week in the office.
- 25 days of annual leave plus public holidays.
- Private healthcare through Vitality.
- Additional Christmas shutdown days.
- Biannual salary reviews.
- Summer and Christmas company events.
- Free Thursday lunch and after-work gatherings.
- Employee referral scheme.
- Cycle to Work scheme.