XYZ Reality

Senior Security & Compliance Engineer

XYZ Reality
Apply
17 days ago
London, United KingdomSenior

Responsibilities

  • Own security architecture and technical security across the company’s technology environment.
  • Assess security posture, vulnerabilities and control gaps, and develop remediation plans.
  • Strengthen Azure cloud, Kubernetes, database and data-pipeline security, including IAM, RBAC, secrets management, pod security and encryption.
  • Embed shift-left security practices and integrate SAST, DAST, dependency scanning and SCA into CI/CD pipelines.
  • Partner with Engineering and Product on secure architecture, technical trade-offs and secure-by-design development.
  • Run threat modeling and support secure coding across Node.js, React Native and C++ environments.
  • Own vulnerability management, risk prioritization, remediation tracking and incident response where required.
  • Improve security logging, monitoring and alerting, and assess AI-related threats and attack vectors.
  • Strengthen SOC 2 Type II and ISO 27001 controls and support controls testing, evidence gathering and auditor coordination.
  • Support GDPR, data residency and enterprise customer security requirements.
  • Automate security controls and help establish the security function’s standards, tooling and operating model.

Requirements

  • Demonstrable in-depth hands-on technical security experience spanning application, cloud and/or infrastructure security.
  • Strong technical security capability with the ability to own security decisions end-to-end rather than working purely in an advisory or governance capacity.
  • Strong cloud security experience, ideally with Azure; significant AWS or GCP experience with the ability to transition to Azure is also considered.
  • Hands-on experience securing Kubernetes or containerized environments, including IAM, RBAC, network segmentation, secrets management, image scanning and pod security.
  • Experience integrating SAST, DAST, SCA and dependency-scanning tools into CI/CD environments.
  • Experience with infrastructure-as-code security and technologies such as Terraform, Helm or GitOps.
  • Understanding of application and API security, including OAuth 2.0, JWT, mTLS and secure development practices.
  • Experience identifying vulnerabilities, assessing technical risk and driving remediation.
  • Ability to write automation using Python, Go, Bash or similar technologies.
  • Practical experience with SOC 2 Type II and/or ISO 27001, including identifying gaps and strengthening controls.
  • Current knowledge of cybersecurity and emerging threats, particularly AI-related threats.
  • Strong communication skills and the ability to explain security requirements to technical and non-technical stakeholders.
  • Experience building or scaling security capability in a high-growth or Series A/B technology business is particularly valuable.
  • A technically strong, curious, proactive and pragmatic approach to collaborating with engineering teams.

Benefits

  • Hybrid role based in the London office with a minimum of 3 days per week in the office.
  • 25 days of annual leave plus public holidays.
  • Private healthcare through Vitality.
  • Additional Christmas shutdown days.
  • Biannual salary reviews.
  • Summer and Christmas company events.
  • Free Thursday lunch and after-work gatherings.
  • Employee referral scheme.
  • Cycle to Work scheme.
XYZ Reality

About XYZ Reality

201-500 employees
Contact me