Product Security Engineering Lead (Shift-Left)
Key Responsibilities
- Define, implement, and validate security controls, architecture patterns, and reference designs across cloud, on-premises, and colocation environments.
- Review infrastructure, platforms, applications, and technical configurations against internal security baselines, industry standards, and relevant regulatory requirements.
- Conduct threat-modelling exercises and technical risk assessments for new and existing products, platforms, and technology initiatives.
- Identify attack paths, design weaknesses, vulnerabilities, and control gaps, and recommend proportionate mitigation strategies.
- Perform secure code reviews and work with engineering teams to address security issues before applications and services are released into production.
- Review technical designs, functional requirements, and solution architectures to identify potential security weaknesses at an early stage.
- Embed security controls, tools, and processes throughout the software development lifecycle.
- Partner with software engineers, product teams, and platform teams to resolve application, cloud, infrastructure, and network security risks.
- Provide expert guidance on secure software development, cloud security, platform security, application security, and network protection.
- Assess security vulnerabilities across AWS services, on-premises systems, data stores, APIs, enterprise applications, and supporting infrastructure.
- Support the integration and improvement of security testing capabilities, including static analysis, dynamic testing, dependency scanning, container scanning, and infrastructure security assessments.
- Track security findings through remediation and provide clear guidance to developers and technical stakeholders.
- Produce security assurance reporting covering risks, control effectiveness, identified gaps, remediation progress, and improvement recommendations.
- Contribute to the development of security tooling, automation, internal frameworks, and engineering-led security capabilities.
- Research emerging attack techniques, vulnerabilities, technologies, and industry developments relevant to the organisation's environment.
- Deliver security education, technical training, and awareness sessions for engineering and wider technology teams.
- Contribute to external security initiatives where appropriate, including technical articles, conference presentations, university engagement, and open-source projects.
- Support the continued development of a strong security culture across the organisation.
Requirements
- Between five and ten years of experience in product security, application security, security architecture, security engineering, or security research.
- Strong understanding of software and product security principles, attack techniques, defensive controls, and secure development practices.
- Proven experience conducting threat modelling, technical risk assessments, and security design reviews.
- Experience developing practical mitigation strategies for complex technical and architectural risks.
- Strong technical foundation in software development, engineering, or computer science.
- Proficiency in one or more programming or scripting languages, together with experience using relevant security tools.
- In-depth knowledge of common vulnerabilities affecting applications, APIs, networks, cloud environments, infrastructure, containers, and platforms.
- Strong experience reviewing technical designs, architecture diagrams, and functional requirements to identify security weaknesses.
- Experience conducting source-code reviews and explaining security vulnerabilities clearly to software engineers.
- Good understanding of cloud security, particularly within AWS environments.
- Familiarity with secure software development lifecycle practices and modern DevSecOps tooling.
- Strong analytical and problem-solving skills, with the ability to investigate complex technical issues.
- Excellent communication skills and the ability to influence stakeholders through clear, evidence-based reasoning.
- Ability to communicate technology risks in terms that are appropriate for both technical and business audiences.
- Strong organisation and time-management skills, with the ability to manage multiple concurrent assessments and remediation activities.
- Ability to track deliverables, manage follow-up actions, and maintain clear ownership of outstanding security issues.
- Previous experience within financial services, trading, fintech, or another highly regulated environment would be advantageous.
FAQs
Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your CV and details on file so when we see similar roles or see skillsets that drive growth in organisations, we will always reach out to discuss opportunities.
Yes. Even if this role isn’t a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.
We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business.Â
That's why we recommend registering your CV so you can be considered for roles that have yet to be created.Â
Yes, we help with CV and interview preparation. From customised support on how to optimise your CV to interview preparation and compensation negotiations, we advocate for you throughout your next career move.