Overview
In this role you will strengthen security across the software development lifecycle for Avigilon’s security platform. You’ll work with cross-functional teams to identify risks, design controls, and ensure compliance in cloud and container environments. You’ll apply both automated and manual testing to validate protections and drive remediation. This is a hybrid role in the UK, offering a chance to influence product security at scale within a global, mission-driven company.
Pay / Benefits
- Competitive salary and bonus schemes
- 25 days holiday entitlement + bank holidays
- Private medical insurance
- Defined contribution pension scheme
- Employee stock purchase plan
- Flexible working options
Responsibilities
- Perform threat modeling, risk assessments, audits, and architecture reviews focusing on cloud and container environments
- Manage Key Management and IAM controls and define security requirements for compliance
- Conduct security code reviews and serve as a technical SME for engineering and compliance teams
- Deploy and manage automated security tools (SCA/SBOM, SAST, DAST, Secret Scanning) within CI/CD pipelines
- Apply manual testing, scripting, and unit test cases to validate controls and recommend tooling improvements
- Lead vulnerability management with emphasis on Kubernetes and container images, triage and prioritize findings, write PoCs
- Communicate security issues to stakeholders and oversee remediation across the SDLC
- Support incident response, including root cause analysis, mitigation strategies, and runbooks; apply detection engineering and maintain IDS/IPS rules
Key requirements
- 7+ years in Security/Application Engineering
- Leadership in process change and mentoring secure-by-design principles
- Strong knowledge of orchestration (AWS, Azure, GCP), Docker, Kubernetes, and container image lifecycles
- Deep understanding of AppSec & DevSecOps: threat modeling (STRIDE, PASTA), IAM, cryptography, web/network protocols, and integrating SCA/SAST/DAST into CI/CD
- Hands-on Software Engineering experience in Go and C#
- Knowledge of NIST, ISO 27001, CIS, and OWASP (ASVS/Testing Guides)
- strong cross-functional communication
- calm under pressure
- experience in high-growth SaaS environments
- threat modeling (STRIDE, PASTA)
- IAM and cryptography
- web/network protocols (HTTP, REST, TLS, TCP/IP)
…
