Overview
In this role you will advance the secure software delivery lifecycle, embedding security into design, testing, and deployment. You’ll shape policy-as-code, integrate threat detection into CI/CD, and drive remediation across embedded, cloud, and mobile platforms. You’ll work closely with DevOps and development teams to strengthen posture and foster a security‑first culture. This is a remote UK opportunity with meaningful impact across product platforms and security practices.
Pay / Benefits
- 25 days holiday + bank holidays
- Ex-gratia day for Christmas Eve
- Online benefits portal
- ASSA ABLOY Family Brand discount (Yale)
- 3 x Annual salary life cover
- Company Pension scheme 5% match
Responsibilities
- Evolve secure-by-default SDLC and define security testing requirements
- Implement policy-as-code solutions and gate security into CI/CD pipelines
- Attest cyber security posture across embedded devices, cloud infrastructure, and mobile apps
- Implement and maintain Security Posture Management across multiple areas
- Foster a security-first culture within development teams and the SDLC
- Lead remediation efforts for identified risks and vulnerabilities, including patch management
- Collaborate on threat modeling exercises within development and DevOps teams
Key requirements
- Knowledge of cyber security architecture in AWS and/or Azure
- Kubernetes knowledge is a bonus
- Specialist security hardening in embedded Linux, iOS/Android mobile, cloud environments
- Strong software engineering skills (C# and Linux toolchains, Bash, PowerShell)
- Hands-on experience with IaC tools (Terraform, CloudFormation, or Bicep)
- Familiar with OWASP, CVE and related security compliance frameworks
- Collaborative
- Communication
- Problem-solving
- AWS/Azure security architecture
- Kubernetes
- Embedded Linux security
…
