Senior Software Cybersecurity Engineer – Edinburgh (Hybrid)
Are you aSenior Cybersecurity Engineer with strong AppSec, DevSecOps, Cloud and Kubernetes experience?
I’m currently working on an exciting opportunity, supporting the Avigilon security team in protecting the software, cloud platforms and intellectual property behind their physical and video security solutions.
This is a hands-on role where you’ll work closely with software engineering teams toidentify vulnerabilities, improve security throughout the SDLC and build secure-by-design solutions.
What you’ll be doing
- Conductthreat modelling, risk assessments and security architecture reviews
- Assess security acrosscloud and Kubernetes/container environments
- EmbedSAST, DAST, SCA, SBOM and secret scanninginto CI/CD pipelines
- Performsecurity code reviewsand provide secure coding guidance
- Define security requirements and support engineering teams with secure-by-design practices
- Drivevulnerability management, particularly across Kubernetes and container images
- Triage and validate vulnerabilities, including developing PoCs where appropriate
- ManageIAM and key management controls
- Support product security incident response, root-cause analysis and remediation
- Develop detection engineering capabilities, IDS/IPS rules and technical runbooks
- Monitor emerging threats and continuously improve security controls
- Work across engineering, security and compliance teams to drive security improvements
You’ll ideally have:
- 7+ years’ experiencein Cybersecurity, Application Security or Security Engineering
- StrongAppSec / DevSecOpsexperience
- Hands-on experience withAWS, Azure or GCP
- StrongKubernetes and Docker/container securityknowledge
- Experience integratingSAST, DAST, SCA and security tooling into CI/CD
- Strong understanding ofthreat modelling, IAM, cryptography and application security
- Experience withGo and/or C# development
- Knowledge ofHTTP, REST, TLS and TCP/IP
- Strong understanding ofOWASP, NIST, ISO 27001 and CIS
- Excellent communication skills with the ability to work closely with developers and technical stakeholders
Desirable
Experience with:
- Vulnerability research / exploit development
- Manual penetration testing
- Cloud, web, embedded or mobile security
- Splunk / OSQuery
- AI/ML security
- Distributed systems
- AWS Security Specialty, OSCP, CISSP, CCSP, CCAK or SANS/GIAC certifications
Why consider it?
You’ll join a global technology organisation developing mission-critical security and video technologies used to help protect people, property and communities worldwide.
You’ll have the opportunity to work at the intersection of:
Application Security | Cloud Security | Kubernetes | DevSecOps | Vulnerability Research | Product Security with strong career development, flexible working and an excellent benefits package.
