Overview
In this role, you will champion security across the software development lifecycle, embedding secure coding and threat modelling into our practices. You’ll collaborate with engineering to modernise DevSecOps, tackle AI/LLM threat classes, and mentor developers to build resilient systems. You act as a technical security partner, guiding teams and helping them ship secure, reliable software aligned with our mission to protect small businesses. This is an opportunity to shape defensive architecture at scale in a collaborative, forward-looking tech environment.
Pay / Benefits
- hybrid work and flexible workload
- 25 days annual leave (+ option to buy 5)
- familial leave: six months full pay primary caregiver, four weeks full pay secondary caregiver
- two-week sabbatical after 5 years, four weeks after 10 years
- private medical insurance (BUPA) with pre-existing condition coverage
- pension match up to 5% and life assurance up to 4x salary (option to 10x)
Responsibilities
- Provide expert guidance on secure coding, threat modelling, and OWASP Top 10 mitigation
- Promote a security-first mindset and mentor developers
- Integrate security assessments, code reviews, and penetration testing into the SDLC
- Evaluate, implement, and run SAST, DAST, and IAST tooling for vulnerability checks
- Research emerging AI and LLM threat classes to design proactive defenses
- Participate in incident response investigations and deliver security training
Key requirements
- 5+ years in application security
- Hands-on penetration testing and security tooling skills
- Knowledge of web vulnerabilities, secure coding practices, and cloud environments (AWS, Azure, or GCP)
- Familiar with DevSecOps and automated security integration
- Strong communication to explain security concepts to technical and non-technical audiences
- Collaborative, empathetic, and capable of mentoring engineers
- Curious and proactive about evolving threat landscapes, including AI security
- open and clear communicator
- collaborative
- empathetic
- SAST
- DAST
- IAST
…
