Platform Security Engineer

Xoriant

Greater London

On-site

GBP 70,000 - 100,000

Full time

43 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Xoriant is seeking an experienced security professional to own platform security end-to-end. You will lead SCB initiatives for enterprise DevOps tools and drive remediation across engineering teams while communicating effectively with developers and senior stakeholders.

The role sits within a mature programme, requiring ownership, advocacy for security best practices, and ongoing improvement across engineering teams. Strong governance and regulatory awareness are essential.

Qualifications

  • 3–5 years of experience in DevSecOps, platform security, or information security engineering roles.
  • Experience building SCBs for enterprise DevOps and collaboration tools (Bitbucket, Bamboo, Jenkins, Nexus, Jira, Confluence, SonarQube, Mend, or equivalent).
  • Strong working knowledge of NIST CSF v2.0, OWASP Security Controls, and ISO 27001/27002.
  • Experience conducting configuration assurance reviews, control gap assessments, and risk-based remediation planning.
  • Familiarity with GDPR, NIS2, DORA, or equivalent regulatory frameworks and their impact on platform configuration.
  • Experience writing Incident Response Playbooks or security runbooks aligned to NIST or SANS frameworks.

Responsibilities

  • Proven ability to lead security engagements end-to-end — planning, stakeholder reporting, and delivery ownership.
  • Bridge technical and non-technical audiences, turning complex security requirements into engineering actions.
  • Experience with Agile delivery; proficient in JIRA for backlog and sprint management.
  • Strong documentation skills — produce clear SCB documentation, audit evidence packs, and executive-level reports.

Skills

DevSecOps
Platform security
Information security engineering

Education

ISO 27001 Lead Auditor/Lead Implementer
CIPM (IAPP) or data privacy certifications
Experience in Financial Services or regulated industries

Tools

Bitbucket
Bamboo
Jenkins
Nexus
Jira
Confluence
SonarQube
Mend

Job description

  • 3–5 years of experience in DevSecOps, platform security, or information security engineering roles.
  • Hands-on experience building SCBs for enterprise DevOps and collaboration tools (Bitbucket, Bamboo, Jenkins, Nexus, Jira, Confluence, SonarQube, Mend, or equivalent).
  • Strong working knowledge of NIST CSF v2.0, OWASP Security Controls, and ISO 27001/27002.
  • Experience conducting configuration assurance reviews, control gap assessments, and risk-based remediation planning.
  • Familiarity with GDPR, NIS2, DORA, or equivalent regulatory frameworks and their impact on platform configuration.
  • Experience writing Incident Response Playbooks or security runbooks aligned to NIST or SANS frameworks.
Delivery & Communication
  • Proven ability to lead security engagements end-to-end — planning, stakeholder reporting, and delivery ownership.
  • Able to bridge technical and non-technical audiences, turning complex security requirements into engineering actions.
  • Experience with Agile delivery; proficient in JIRA for backlog and sprint management.
  • Strong documentation skills — able to produce clear SCB documentation, audit evidence packs, and executive-level reports.
Preferred Qualifications (Not Mandatory)
  • ISO 27001 Lead Auditor or Lead Implementer certification.
  • CIPM (IAPP) or other data privacy certifications.
  • Experience in Financial Services or other regulated industries.
What We're Looking For

The ideal candidate takes full ownership of platform security from day one. You have built SCBs before, know how to drive remediation across engineering teams, and can hold your own in conversations with both developers and senior stakeholders. You'll be joining a mature programme and are expected to sustain, challenge, and improve it.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Platform Security Engineer: Lead SCBs & Secure DevOps
Platform Security Engineer: Lead SCBs & Secure DevOps

Xoriant • Greater London

On-site
GBP 70,000 - 100,000
Security Platform Engineering Lead
Security Platform Engineering Lead

CMC Markets • Greater London

On-site
GBP 110,000 - 150,000
Technical Security Consultant
Technical Security Consultant

Barclay Simpson • City Of London

On-site
GBP 75,000 - 110,000
Security Engineer (Site Reliability Engineering)
Security Engineer (Site Reliability Engineering)

Sanderson Government & Defence • Greater London

Hybrid
GBP 101,000 - 109,000
Security Assurance Lead
Security Assurance Lead

Motability Operations Ltd • Greater London

On-site
GBP 70,000 - 100,000
Technical Security Consultant
Technical Security Consultant

Barclay Simpson • Greater London

Hybrid
GBP 80,000 - 110,000
Senior Security Engineer
Senior Security Engineer

Natter • United Kingdom

On-site
GBP 90,000 - 130,000
Platform & Dev Sec Ops Lead
Platform & Dev Sec Ops Lead

Jobtailor • Leatherhead

On-site
GBP 75,000 - 110,000
Security Engineer
Security Engineer

Conduct AI • Greater London

On-site
GBP 70,000 - 110,000
Security Engineer
Security Engineer

Conduct • Greater London

On-site
GBP 70,000 - 110,000