Principal Security Engineer

Travelport

Langley

On-site

GBP 110,000 - 140,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Travelport is seeking a Principal Security Engineer in the UK with hybrid Langley work pattern to lead deep technical security across applications, cloud, and infrastructure. You will partner with engineering and architecture teams to translate security strategy into scalable solutions and advise on risk and governance throughout the lifecycle.

The role focuses on IAM, PCI-DSS, cloud security, and secure SDLC practices, enabling secure design reviews and complex security initiatives across

Qualifications

  • 10+ years in cybersecurity/security engineering roles.
  • Experience with PCI-DSS and cloud security.
  • Strong collaboration with engineering teams and security architecture.

Responsibilities

  • Serve as a senior technical security expert across application, network, cloud, and infrastructure security.
  • Partner with engineering and architecture teams to develop secure environments.
  • Translate security principles into practical implementations.
  • Lead architecture reviews for new apps and platforms.
  • Identify security risks and develop pragmatic solutions with engineering teams.
  • Apply security best practices to web apps, APIs, microservices, and cloud-native apps.
  • Perform threat modeling and security design assessments for critical systems.
  • Escalate complex security engineering issues when needed.
  • Provide deep expertise in IAM technologies and platforms.
  • Review cloud environments for adherence to security standards.

Skills

Security engineering
Cybersecurity
IAM
PCI-DSS
AWS security
Threat modeling
CI/CD / DevSecOps
Networking
Okta
Auth0

Education

Bachelor's degree in Computer Science or related field

Tools

Akamai WAF
Okta
Auth0
AWS IAM
VPC security

Job description

Job Description

PRINCIPAL SECURITY ENGINEER | UK | LANGLEY HYBRID

Travel obsessed? Big tech fan? Hey, you're in good company. If you want to be part of the industry that makes the world go round, then look no further.

Travelport is the brains behind lots of your travel bookings- plane, car or hotel. Our technology is used to book that magical holiday, infamous bachelorette party or long overdue school reunion. While we can't solve mosquito bites or lost luggage, we can simplify a lot of the technical parts of travel, and we're looking for the best thinkers to help us do it.

We're hiring right now for a Senior Cloud Engineer!

How you'll make an impact:

The Principal Security Engineer is a senior individual contributor responsible for providing deep technical security expertise across the organization's applications, infrastructure, networks, cloud environments, and security platforms.

Working closely with the Engineering and Architecture teams, this role helps translate security strategy, architectural principles, and regulatory requirements into practical, scalable technical solutions. The Principal Security Engineer will serve as a trusted technical advisor to engineering, infrastructure, cloud, network, architecture, and product teams, helping ensure security is incorporated throughout the design and implementation lifecycle.

Your role in action:
  • Serve as a senior technical security expert across application, network, cloud, and infrastructure security.
  • Partner closely with the engineering and architecture teams to develop, evaluate, and implement secure technology environments.
  • Translate security approach principles, standards, and reference patterns into practical technical implementations.
  • Participate in architecture and design reviews for new applications, platforms, infrastructure, and significant technology changes.
  • Identify security risks within proposed architectures and work collaboratively with engineering and architecture teams to develop pragmatic solutions.
  • Apply security best practices to common application architectures, including web applications, APIs, microservices, distributed systems, and cloud-native applications.
  • Perform technical threat modeling and security design assessments for critical applications and infrastructure.
  • Act as an escalation point for complex security engineering and architecture issues.
  • Provide deep technical expertise in Identity and Access Management (IAM) technologies and platforms.
  • Review cloud environments and application architectures for adherence to security standards and best practices
PCI DSS, Compliance & Risk
  • Provide technical security expertise in support of PCI-DSS and other security compliance programs.
  • Interpret PCI-DSS requirements and translate them into practical technical controls and implementation guidance.
  • Design and validate network segmentation and scope-reduction strategies for PCI environments.
  • Work with Engineering, Architecture, Governance, Risk and Compliance teams to ensure security controls satisfy technical and regulatory requirements.
  • Support security assessments, technical evidence gathering, remediation activities, segmentation validation, and discussions with internal and external assessors.
  • Help evaluate compensating controls and alternative technical approaches when standard implementation patterns are not practical.
Technical Leadership
  • Serve as a recognized technical authority and trusted advisor on cybersecurity engineering matters.
  • Mentor security engineers and other technical professionals and help develop security expertise across engineering teams.
  • Lead complex cross-functional security initiatives involving engineering, architecture, applications, infrastructure, networking, cloud, and security teams.

Communicate complex security issues clearly to engineers, architects, technology leaders, risk teams, and other stakeholders

Could this be you?
  • 10+ years of progressive experience in cybersecurity, security engineering, network security, infrastructure security, application security, or related technical disciplines.
  • Demonstrated experience operating as a senior or principal-level individual contributor responsible for solving complex, cross-domain security problems.
  • Deep knowledge of networking and network security, including segmentation, routing, firewalls, proxies, DNS, load balancing, TLS, and secure network architecture.
  • Demonstrated experience designing network segmentation strategies for security and regulatory scope reduction, particularly within PCI DSS environments.
  • Strong experience with Identity and Access Management, including OAuth 2.0, OIDC, SAML, federation, SSO, authentication, and authorization.
  • Hands-on experience with Okta and/or Auth0, including application integrations, authentication flows, federation, authorization, and troubleshooting complex identity implementations.
  • Experience designing secure identity solutions for workforce IAM, customer identity (CIAM), APIs, and service-to-service authentication.
  • Hands-on experience with enterprise security technologies, particularly Akamai Web Application Firewall (WAF) or comparable application and edge security platforms.
  • Strong knowledge of PCI-DSS, including experience supporting compliance assessments, remediation, technical controls, and scope-reduction strategies.
  • Strong knowledge of AWS security, including IAM, VPC and network security, encryption, logging, monitoring, and workload security.
  • Experience applying security best practices to web applications, APIs, microservices, distributed systems, and cloud-native architectures.
  • Strong understanding of CI/CD principles, DevSecOps, secure SDLC practices, Infrastructure as Code, and automated security testing.
  • Knowledge of common application and API security vulnerabilities and mitigation techniques.
  • Experience conducting security design reviews, technical risk assessments, and threat modeling.
  • Experience collaborating with engineering and architecture teams to develop and implement secure solutions.
  • Ability to troubleshoot complex technical security issues spanning applications, identity, networking, cloud infrastructure, and security platforms.
  • Strong written and verbal communication skills with the ability to explain complex security topics to both highly technical and non-technical audiences.
Preferred Qualifications
  • Experience working in large-scale, highly distributed, global, or regulated technology environments.
  • Advanced experience with Okta and Auth0 administration, configuration, integration, and security architecture.
  • Experience securing payment platforms, e-commerce environments, APIs, or other high-volume transactional systems.
  • Experience with Zero Trust architecture and identity-centric security models.
  • Experience with container and Kubernetes security.
  • Experience with Infrastructure as Code technologies and automated cloud security.
  • Familiarity with security frameworks such as NIST CSF, NIST 800-53, ISO 27001, SOC 2, or CIS Controls.
  • Experience with threat modeling and architecture risk assessment methodologies.
  • Relevant certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or equivalent credentials.

We are an equal opportunities employer and will consider all qualified applicants purely on their skills and abilities. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform crucial job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation, if needed.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer
Principal Security Engineer

Growtoday AB • Greater London

Hybrid
GBP 140,000 - 300,000
Healthcare
Life insurance
Retirement plan
+3
Principal Information Security Engineer
Principal Information Security Engineer

AJ Bell Management Limited • United Kingdom

On-site
GBP 70,000 - 90,000
26 days holiday, increasing with service
7% Pension with matched contributions
Discretionary bonus scheme
+2
Senior Security Architect - Cloud & IAM
Senior Security Architect - Cloud & IAM

Travelport • Langley

Hybrid
GBP 110,000 - 140,000
Hybrid work model
Cloud Security
Cloud Security

PA Consulting • City of Westminster

Hybrid
GBP 60,000 - 85,000
Health and lifestyle perks
25 days annual leave
Generous pension scheme
+2
Principal Security Engineer, SDO AppSec EMEA
Principal Security Engineer, SDO AppSec EMEA

Amazon • Greater London

On-site
GBP 120,000 - 180,000
Lead Security Engineer
Lead Security Engineer

Winston Fox • Greater London

On-site
GBP 70,000 - 95,000
Security Engineering Lead
Security Engineering Lead

THG Ingenuity • Manchester

On-site
GBP 75,000 - 95,000
Application Security Specialist
Application Security Specialist

Experis IT • Greater London

Hybrid
GBP 90,000 - 120,000
Hybrid working
Competitive salary
Annual bonus
+2
Senior Technical Security Consultant
Senior Technical Security Consultant

Accenture • Greater London

Hybrid
GBP 50,000 - 75,000
30 days vacation per year
Private medical insurance
3 extra days of leave for charitable工作
Senior Information Security Engineer
Senior Information Security Engineer

Selby Jennings • Greater London

On-site
GBP 80,000 - 120,000