Product Security Engineer

Redgate Software

Cambridge

Hybrid

GBP 60,000 - 75,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive health coverage
Monthly wellbeing allowance
Generous paid time off
Employee assistance program
Community and social events

Job summary

A software company in Cambridge is looking for a Product Security Engineer to embed security into the software development lifecycle. Responsibilities include auditing code, driving security adoption, and collaborating with engineering teams. The ideal candidate will have strong knowledge of application security, SAST/DAST processes, and experience with cloud environments. A salary range of £60,000 to £75,000 is offered based on experience. Flexible working arrangements are available.

Qualifications

  • Hands-on experience supporting engineering teams in a modern SDLC.
  • Strong knowledge of security mitigation patterns.
  • Comfort with cloud and container security in AWS environments.

Responsibilities

  • Partner with teams to define and operationalise security requirements.
  • Audit application code for vulnerabilities.
  • Drive SAST/DAST adoption and quality.

Skills

Product/application security experience
Knowledge of OWASP Top 10
SAST/DAST process improvement
Cloud and container security fundamentals
C# ecosystem knowledge

Tools

C#/.NET
AWS
Docker
SAST/DAST tools

Job description

Company Overview

Redgate Software creates ingeniously simple software that helps data professionals get the most value out of any database. Our solutions address complex database management challenges across the DevOps lifecycle, making life easier for IT leaders, development, and operations teams by increasing efficiency, reducing errors, and protecting business‑critical data. The data community trusts Redgate to balance speed to market, team collaboration, and data protection.

The Role

As a Product Security Engineer, you will embed security into the software development lifecycle across multiple product teams. You’ll help teams build, ship, and operate secure software by defining requirements, improving detection and prevention (SAST/DAST), assisting teams with application security governance, and running threat modelling.

Your Work at Redgate
  • Partner with engineering and product teams to define and operationalise security requirements across the SDLC (from design to release).
  • Audit application code for weaknesses and vulnerabilities.
  • Own or co‑own application security governance practices: secure‑by‑default standards, patterns, guardrails, and exceptions/risk acceptance.
  • Drive SAST/DAST adoption and quality: tool tuning, triage workflows, severity calibration, and ‘fix-forward’ enablement.
  • Support adoption of threat modelling for new features, architectural changes, and high‑risk services—turning findings into actionable engineering work.
  • Provide product security guidance for cloud‑native environments (AWS + containerised workloads), with an emphasis on secure service design and deployment practices.
  • Build strong relationships with product teams through clear communication, coaching, and security enablement.
  • Review and assist in the development of engineering policies aligned with security best practices.
  • Contribute secure shared libraries/paved‑road components or perform targeted security testing/pentesting to validate controls.
  • Work with product teams to support implementation of AI, including LLMs, SLMs, and MCP.
What you bring to the table
  • Hands‑on product/application security experience supporting engineering teams in a modern SDLC (requirements, design review, secure coding guidance, release support).
  • Strong knowledge of the OWASP Top 10 and practical mitigation patterns; familiarity with OWASP ASVS is a plus.
  • Experience implementing or improving SAST/DAST processes: tool selection/tuning, signal‑to‑noise reduction, and scalable remediation workflows.
  • Working understanding of cloud and container security fundamentals in an environment using AWS and Docker (and related CI/CD practices).
  • Comfort working across a primarily C# ecosystem (with some Java/Python), including the ability to review code and explain security issues clearly to developers.
  • Ability to translate security risk into actionable engineering priorities—balancing risk, delivery timelines, and operational realities.
Who you are
  • You’re pragmatic: you care about real risk reduction, not checkbox compliance or perfect theoretical security.
  • You communicate clearly and respectfully, able to influence without authority and build trust across multiple product teams.
  • You’re structured and evidence‑driven: you document decisions, measure outcomes, and iterate based on what’s working.
  • You’re comfortable in ambiguity and can shape an approach when requirements, tooling, or ownership aren’t fully defined yet.
Salary
  • £60,000 to £75,000 subject to experience
Tech / Tool Stack
  • C# / .NET (primary engineering ecosystem), React
  • Java (J2EE), TypeScript, and Python
  • AWS (cloud infrastructure and services), Docker (containerised workloads)
  • SAST/DAST tooling (specific products may vary; you’ll help tune and operationalise them)
Impact Plan
30 Days
  • Onboard into Redgate’s products, SDLC, and delivery rhythms (how work moves from idea → code → deploy).
  • Get access to core systems and security tooling; understand what’s in place today (SAST/DAST coverage, alert volumes, current processes).
  • Shadow the Product Security Architect and sit in on a handful of ceremonies (planning/refinement/retro) to understand team dynamics and where security naturally fits.
  • Triage a small set of findings with guidance (e.g., top recurring SAST issues), focusing on learning severity expectations and remediation patterns.
  • Start building a knowledge base: common app patterns, approved controls, ‘how we do security here,’ and where to find the right people.
60 Days
  • Begin owning a defined slice of AppSec work with supervision (e.g., one product area or a specific SDLC initiative like SAST tuning or DAST onboarding).
  • Build working relationships with a small set of partner teams and establish a predictable engagement model (intake path, review checklist).
  • Start contributing to security reviews for new features or higher‑risk changes—initially as a second set of eyes, then independently for scoped areas.
  • Help improve signal‑to‑noise in SAST/DAST: tune rules, reduce duplicates, and document triage guidance that developers can follow.
  • Support lightweight threat modelling sessions alongside the Architect (prep, note‑taking, translating outcomes into engineering actions).
90 Days
  • Independently handle routine AppSec support for agreed scope (e.g., first‑pass triage, basic secure design guidance, follow‑ups with teams), escalating appropriately.
  • Deliver tangible process improvements that reduce friction (e.g., clearer severity rubric, a repeatable intake template, a 'common findings' fix guide).
  • Demonstrate steady throughput on findings: consistent triage quality, meaningful developer support, and reduced turnaround time for the scoped area.
  • Contribute to a secure‑by‑default library/SDK.
Why Join Us?

At Redgate, we believe supporting and empowering our people is key to our success. We create an environment where you can thrive in your career and enjoy every moment of your journey with us. Benefits include competitive salary, comprehensive health coverage, monthly wellbeing allowance, flexible working arrangements, generous paid time off, employee assistance program, community and social events. Redgate has adopted a flexible‑hybrid model. This means that people will work flexibly with a blend of remote (home) and co‑located (office) work, with teams having the flexibility to decide which location best suits the outcomes they need to deliver.

Our Diversity, Equity, Inclusion & Belonging Commitments
  • Recruitment & retention: hiring and retaining diverse talent.
  • Authenticity & belonging: promoting inclusive language and behaviours.
  • Growth: supporting personal and professional development.
Equal Opportunity

Redgate is an equal opportunity employer, welcoming applications from all backgrounds. If you need accommodation, please let us know via our application process or email careers@red-gate.com. Learn more about our commitment to diversity on our diversity page. While we outline the qualities we typically seek, we recognise that you may possess additional attributes and skills that could make you an excellent fit for our team. We do not discriminate based on race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Manager (Security Monitoring)
Senior Product Manager (Security Monitoring)

hackajob • Cambridge

On-site
GBP 70,000 - 90,000
Competitive salary
Comprehensive health coverage
Monthly wellbeing allowance
+3
Cyber Security Engineer
Cyber Security Engineer

Redgate Software • Cambridge

Hybrid
GBP 60,000 - 90,000
Hybrid working
Wellbeing allowance
Career development
+2
Cyber Security Engineer
Cyber Security Engineer

RED GATE STORAGE • Cambridge

Hybrid
GBP 60,000 - 70,000
Monthly wellbeing allowance
Generous paid time off
Private health insurance
+1
Software Engineer
Software Engineer

RED GATE STORAGE • Cambridge

Hybrid
GBP 33,000 - 55,000
Hybrid work (Cambridge)
Wellbeing allowance
Paid time off
+2
Software Engineer
Software Engineer

慨正橡扯 • Cambridge

Hybrid
GBP 33,000 - 55,000
Private health insurance
Hybrid work model
Wellbeing allowance
+1
Software Engineer
Software Engineer

Redgate Software • Cambridge

Hybrid
GBP 45,000 - 55,000
Hybrid working
Private health insurance
Monthly wellbeing allowance
+2
Senior Software Engineer
Senior Software Engineer

Redgate Software • Cambridge

On-site
GBP 80,000 - 110,000
Senior Software Engineer
Senior Software Engineer

Redgate Software • Cambridgeshire and Peterborough

Hybrid
GBP 85,000 - 120,000
Hybrid working: home and Cambridge
Monthly wellbeing allowance
Generous paid time off
+1
Senior Software Engineer, Foundry
Senior Software Engineer, Foundry

RED GATE STORAGE • Cambridge

Hybrid
GBP 55,000 - 75,000
Monthly wellbeing allowance
Generous paid time off
Private health insurance
Service Desk Engineer
Service Desk Engineer

Redgate Software • Cambridge

Hybrid
GBP 35,000 - 40,000
Private health insurance
Wellbeing allowance
Generous paid time off