Product Security Engineer

One Big Circle Ltd

West of England

On-site

GBP 70,000 - 110,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Work related training courses
Complimentary snacks and refreshments
Bike to Work Scheme
Secure bike storage and shower

Job summary

One Big Circle Ltd is seeking a senior security engineer to own the end-to-end security of AIVR. You will think like an attacker, identify weaknesses, coordinate remediation with engineering and verify fixes across devices, cloud, web apps, and ML infrastructure.

You’ll drive threat modelling, pentesting and secure coding practices, shaping security architecture and incident response within a fast-growing Bristol tech team.

Qualifications

  • Proven ability to model threats and reason about attacker techniques.
  • Experience performing penetration tests and validating fixes.
  • Ability to review code and configurations for security issues.
  • Strong written and verbal communication of findings.

Responsibilities

  • Continuously red team our product stack: threat modelling, pentesting, code and config reviews.
  • Explain findings and validate fixes with engineers.
  • Contribute to AWS security architecture: IAM, networking, encryption, logging.
  • Evaluate device security including secure boot and remote access governance.
  • Harden the software supply chain: SBOMs, CI/CD integrity, CVE handling.
  • Build secure shipping practices: static/dynamic analysis, IaC checks.
  • Improve detection/response: logging, alerting, incident involvement.
  • Scope and triage third party pen tests and vulnerability reports.
  • Document findings clearly for engineers and ISO 27001 evidence.
  • Mentor the team and promote secure design culture.

Skills

Threat modelling
Penetration testing
Secure coding
Security architecture
Incident response
Threat hunting
Technical writing

Tools

AWS
Yocto
CI/CD security
Container security

Job description

Full-Time 37.5 hours, over 5 days (minimum 4 days per week in the office)
About One Big Circle

Be part of an award-winning workplace: The Sunday Times Best Medium-sized Technology Company 2025

Formed in 2017, One Big Circle is a fast-growing Bristol technology company that provides “Intelligent Video” solutions. We focus entirely on solving real-world industry problems by fusing new technology in the field of Video, IOT, Cloud and AI providing end to end solutions which allow our customers to dramatically improve their operational efficiency and safety. Our culture is one of high-quality technical delivery and we work at a speed that many industries are unaccustomed to; we have done this by building a team dynamic that challenges and empowers our people and creating an environment where everyone contributes and learns. We are growing, profitable and have ambitious plans to continue expansion in and beyond our existing markets.

We are looking for a proactive and motivated individual to join our team to support the business in further growing our flagship award-winning product: AIVR. AIVR (Automated Intelligent Video Review) is a state-of-the-art video technology system used by thousands of people in the rail industry. AIVR has won dozens of awards and is recognised as the market leading solution, but we are building many more opportunities both in existing and new markets which will further accelerate our growth.

We have built a culture where people feel supported, included, and empowered to do their best work. Our team is growing, and we’d love for you to be part of the journey.

Role Summary

We are looking for a senior, hands‑on security engineer to own the security of our AIVR product stack end to end. You will spend your time thinking like an attacker, finding weaknesses in our systems before anyone else does, and then coordinating with the engineering teams to remediate.

You will pull the architecture apart, work out the realistic attack paths, test them, prove what's exploitable, explain the impact to the engineers who own them, help them work out a sensible fix, and then verify the fix.

This is a technical role in a team that likes getting things done. It is not a compliance or GRC position.

Your job is to make the product secure by continuously scouting for vulnerabilities and red teaming the AIVR product.

What You’ll Be Securing
  • Edge devices on trains. Embedded Linux devices with cameras and other sensors, fitted to in- service rolling stock. They are remote, physically outside our control, and connect back to us over 4G/5G.
  • AWS cloud platform. A comprehensive and complex data processing platform, including serverless and containerised services developed predominantly in Python and hosting 7+ PB of Data.
  • Web applications. The AIVR web applications used across the rail industry, with multi-tenant workspaces, sharing tools and integrations.
  • Machine learning infrastructure. Training and inference workloads running in a 3rd party datacentre.
Responsibilities
  • Continuously red team our product stack: threat modelling, penetration testing, code and configuration review, and adversarial thinking applied across devices, cloud, applications and ML infrastructure.
  • Highlight findings and their impact. Work with the team that owns the system to explain findings and validate fixes.
  • Input into AWS security architecture with the Platform team: IAM, organisation and account structure, networking, encryption, logging and detection.
  • Evaluate device‑side security with the Device team: secure boot and update signing, credential and certificate lifecycle, remote access, tamper and theft scenarios.
  • Harden the software supply chain: dependency and container vulnerability management, SBOMs, CI/CD pipeline integrity, and CVE exposure.
  • Build security into the way we ship: static and dynamic analysis, IaC and container scanning, secrets detection, and secure coding guidance that engineers will actually use.
  • Improve detection and response: make sure the right things are logged and alerted on and contribute hands‑on when there is an incident. Incident response here is an all‑hands affair; depending on the incident you may lead it or support whoever does.
  • Scope, run and challenge third party penetration tests, and triage reports that arrive through our vulnerability disclosure policy.
  • Document what you find and what you change in clear technical writing that engineers can act on and that feeds naturally into our ISO 27001 evidence and customer security assurance, without you having to run that process.
  • Raise the bar across the team through code review, threat modelling sessions and mentoring, so that security knowledge spreads rather than bottlenecking on you.
Capability Areas

These describe the kinds of problems you will work on.

AWS IAM design and review, permissions, SSO, credentials, secrets management, account segmentation, VPC and network controls, S3 data protection at scale, WAF, container and serverless security, infrastructure as code, CI/CD security, ransomware resilience and recovery testing.

Edge Device & Embedded Security

Embedded Linux hardening (Yocto or similar), secure boot, over‑the‑air updates, disk encryption, device identity and PKI, certificate lifecycle, VPN and remote access design, cellular connectivity, edge API security, physical attack and tamper scenarios, firmware analysis, OT security principles, secure device provisioning and decommissioning.

Application Security

Supply Chain & ML Infrastructure

Dependency and container vulnerability management, SBOM generation and tracking, CVE triage and prioritisation, artifact signing and provenance, pipeline integrity, datacentre network segmentation, ML framework exposure, data flows between datacentre and cloud.

Detection & Response

Logging strategy, alerting and SIEM concepts, threat hunting, incident response, forensics fundamentals, tabletop exercises, backup and recovery testing.

Nice to Have
  • Certifications such as OSCP, OSWE, CRTO or AWS Certified Security Specialty are welcome, but we care far more about demonstrable work than certifications.
  • Experience in rail, transport, utilities or other national infrastructure, and familiarity with the NCSC Cyber Assessment Framework, NIS regulations, ISO 27001 or IEC 62443.
  • Public evidence of your craft: CVEs, write‑ups, open source tooling, bug bounty history or conference talks.
Personal Attributes
  • Curious and persistent: you enjoy working out how something can be made to misbehave.
  • Practical and delivery‑focused, balancing security rigour with the reality of a relatively small team shipping frequent product updates.
  • Direct and constructive: you can tell an engineer their design is broken in a way that makes them want to fix it with you.
  • Self‑motivated, comfortable owning an area without close supervision, and happy to flex across responsibilities in a growing company.
  • Strong written communication, able to produce findings and documentation that stand on their own.
Company Benefits Include:
  • Work related training courses as required
  • Complimentary snacks and refreshments including fresh fruit
  • Access to Bike to Work Scheme
  • Secure bike storage and shower facilities

Successful applicants will be required to pass a BPSS (Baseline Personnel Security Standard) check.

Find out more about us at www.onebigcircle.co.uk

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

One Big Circle • West of England

Hybrid
GBP 60,000 - 80,000
Life Assurance
Pension Scheme
Training courses
+4
Software Engineer (Mid and Senior Levels)
Software Engineer (Mid and Senior Levels)

One Big Circle Ltd • Bradley Stoke

On-site
GBP 36,000 - 70,000
Auto enrolment Pension Scheme
25 Days Holiday
Life Assurance
+6
Software Engineer (Mid and Senior Levels)
Software Engineer (Mid and Senior Levels)

One Big Circle Ltd • Newport

On-site
GBP 36,000 - 70,000
Pension
25 days holiday
Life Insurance
+6
Junior Platform Software Developer
Junior Platform Software Developer

One Big Circle Ltd • West of England

On-site
GBP 25,000 - 32,000
Training courses
Snacks and refreshments
Bike to Work Scheme
+1
Software Engineer (Mid and Senior Levels)
Software Engineer (Mid and Senior Levels)

One Big Circle Ltd • Bath

On-site
GBP 36,000 - 70,000
Auto enrolment Pension Scheme
25 Days Holiday plus bank holidays
Life Assurance
+4
Product Operations Assistant- Rail
Product Operations Assistant- Rail

One Big Circle Ltd • Bristol

On-site
GBP 28,000 - 42,000
Work-related training courses
Complimentary snacks and refreshments
Access to Bike to Work Scheme
+1
Junior Device Software Developer
Junior Device Software Developer

One Big Circle Ltd • West of England

Hybrid
GBP 25,000 - 35,000
Life Assurance
Share Options
Work related training courses
+5
Software Engineer (Mid and Senior Levels)
Software Engineer (Mid and Senior Levels)

One Big Circle Ltd • West of England

On-site
GBP 45,000 - 65,000
Work related training courses
Complimentary snacks and refreshments
Bike to Work Scheme
+1
Junior Device Software Developer
Junior Device Software Developer

One Big Circle Ltd • Bradley Stoke

On-site
GBP 27,000 - 30,000
Pension scheme
25 days holiday
Life Assurance
+8
Junior Device Software Developer
Junior Device Software Developer

One Big Circle Ltd • Newport

Hybrid
GBP 27,000 - 30,000
Pension
Private Healthcare
Life Assurance
+4