Product Security Engineer — DevSecOps & Cloud Security

Genomics England

Greater London

Hybrid

GBP 67,000 - 91,000

Full time

46 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Generous Leave
Pension & Financial
Learning & Development
Recognition & Rewards
Health & Wellbeing

Job summary

Genomics England is seeking a Product Security Engineer to join our London office. You will embed security into software delivery, collaborate with engineering teams on architectures, and help shape secure development practices across CI/CD and cloud environments.

You will review designs, run threat modelling, and translate security standards into actionable guidance while advancing a culture of security education.

Qualifications

  • A strong foundation in cyber security engineering, including secure design principles and risk-based decision making.
  • Practical experience embedding security into software development, including supporting shift-left practices across design, development, and delivery.
  • Experience working hands-on with engineering teams, with the ability to understand application architectures, review code or designs, and help troubleshoot security issues.
  • Experience integrating security controls into CI/CD pipelines, including code, dependency, and infrastructure-as-code scanning, with an emphasis on automation and developer experience.
  • Practical familiarity with public cloud environments, particularly AWS, including common security patterns and risks.
  • Experience working alongside Infrastructure-as-Code and delivery pipelines (e.g. Terraform, GitLab CI/CD or equivalent), with the ability to review and influence implementations.
  • Confidence engaging at an engineering level on designs, pipelines and configurations, even where you are not the primary implementer.
  • Solid understanding of vulnerability management, including helping teams interpret findings, prioritise remediation, and manage vulnerabilities as part of business-as-usual delivery.
  • Experience facilitating threat modelling and contributing to design reviews, helping teams identify and address security risks early in the development lifecycle.
  • Ability to translate security standards and policies into clear, actionable engineering guidance, patterns, and reusable approaches.
  • Experience working in modern engineering environments (e.g. cloud platforms, APIs, microservices, or containerised systems).
  • Strong communication and stakeholder-management skills, with the ability to influence teams through collaboration rather than authority.
  • An interest in security education, enablement, and culture, including mentoring engineers and supporting security champions within teams.
  • This role does not require ownership of production platforms or central security tooling but does require the credibility to work closely with engineers and influence how security is implemented.
  • Qualifications are not essential for this role; practical experience working with engineering teams and embedding security into delivery is far more important.
  • However, the following certifications or areas of formal training may be beneficial:
  • Certifications or training in secure software development or application security (e.g. secure coding, secure SDLC, or application security practices).
  • Knowledge of cloud security principles, whether through formal certification or hands‑on experience.
  • Training in threat modelling, secure design, or security architecture.
  • Exposure to DevSecOps practices, including integrating security into CI/CD pipelines.
  • Evidence of ongoing professional development in cyber security or software security, such as learning new tools, techniques, or contributing to security practices within teams.
  • Equivalent real-world experience enabling teams to adopt secure development practices, integrate security into CI/CD pipelines, and manage vulnerabilities effectively is considered equally valuable.

Skills

Secure design
Shift-left security
Collaboration with engineers
CI/CD security automation
Cloud security (AWS)
Infrastructure-as-Code
Vulnerability management
Threat modelling
Security coaching/mentoring

Education

Cyber security certifications
Cloud security knowledge
Threat modelling training

Tools

Terraform
GitLab CI/CD

Job description

Genomics England is seeking a Product Security Engineer to join our London office. You will embed security into software delivery, collaborate with engineering teams on architectures, and help shape secure development practices across CI/CD and cloud environments.

You will review designs, run threat modelling, and translate security standards into actionable guidance while advancing a culture of security education.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer - Build Secure, Cloud-Native Apps
Product Security Engineer - Build Secure, Cloud-Native Apps

Genomics England • Greater London

Hybrid
GBP 71,000 - 87,000
Generous Leave
Pension & Financial
Learning & Development budgets
+1
Product Security Engineer: Secure by Design in CI/CD
Product Security Engineer: Secure by Design in CI/CD

Genomics England • City Of London

On-site
GBP 71,000 - 87,000
30 days holiday
Pension & Life Assurance
Remote work abroad up to 30 days
Product Security Engineer (we have office locations in Cambridge, Leeds & London)
Product Security Engineer (we have office locations in Cambridge, Leeds & London)

Genomics England • City Of London

On-site
GBP 71,000 - 87,000
30 days holiday
Pension & Life Assurance
Remote work abroad up to 30 days
Product Security Engineer (we have office locations in Cambridge, Leeds & London) London
Product Security Engineer (we have office locations in Cambridge, Leeds & London) London

Genomics England • Greater London

Hybrid
GBP 71,000 - 87,000
Generous Leave
Pension & Financial
Learning & Development budgets
+1
Embedded Security Engineer: Build Secure, Scalable Systems
Embedded Security Engineer: Build Secure, Scalable Systems

G-Research • Greater London

On-site
GBP 90,000 - 120,000
Just Eat lunch
Barista bar
35 days leave
+5
Embedded Security Engineer: Production‑Focused Security
Embedded Security Engineer: Production‑Focused Security

G-Research • City of Westminster

On-site
GBP 90,000 - 120,000
Competitive compensation
Lunch via Just Eat for Business
35 days’ annual leave
+5
Product Security Engineer — AI-Driven DevSecOps
Product Security Engineer — AI-Driven DevSecOps

Bloomberg • Greater London

On-site
GBP 90,000 - 120,000
Product Security Engineer — SDLC Security & Cloud
Product Security Engineer — SDLC Security & Cloud

Redgate Software • Cambridge

Hybrid
GBP 60,000 - 75,000
Comprehensive health coverage
Monthly wellbeing allowance
Generous paid time off
+2
Product Security Engineer (we have office locations in Cambridge, Leeds & London)
Product Security Engineer (we have office locations in Cambridge, Leeds & London)

Genomics England • Greater London

Hybrid
GBP 67,000 - 91,000
Generous Leave
Pension & Financial
Learning & Development
+2
Secure by Design Product Security Engineer
Secure by Design Product Security Engineer

Technify Talent Limited • Greater London

On-site
GBP 55,000 - 90,000