Job Title: Software Engineer - Cyber Security Engineering
Duration: 6 Months
Location: London - Hybrid
Description:
Join a hands-on cyber engineering team strengthening security across product and platform domains. You’ll turn bug-bounty findings into fixes, support incident response, and provide pragmatic guidance on identity and secrets management.
We’re committed to diversity and inclusion in tech, and we actively encourage applications from underrepresented groups.
What You’ll Do
- HackerOne lifecycle: triage, reproduce, assess risk/severity, coordinate remediation, retest, and close out reports with clear write-ups.
- Security incidents: contribute engineering expertise during investigations and recovery; implement short-term mitigations and drive durable fixes.
- Okta & Doppler: advise engineers on integrations, use existing playbooks, identify gaps, and author new ones to standardise patterns.
- Automation: design automations that scale application and cloud security.
- Collaboration: partner with the Director of Cybersecurity on AppSec, DevSecOps, and cloud-security initiatives.
Skills & Experience Required
- Experience with HackerOne or similar bug bounty platforms (triage, PoCs, retesting, communication).
- Strong understanding of web application security (OWASP Top 10 / ASVS, common attack paths, practical mitigations) and threat modelling.
- Ability to build developer-friendly security tooling and automation.
- Familiarity with web security testing (e.g. Burp Suite, safe minimal PoCs).
- Exposure to incident response from an application security standpoint.
- Clear written and verbal communication across technical and non-technical audiences.
Highly Useful
- Good scripting experience (e.g. Python).
- Hands-on use of SAST, SCA, secrets scanning, and DAST tools, especially in CI/CD pipelines.
- Awareness of CI/CD and infrastructure security patterns (GitHub Actions, Terraform, Kubernetes, least-privilege IAM).
- Practical experience with Okta (OIDC/SAML, MFA, policies, workflows) and Doppler (secrets lifecycle, rotation, environments).
- Hands-on Cloud Security (AWS) experience