Senior Engineer, Software Security

Nothing

Greater London

On-site

GBP 90,000 - 130,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Nothing is seeking an experienced security engineer in London to own security across backend services and cloud platforms. You will define secure development standards, integrate SAST/DAST/SBOM into pipelines, and drive vulnerability management with engineering teams.

You’ll design security testing, collaborate with privacy and legal, and lead threat modelling using AI to simulate attacks and build defences. This is a full-time London-based role with office presence.

Qualifications

  • 6+ years in application security, including security architecture you’ve designed for commercial products and services.
  • Deep threat modelling expertise with methodology definition.
  • Hands-on cloud security across AWS, GCP, Azure, with secure backend services at scale.
  • Proficiency with SAST, DAST, SBOM and knowing which findings matter.
  • Experience applying AI or LLMs to security: simulating threats and building countermeasures.
  • Solid cryptography and identity fundamentals (TLS, OAuth 2.0, SSO, token management); production-quality code in at least two languages.
  • Ability to own a domain end-to-end and communicate across engineers and lawyers.

Responsibilities

  • Own security lifecycle and secure architecture for backend services and cloud platforms, from design to live operations.
  • Define secure development standards and wire SAST, DAST and SBOM tooling into how we ship.
  • Own vulnerability management end to end: find issues, triage findings, and drive engineering teams to closure.
  • Design our security testing, from penetration testing to fuzzing, and build tools other engineers can run without you.
  • Ship network and server-side and data protection: API security, WAF, gateways, runtime defences, encryption in transit and at rest.
  • Partner with our mobile, OS and desktop teams on client-side security tactics and strategy.
  • Collaborate with our privacy and legal functions to help us engineer solutions to our global regulatory requirements focusing on emergent technologies such as AI
  • Lead threat modelling across authentication, data protection and input handling. Use AI and LLMs to simulate attacks before they happen, then collaborate with the various teams to build the defences.

Skills

Application security
Threat modelling
Cloud security
Secure SDLC
AI in security
Cryptography & identity
Python
Go
Java
C++

Tools

AWS
GCP
Azure

Job description

About Nothing

Nothing exists to make tech feel exciting again.

About Nothing

Nothing exists to make tech feel exciting again.

We’re building a different kind of technology company, one that puts design, emotion, and human creativity at the heart of everything we do. From the way our products look and feel to how we communicate and show up in culture, we believe technology should make you feel something.

Founded in London in 2020, we’ve grown from idea to global challenger in just a few years. Backed by GV (Google Ventures), EQT Ventures, and C Ventures, and investors like Tony Fadell (iPod), Casey Neistat, and Kevin Lin (Twitch), we’re now sold in 40+ markets with millions of users worldwide.

About The Team

Nothing builds phones, audio products and an operating system used by millions of people. Behind all of it sits Technology & Data in London: the backend services, cloud platforms and data infrastructure that make our products work. That stack runs across multiple cloud platforms such as AWS, GCP, Azure, and various other global hyperscalers. You'll be the engineer who defines how we secure the stack. Standards, tooling, strategies, tactics, architecture: you set them, and the hard part is doing it without slowing anyone down.

What You'll Do
  • Own security lifecycle and secure architecture for Nothing's backend services and cloud platforms, from first design to live operations across all our CI/CD pipelines
  • Define our secure development standards and wire SAST, DAST and SBOM tooling into how we ship.
  • Own vulnerability management end to end: find issues, triage findings, and drive engineering teams to closure.
  • Design our security testing, from penetration testing to fuzzing, and build tools other engineers can run without you.
  • Ship network and server-side and data protection: API security, WAF, gateways, runtime defences, encryption in transit and at rest.
  • Partner with our mobile, OS and desktop teams on client-side security tactics and strategy.
  • Collaborate with our privacy and legal functions to help us engineer solutions to our global regulatory requirements focusing on emergent technologies such as AI
  • Lead threat modelling across authentication, data protection and input handling. Use AI and LLMs to simulate attacks before they happen, then collaborate with the various teams to build the defences.
What We’re Looking For
  • 6+ years in application security, including security architecture you've designed for commercial products and services and have managed the posture of ongoing production.
  • Deep threat modelling expertise. You can define the methodology for a company, not just follow one.
  • Hands-on cloud security across AWS, GCP, Azure, and other global hyperscalers. You've secured backend services at real scale and depth of complexity.
  • Command of the secure SDLC: SAST, DAST, SBOM and the judgement to know which findings matter.
  • Experience applying AI or LLMs to security: simulating threats, probing defences, building countermeasures.
  • Solid cryptography and identity fundamentals, including TLS, OAuth 2.0, SSO and token management. You write production-quality code in at least two of the languages such as Python, Go, Java, and C++, and know when to reach for each.
  • You own a domain end to end, hold a high bar, and cut through ambiguity, whether the person across the table is an engineer or a lawyer.
How We Work

Location: London (Kings Cross & Farringdon offices)

Working Pattern: Full-time in our London office, five days a week. Occasional home working for personal needs is fine, but this isn't a hybrid role.

Commute: We ask that you live within a 60-minute commute of your office.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Data
Head of Data

Nothing • Greater London

On-site
GBP 120,000 - 180,000
Engineering Manager
Engineering Manager

Nothing • Greater London

On-site
GBP 80,000 - 110,000
Growth Lead, Subscription Products
Growth Lead, Subscription Products

Nothing • Greater London

On-site
GBP 90,000 - 130,000
Ecommerce Executive
Ecommerce Executive

Nothing • Greater London

On-site
GBP 26,000 - 32,000
Lead Product Manager, Subscriptions & Revenue
Lead Product Manager, Subscriptions & Revenue

Nothing • Greater London

On-site
GBP 70,000 - 100,000
Growth Lead, Software & Services
Growth Lead, Software & Services

Nothing • Greater London

On-site
GBP 90,000 - 150,000
Product Manager, Subscription Products
Product Manager, Subscription Products

Nothing • Greater London

On-site
GBP 90,000 - 130,000
Platform Security Engineer
Platform Security Engineer

Gear4music Ltd. • Manchester

On-site
GBP 40,000 - 60,000
Personal development plan
Flexible hours
Health Assured Employee Assistance Programme
+2
Infrastructure Security Engineer
Infrastructure Security Engineer

ElevenLabs • United Kingdom

Remote
GBP 90,000 - 130,000
Senior Software Security Developer – Core Platform Services London
Senior Software Security Developer – Core Platform Services London

PhysicsX Ltd • Greater London

On-site
GBP 70,000 - 90,000
Equity options
10% employer pension contribution
Free office lunches
+7