Get more replies from employers
Send a job-specific resume in minutes.
XYZ Reality, a leading AR/construction tech company, is seeking a Senior Security & Compliance Engineer in London. Based in London on a hybrid basis, you will own security across the product stack, engage with engineering to embed secure development practices, and lead governance around SOC 2 Type II, ISO 27001 and GDPR.
You'll work closely with AI enablement efforts to address emerging threats, while ensuring scalable security for worldwide deployments.
Build the security foundations behind cutting-edge construction technology
At XYZ Reality, we've created the world's first engineering-grade Augmented Reality solution for construction. Our product, The Atom, is used on major projects worldwide to bring designs to life on-site and help teams build more accurately, efficiently and with fewer mistakes.
As a Series B business scaling across the UK, US and Europe, our technology - and the security environment supporting it - is becoming increasingly sophisticated.
Our stack spans Kubernetes on Azure, mobile and embedded AR, REST APIs, real-time collaboration and AI-powered data pipelines. We already hold SOC 2 Type II and ISO 27001, but as our product, customers and use of AI continue to evolve, we now need dedicated security expertise within the business.
We're looking for an experienced Senior Security & Compliance Engineer to take ownership of security across XYZ Reality and help build a security capability that can scale with us.
This is a critical hire and an opportunity to become our first dedicated security specialist, with genuine ownership and influence across the business.
While we already have established compliance activity and SOC 2 Type II and ISO 27001 certifications, security responsibilities currently sit across different teams. We're now looking for someone who can bring that together, identify where we need to strengthen our approach and provide dedicated technical security leadership as we scale.
This is first and foremost a technical security role. You'll sit within Engineering and work directly alongside the teams building our technology, participating in architecture discussions, development workflows and technical decision-making rather than operating as a separate security function reviewing work after the fact.
You’ll take ownership of security architecture across our technology stack, embed shift-left security practices into how we build, strengthen our cloud and application security, and ensure we remain ahead of both established and emerging threats.
As our use of AI continues to develop, you'll also help us understand and respond to new AI-related security risks and attack vectors, ensuring our security approach evolves alongside our technology.
Compliance remains an important part of the role. You'll help strengthen our SOC 2 Type II and ISO 27001 posture and support areas including GDPR, data residency and enterprise customer requirements. However, we're looking for someone who brings strong hands‑on security expertise first, alongside the governance and compliance knowledge needed to operate effectively across both areas.
You won’t simply inherit a security playbook, you'll have the opportunity to help build one.
The role is based in London on a hybrid basis, with a minimum of