Senior Security & Compliance Engineer

United States Digital Space LLC

Greater London

Hybrid

GBP 110,000 - 160,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid London office
Private healthcare
25 days annual leave
Company events

Job summary

United States Digital Space LLC is seeking an experienced Senior Security & Compliance Engineer to own security across the company. You’ll lead architecture decisions, strengthen cloud and application security, and drive compliance programs as we scale in the UK, US and Europe.

You’ll work within Engineering, embed shift-left security, and help define a scalable security capability while addressing AI-related risks and enterprise customer needs.

Qualifications

  • Hands-on security across cloud, application and infrastructure.
  • Experience securing Azure and Kubernetes environments.
  • Strong governance, SOC 2 Type II and ISO 27001 familiarity.
  • Experience with CI/CD security tooling and threat modelling.
  • Ability to translate security requirements to engineers.

Responsibilities

  • Take ownership of security architecture across the company’s technology environment.
  • Assess security posture, identify vulnerabilities and create remediation plans.
  • Architect and strengthen security across Azure cloud, Kubernetes, databases and data pipelines.
  • Own IAM, zero-trust, secrets management, RBAC, pod security and encryption.
  • Embed shift-left security into engineering workflows and CI/CD pipelines (SAST/DAST/SCA).
  • Partner with Engineering and Product on secure-by-design decisions.
  • Run threat modelling and support secure coding in Node.js, React Native, C++.
  • Own vulnerability management: triage, remediation tracking, incident response as needed.
  • Improve logging, monitoring and alerting for security threats.
  • Assess AI-related threats and adapt security accordingly.
  • strengthen SOC 2 Type II and ISO 27001 controls; support audits.
  • Support GDPR and data residency across infra and data pipelines.
  • Engage with enterprise customers on security posture when required.
  • Automate controls and tooling to scale security across the business.

Skills

Cloud security
Azure
Kubernetes
IAM
RBAC
SAST
DAST
SCA
CI/CD
Python

Tools

Terraform
Helm
GitOps

Job description

Build the security foundations behind cutting‑edge construction technology

At the company, we’ve created the world’s first engineering‑grade Augmented Reality solution for construction. Our product, The Atom, is used on major projects worldwide to bring designs to life on‑site and help teams build more accurately, efficiently and with fewer mistakes.

As a Series B business scaling across the UK, US and Europe, our technology – and the security environment supporting it – is becoming increasingly sophisticated.

Our stack spans Kubernetes on Azure, mobile and embedded AR, REST APIs, real‑time collaboration and AI‑powered data pipelines. We already hold SOC 2 Type II and ISO 27001, but as our product, customers and use of AI continue to evolve, we now need dedicated security expertise within the business.

We’re looking for an experienced Senior Security & Compliance Engineer to take ownership of security across the company and help build a security capability that can scale with us.

The Role

This is a critical hire and an opportunity to become our first dedicated security specialist, with genuine ownership and influence across the business.

While we already have established compliance activity and SOC 2 Type II and ISO 27001 certifications, security responsibilities currently sit across different teams. We’re now looking for someone who can bring that together, identify where we need to strengthen our approach and provide dedicated technical security leadership as we scale.

This is first and foremost a technical security role. You’ll sit within Engineering and work directly alongside the teams building our technology, participating in architecture discussions, development workflows and technical decision-making rather than operating as a separate security function reviewing work after the fact.

You’ll take ownership of security architecture across our technology stack, embed shift‑left security practices into how we build, strengthen our cloud and application security, and ensure we remain ahead of both established and emerging threats.

As our use of AI continues to develop, you’ll also help us understand and respond to new AI‑related security risks and attack vectors, ensuring our security approach evolves alongside our technology.

Compliance remains an important part of the role. You’ll help strengthen our SOC 2 Type II and ISO 27001 posture and support areas including GDPR, data residency and enterprise customer requirements. However, we’re looking for someone who brings strong hands‑on security expertise first, alongside the governance and compliance knowledge needed to operate effectively across both areas.

You won’t simply inherit a security playbook, you’ll have the opportunity to help build one.

The role is based in London on a hybrid basis, with a minimum of 3 days per week in the office, enabling you to work closely with our Engineering, Product and wider business teams.

What You’ll Be Doing
  • Take ownership of security architecture and technical security across the company’s technology environment.
  • Assess our current security posture, identify vulnerabilities and control gaps, and develop pragmatic remediation plans.
  • Architect and strengthen security across our Azure cloud environment, including Kubernetes clusters, databases and data pipelines.
  • Own and improve areas including IAM, zero‑trust networking, secrets management, RBAC, pod security and encryption.
  • Embed shift‑left security into engineering workflows, integrating SAST, DAST, dependency scanning and SCA into our CI/CD pipelines.
  • Partner directly with Engineering and Product teams on architectural decisions, technical trade‑offs and secure‑by‑design development.
  • Run threat‑modelling exercises and support developers with secure coding practices across Node.js, React Native and C++ environments.
  • Own vulnerability management, including triage, risk prioritisation, remediation tracking and incident response where required.
  • Develop and improve the logging, monitoring and alerting capabilities needed to identify and respond to security threats.
  • Assess emerging threats, including those associated with AI‑enabled products, tooling and new attack methodologies, and ensure our security approach continues to evolve.
  • Strengthen our SOC 2 Type II and ISO 27001 controls, identifying gaps and improving implementation where needed.
  • Support compliance cycles including controls testing, evidence gathering and auditor coordination.
  • Support GDPR and data residency requirements across our infrastructure and data pipelines.
  • Engage with enterprise customers and prospects on the company’s security posture when required.
  • Automate security controls and processes wherever possible rather than relying on manual intervention.
  • Help establish the standards, tooling and operating model for a security capability that can scale with the business.
What We’re Looking For
  • Demonstrable in-depth hands‑on technical security experience, ideally spanning application, cloud and/or infrastructure security.
  • Strong technical security capability and the confidence to own security decisions end‑to‑end rather than operating purely in an advisory or governance capacity.
  • Strong cloud security experience, ideally Azure, although significant AWS or GCP expertise with the ability to transition quickly to Azure would also be considered.
  • Hands‑on experience securing Kubernetes/containerised environments, including IAM, RBAC, network segmentation, secrets management, image scanning and pod security.
  • Experience integrating security tooling into CI/CD environments, including SAST, DAST, SCA and dependency scanning.
  • Experience with infrastructure‑as‑code security and technologies such as Terraform, Helm or GitOps.
  • Understanding of application and API security, including OAuth 2.0, JWT, mTLS and secure development practices.
  • Experience identifying vulnerabilities, assessing technical risk and driving remediation.
  • Comfortable writing automation using Python, Go, Bash or similar to operationalise security controls.
  • Practical experience working with SOC 2 Type II and/ or ISO 27001, including identifying gaps and strengthening controls.
  • Current knowledge of the evolving cybersecurity landscape and an interest in emerging threats, particularly those associated with AI.
  • Strong communication skills and the ability to translate security requirements for both technical and non‑technical stakeholders.
  • A pragmatic, collaborative approach, you understand that great security enables engineering teams rather than creating unnecessary barriers.

Experience building or scaling security capability within a high‑growth or Series A/B technology business would be particularly valuable. You’ll understand the balance between addressing today’s risks and building security foundations capable of supporting where the business is heading next.

Above all, we’re looking for someone who is technically strong, curious and proactive, someone engineers want to work with, who can bring credibility to security conversations while remaining pragmatic about how we build and ship great technology.

What You Could Be Working On

From the outset, you’ll have the opportunity to make an impact across areas including:

  • Azure and Kubernetes security architecture
  • Application and API security
  • Secure software development and shift‑left security
  • Vulnerability management and incident response
  • AI‑related security and emerging threat management
  • SOC 2 Type II and ISO 27001 maturity
  • Security automation and CI/CD integration
  • Enterprise customer security requirements
  • Building the company’s longer‑term security capability and roadmap
Why Join Us

Become our first dedicated security hire and have genuine ownership over how security develops at the company

  • Hybrid working from our London office
  • 25 days annual leave + public holidays
  • Private healthcare with Vitality
  • Additional Christmas shutdown days
  • Biannual salary reviews
  • Summer & Christmas company events
  • Free Thursday lunch and after‑work gatherings
  • Employee referral scheme
  • Cycle to Work scheme
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

XYZ Reality • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid work from London office
Private healthcare
25 days annual leave
+1
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

Jackalope Digital LLC • Greater London

Hybrid
GBP 90,000 - 130,000
Private healthcare
25 days annual leave
Hybrid London office
+3
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

Cybermindspace • Greater London

Hybrid
GBP 90,000 - 130,000
Security Engineering Lead
Security Engineering Lead

United States Digital Space LLC • Greater London

On-site
GBP 120,000 - 150,000
Equity in an early-stage tech company
25 days holiday plus local public hols
Apple hardware
+4
Engineering Manager, Security
Engineering Manager, Security

Insignis Cash • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday
5% Pension contributions
Private medical insurance with Vitaliy
+5
Senior Engineering Manager, Security
Senior Engineering Manager, Security

Insignis • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday (exc. Bank holidays)
5% Pension contributions
Private medical insurance with Vitaliy
+4
Senior Security Operations Engineer New London
Senior Security Operations Engineer New London

Risk Ledger • Greater London

Hybrid
GBP 90,000 - 135,000
EMI equity
Healthcare AXA
Hybrid working policy
+3
Principal Security Architect
Principal Security Architect

Artificial • United Kingdom

On-site
GBP 110,000 - 140,000
Private medical insurance
Income protection
Company stock options
+2
Security Lead - Member of Technical Staff
Security Lead - Member of Technical Staff

United States Digital Space LLC • Greater London

On-site
GBP 120,000 - 180,000
Salary competitiveness
Equity & Ownership
Private healthcare
+1
Lead Security Engineer
Lead Security Engineer

Eeze • Greater London

Hybrid
GBP 80,000 - 100,000
26 days paid holiday
Hybrid Working
Pension and Life Assurance
+2