Senior Product Security Engineer

London
2 months ago
Applications closed

Related Jobs

View all jobs

Senior Software Engineer

Senior Software Engineer

Senior Software Engineer

Senior Security Consultant

Senior Security Consultant

Senior Security Consultant

Senior Product Security Engineer** (Contract)

Duration: 8 Months (Possibility for extension)

Location: London/Hybrid (2 days per week on site)

Rate: A highly competitive Umbrella Day Rate is available for suitable candidates

Role Overview

As a Senior Product Security Engineer, you will be an essential partner in embedding security practices throughout the entire product lifecycle-from design and development to deployment and maintenance. Your collaboration with engineering, product management, and compliance teams will ensure our products are not only secure by design but also resilient in production environments.

Key Responsibilities:

Security Policy Development: Define and implement robust security policies and tooling across the product lifecycle, ensuring security is integrated from the ground up.
Threat Modeling Leadership: Lead threat modeling sessions for both new and existing applications, guiding teams to ensure documented and actionable outputs.
Vulnerability Management: Oversee the product vulnerability backlog by prioritizing the remediation of high and critical vulnerabilities, and track key metrics such as open vulnerabilities and SLA compliance.
Bug Bounty Coordination: Manage findings from bug bounty programs and ensure timely remediation of identified issues.
Root Cause Analysis: Conduct thorough root cause analysis for security incidents and systemic vulnerabilities, leveraging insights to drive developer training and systemic improvements.
Incident Response Management: Act as Investigation Lead or Incident Commander during incident response efforts, including facilitating tabletop exercises to enhance our incident readiness.

Skills & Experience:

Expertise: Deep knowledge in vulnerability management, threat modeling, security architecture, and secure software development lifecycle (SDLC) practices.
Incident Response Skills: Strong background in incident response, root cause analysis, and managing bug bounty programs.
Communication Ability: Excellent communication and stakeholder management skills, with proven experience in driving cross-functional initiatives.
Risk Management Experience: Familiarity with third-party risk management, security assessments, and regulatory compliance.
Technical Proficiency: Experience working with CI/CD teams to implement security technologies in the pipeline, including SAST, DAST, and SCA tools.
Collaborative Spirit: A track record of partnering with cross-functional teams to deliver impactful security initiatives.

Candidates will need to show evidence of the above in their CV in order to be considered.

If you feel you have the skills and experience and want to hear more about this role 'apply now' to declare your interest in this opportunity with our client. Your application will be observed by our dedicated team.

We will respond to all successful applicants ASAP however, please be advised that we will always look to contact you further from this time should we need further applicants or if other opportunities arise relevant to your skillset.

Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyone's chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities, and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive.

As part of our standard hiring process to manage risk, please note background screening checks will be conducted on all hires before commencing employment.

We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cloud Computing Jobs in the UK (2026 Guide)

Advertising cloud computing jobs in the UK requires a different approach to most technical hiring. The candidate pool is large relative to other deep tech disciplines but highly segmented — cloud architects, DevOps engineers, platform engineers, FinOps specialists and cloud security professionals each occupy distinct communities with different job search behaviours, certification profiles and salary expectations. General job boards reach a broad audience but struggle to differentiate between these disciplines, producing high application volumes but low candidate quality for specialist cloud roles. This guide, published by CloudComputingJobs.co.uk, covers where to advertise cloud computing roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

New Cloud Computing Employers to Watch in 2026: UK and Global Companies Powering the Digital Economy

Cloud computing is no longer just a backbone technology—it is now the engine of digital transformation, underpinning everything from AI and fintech to healthcare and government services. For professionals browsing CloudComputingJobs.co.uk, the biggest opportunities lie with new and fast-scaling employers that are investing heavily in infrastructure, platforms, and next-generation cloud services. In this article, we explore the new cloud computing employers to watch in 2026, focusing on UK-based startups, scale-ups, and global companies expanding their footprint across Britain. These organisations have recently secured funding, launched major projects, or won strategic contracts—clear signals of hiring growth.

Cloud Engineer Jobs in the UK: Salary, Skills, Career Paths & How to Get Hired

Cloud engineer jobs are among the fastest-growing technology roles in the UK. As organisations move infrastructure, applications and data into the cloud, demand for skilled cloud professionals continues to surge across finance, healthcare, retail, defence, government and high-growth startups. If you’re exploring a career in cloud engineering — or looking for your next role — this guide covers everything you need to know: What a cloud engineer does Types of cloud engineer jobs Required skills and certifications UK salary expectations Career progression pathways How to land a cloud engineer job in the UK Whether you’re a graduate, IT professional transitioning into cloud, or an experienced engineer looking to specialise, this article will help you position yourself competitively.