Senior Product Security Engineer

London
2 weeks ago
Create job alert

Senior Product Security Engineer** (Contract)

Duration: 8 Months (Possibility for extension)

Location: London/Hybrid (2 days per week on site)

Rate: A highly competitive Umbrella Day Rate is available for suitable candidates

Role Overview

As a Senior Product Security Engineer, you will be an essential partner in embedding security practices throughout the entire product lifecycle-from design and development to deployment and maintenance. Your collaboration with engineering, product management, and compliance teams will ensure our products are not only secure by design but also resilient in production environments.

Key Responsibilities:

Security Policy Development: Define and implement robust security policies and tooling across the product lifecycle, ensuring security is integrated from the ground up.
Threat Modeling Leadership: Lead threat modeling sessions for both new and existing applications, guiding teams to ensure documented and actionable outputs.
Vulnerability Management: Oversee the product vulnerability backlog by prioritizing the remediation of high and critical vulnerabilities, and track key metrics such as open vulnerabilities and SLA compliance.
Bug Bounty Coordination: Manage findings from bug bounty programs and ensure timely remediation of identified issues.
Root Cause Analysis: Conduct thorough root cause analysis for security incidents and systemic vulnerabilities, leveraging insights to drive developer training and systemic improvements.
Incident Response Management: Act as Investigation Lead or Incident Commander during incident response efforts, including facilitating tabletop exercises to enhance our incident readiness.

Skills & Experience:

Expertise: Deep knowledge in vulnerability management, threat modeling, security architecture, and secure software development lifecycle (SDLC) practices.
Incident Response Skills: Strong background in incident response, root cause analysis, and managing bug bounty programs.
Communication Ability: Excellent communication and stakeholder management skills, with proven experience in driving cross-functional initiatives.
Risk Management Experience: Familiarity with third-party risk management, security assessments, and regulatory compliance.
Technical Proficiency: Experience working with CI/CD teams to implement security technologies in the pipeline, including SAST, DAST, and SCA tools.
Collaborative Spirit: A track record of partnering with cross-functional teams to deliver impactful security initiatives.

Candidates will need to show evidence of the above in their CV in order to be considered.

If you feel you have the skills and experience and want to hear more about this role 'apply now' to declare your interest in this opportunity with our client. Your application will be observed by our dedicated team.

We will respond to all successful applicants ASAP however, please be advised that we will always look to contact you further from this time should we need further applicants or if other opportunities arise relevant to your skillset.

Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyone's chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities, and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive.

As part of our standard hiring process to manage risk, please note background screening checks will be conducted on all hires before commencing employment.

We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention

Related Jobs

View all jobs

Systems Engineer

Senior Software Engineer

Senior Software Engineer

Senior Software Engineer

Senior Devops Engineer

Senior Cloud Engineer

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cloud Engineer Jobs in the UK: Salary, Skills, Career Paths & How to Get Hired

Cloud engineer jobs are among the fastest-growing technology roles in the UK. As organisations move infrastructure, applications and data into the cloud, demand for skilled cloud professionals continues to surge across finance, healthcare, retail, defence, government and high-growth startups. If you’re exploring a career in cloud engineering — or looking for your next role — this guide covers everything you need to know: What a cloud engineer does Types of cloud engineer jobs Required skills and certifications UK salary expectations Career progression pathways How to land a cloud engineer job in the UK Whether you’re a graduate, IT professional transitioning into cloud, or an experienced engineer looking to specialise, this article will help you position yourself competitively.

How Many Cloud Computing Tools Do You Need to Know to Get a Cloud Job?

If you are aiming for a role in cloud computing, it can feel like the skills list never ends. One job advert asks for AWS, Terraform and Kubernetes. Another mentions Azure DevOps, PowerShell and ARM templates. A third throws in Docker, Python, Linux, CI/CD, monitoring tools and security frameworks. It is no surprise that many cloud job seekers feel overwhelmed before they even apply. Here is the reality most cloud hiring managers agree on: they are not hiring you because you know every cloud tool. They are hiring you because you understand cloud concepts, can design reliable systems, manage costs, keep things secure and support real workloads. Tools matter, but only when they support outcomes. So how many cloud computing tools do you actually need to know to get a job? For most roles, the answer is far fewer than you think. This article explains what employers really expect, which tools are essential, which are role-specific, and how to focus your learning so you look capable and employable rather than scattered.

What Hiring Managers Look for First in Cloud Computing Job Applications (UK Guide)

anding a job in cloud computing can be highly competitive — especially in the UK market where demand far outpaces supply in many segments. Whether you’re aiming for roles in Cloud Engineering, DevOps, Site Reliability, Cloud Architecture, Security, Data/Analytics, or Platform Operations, hiring managers screen applications quickly and with specific priorities in mind. Hiring managers don’t read every detail at first; they scan for critical signals in the first 10–20 seconds. These early signals determine whether your CV gets read more closely, whether your LinkedIn profile gets clicked, and whether you’re invited to interview. This guide breaks down, in practical terms, exactly what hiring managers look for first in cloud computing applications — and what you should emphasise in your CV, cover letter and portfolio to stand out on www.cloudcomputingjobs.co.uk .