Senior Security & Compliance Engineer
Role Summary
Join XYZ Reality as a Senior Security & Compliance Engineer in London, focusing on enhancing security for innovative construction technology.
About the Organisation
If you’re an experienced security engineer who wants more than maintaining an established security programme, and you’re excited by the opportunity to build, influence and own security within a growing technology business, we’d love to hear from you.
Find Jobs in United Kingdom on Arbeitnow
- 🔐 Become our first dedicated security hire and have genuine ownership over how security develops at XYZ Reality
- 🏠 Hybrid working from our London office
- 🏝️ 25 days annual leave + public holidays
- 🩺 Private healthcare with Vitality
- 🎄 Additional Christmas shutdown days
- 🪙 Biannual salary reviews
- 🥳 Summer & Christmas company events
- 🍣 Free Thursday lunch and after-work gatherings
- 💰 Employee referral scheme
- 🚲 Cycle to Work scheme
Minimum Requirements
Experience building or scaling security capability within a high-growth or Series A/B technology business would be particularly valuable. You’ll understand the balance between addressing today’s risks and building security foundations capable of supporting where the business is heading next.
Above all, we’re looking for someone who is technically strong, curious and proactive, someone engineers want to work with, who can bring credibility to security conversations while remaining pragmatic about how we build and ship great technology.
- Demonstrable in-depth hands-on technical security experience, ideally spanning application, cloud and/or infrastructure security.
- Strong technical security capability and the confidence to own security decisions end-to-end rather than operating purely in an advisory or governance capacity.
- Strong cloud security experience, ideally Azure, although significant AWS or GCP expertise with the ability to transition quickly to Azure would also be considered.
- Hands-on experience securing Kubernetes/containerised environments, including IAM, RBAC, network segmentation, secrets management, image scanning and pod security.
- Experience integrating security tooling into CI/CD environments, including SAST, DAST, SCA and dependency scanning.
- Experience with infrastructure-as-code security and technologies such as Terraform, Helm or GitOps.
- Understanding of application and API security, including OAuth 2.0, JWT, mTLS and secure development practices.
- Experience identifying vulnerabilities, assessing technical risk and driving remediation.
- Comfortable writing automation using Python, Go, Bash or similar to operationalise security controls.
- Practical experience working with SOC 2 Type II and/or ISO 27001, including identifying gaps and strengthening controls.
- Current knowledge of the evolving cybersecurity landscape and an interest in emerging threats, particularly those associated with AI.
- Strong communication skills and the ability to translate security requirements for both technical and non-technical stakeholders.
- A pragmatic, collaborative approach, you understand that great security enables engineering teams rather than creating unnecessary barriers.
Eligibility Criteria
Eligibility requirements unclear, further review needed for details on sponsorship and applicant countries.
⚠️ Disclaimer: PathwayAI Africa does not guarantee employment, scholarships, visas, or admission. Always verify all opportunities through official sources before submitting personal information.
Check if You Qualify
Upload your CV to compare it against this specific opportunity. You can still apply even if improvements are recommended.
