> Markdown version of [/jobs/ext/2009587-product-security-architect](https://www.wearedevelopers.com/jobs/ext/2009587-product-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Security Architect - **Company:** SRT Marine Systems plc - **Location:** Midsomer Norton, UK - **Experience:** Expert - **Salary:** £75,000.0 - £110,000.0 - **Contract:** Permanent contract - **Skills:** Software as a Service, Cyber Security, Continuous Integration, Secure Coding, Software Engineering, Software Vulnerability Management, Software Security, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5830332743 ## About the Role * Strong experience in product security, application security, secure software engineering, security architecture or a similar role in a software-led environment. * Good understanding of how product and development teams operate, including how security considerations are balanced alongside product delivery. * Strong experience of threat modelling, secure design review, vulnerability assessment and remediation prioritisation. * The judgement to assess exploitability and business impact pragmatically. * Practical experience applying security across the software development lifecycle, including areas such as threat modelling, secure coding, testing, vulnerability management and secure delivery. * Ability to influence product, development and cross-functional stakeholders without direct authority. * Strong communication skills, with the ability to turn technical security concerns into clear, actionable decisions. * Familiarity with recognised frameworks or certifications such as ISO 27001, NIST CSF or similar would be helpful. * Experience in a product, platform or SaaS business. * Experience in high-trust, regulated or mission-critical environments would be valuable. ## Description * Act as a senior security voice across the product and development teams, ensuring security is properly represented in roadmap, backlog and design decisions. * Work with colleagues across product, development, and networks & infrastructure to embed security across the product lifecycle. * Carry out threat modelling, secure design reviews and technical risk assessments for new and existing product capabilities. * Assign pragmatic risk levels and support sensible prioritisation of remediation alongside feature delivery and other technical work. * Help improve secure software development and delivery practices, including CI/CD and related controls. * Support vulnerability remediation, including root cause analysis and long-term fixes. * Contribute to security standards, metrics and ways of working that improve product security maturity over time. * Provide security leadership and architectural guidance for the secure implementation and operation of our products in customer environments, including defining the principles, patterns and guidance that customer-facing and implementation teams should follow. * Work with internal stakeholders to ensure engineering reality supports the security claims we make to customers, partners and auditors. * Contribute to wider assurance and certification activity, including ISO 27001 or other relevant standards. Technologies: * CI/CD * Support * PLC * Security * Architect * Network ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering)