> Markdown version of [/jobs/ext/2107987-product-security-engineer-software-security-enablement](https://www.wearedevelopers.com/jobs/ext/2107987-product-security-engineer-software-security-enablement). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Security Engineer - Software Security Enablement - **Company:** Bloomberg - **Location:** London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Build Automation, Microsoft Azure, C++ (Programming Language), Cloud Computing, CMake, Static Program Analysis, Code Review, Cyber Security, Computer Programming, DevOps, Github, Gradle, Information Security Management, Python (Programming Language), Apache Maven, Open Web Application Security, Package Management Systems, Secure Coding, Software Engineering, Systems Integration, TypeScript, Google Cloud, Delivery Pipeline, Large Language Models, Software Security, Kubernetes, Free and Open-Source Software, Build Tools, Npm(Software), Docker, Security Orchestration, Automation & Response, Service Stack, Jenkins, Vulnerability Analysis, Programming Languages - **Published:** August 19, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2933627963-2 ## About the Role Explore, evaluate, and build automation using modern LLM tooling and integration patterns, including custom skills, MCP servers, agentic workflows, retrieval-augmented workflows, and integrations with development and security tooling. You'll need to have: A strong core engineering background with a proven track record. 3+ years of experience in software development. Strong programming experience, with working knowledge of at least one of: C/C++, Python, JavaScript/TypeScript. Knowledge and experience with DevOps and software used in development pipelines (e.g. Github, Jenkins). Working knowledge of build systems, package managers, and development tooling (such as cmake, npm, maven, gradle etc). A core understanding of common security vulnerabilities, such as OWASP Top 10 issues and language-specific vulnerabilities. Experience using, evaluating, or building with LLMs or AI-assisted tooling in technical workflows. Ability to combine technical knowledge with an understanding of core aspects of an information security program. Motivation to keep up with latest trends and techniques in the information security community. Excellent written and verbal communication skills. We'd love to see (not required, but nice to have!): Experience or familiarity with running, maintaining, and customizing static analysis security testing tools such as CodeQL and Semgrep. Broad familiarity with programming language ecosystems and frameworks, particularly C++, JavaScript/TypeScript, Python, Java as well as well as modern systems and infrastructure languages such as Go and Rust Experience using LLMs or AI-assisted tools for security assessments, vulnerability research, secure code review, developer enablement, or security automation.Familiarity with LLM automation concepts and tooling, such as custom skills, MCP servers, agentic workflows, retrieval-augmented workflows, or integrations with development and security tooling. Knowledge of open source software component management, Software Composition Analysis, and related security tools. Knowledge of core concepts in public cloud providers such as AWS, GCP, and Azure. Familiarity with container orchestration technologies such as Kubernetes and Docker, and cloud deployment orchestration. Technical information security certifications, such as CISSP, CSSLP, or SANS certifications. Prior experience integrating security testing into DevOps pipelines.If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role. ## Description that integrate into development pipelines. Maintain and enhance existing security automation processes and security capabilities. Understand and research technical details of core technology stacks and develop or enhance custom code analysis queries. Communicate vulnerability landscape and work on mitigations with stakeholders across the business. Actively monitor the latest news and trends in automated security capabilities, secure development, and AI-assisted security workflows. Develop and enhance operational run books Perform ad-hoc vulnerability discovery, including code review and static analysis for key engineering teams, applications and services. Build or adopt new security capabilities to address issues at scale, such as Software Composition Analysis, Secret searching, and other automated security testing techniques. Use LLMs and AI-assisted workflows as part of security assessments, vulnerability research, secure code review, developer enablement, and security automation. ## Related Videos - [Code to Road in < 12 hours](https://www.wearedevelopers.com/videos/1082-code-to-road-in-12-hours) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Modular Secrets to Lightning-Fast Android Builds](https://www.wearedevelopers.com/videos/1428-modular-secrets-to-lightning-fast-android-builds) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)