Product Security Engineer (we have office locations in Cambridge, Leeds & London)

Genomics England
London, UK
8 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£61,234.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Applications Architecture Cloud Computing Code Review Cyber Security Continuous Integration Reliability Engineering Software Engineering Software Vulnerability Management Delivery Pipeline Software Security
+3 more
Gitlab-ci Terraform Microservices

Job description

As a Product Security Engineer, you will work as part of the Cyber Security team at Genomics England, partnering closely with engineering squads and product teams to integrate security into day-to-day delivery.

The purpose of this role is to bring security closer to where engineering decisions are made, enabling teams to adopt Genomics England’s security standards in a practical and scalable way. You will work directly with squads as a trusted partner, helping them build and deliver secure systems rather than acting as a central gatekeeper.

You will support teams to shift security left by contributing to secure design and development from the outset. This includes helping teams implement security testing in CI/CD pipelines, improving vulnerability management within squads, and ensuring security issues are addressed as part of normal delivery.

Acting as a bridge between central security and delivery teams, you will translate security policies and risk expectations into clear, actionable engineering practices. You will contribute to threat modelling, design discussions, and security reviews, helping teams break down complex security challenges into pragmatic technical solutions.

This is a hands-on, product-embedded security role. While it is not a platform or site reliability engineering position, it requires strong practical familiarity with cloud-native systems, CI/CD pipelines and infrastructure-as-code to credibly influence design and implementation decisions within squads.

A key part of the role is enabling and scaling security capability through the Security Champions programme. You will support and grow this community, helping champions build security knowledge and embed good practices within their teams.

Through this role, you will help evolve Genomics England towards a model where security is owned by engineering teams, with Cyber Security providing guidance, expertise, and enablement.

Requirements

  • A strong foundation in cyber security engineering, including secure design principles and risk-based decision making.

  • Practical experience embedding security into software development, including supporting shift-left practices across design, development, and delivery.

  • Experience working hands-on with engineering teams, with the ability to understand application architectures, review code or designs, and help troubleshoot security issues.

  • Experience integrating security controls into CI/CD pipelines, including code, dependency, and infrastructure-as-code scanning, with an emphasis on automation and developer experience.

  • Practical familiarity with public cloud environments, particularly AWS, including common security patterns and risks.

  • Experience working alongside Infrastructure-as-Code and delivery pipelines (e.g. Terraform, GitLab CI/CD or equivalent), with the ability to review and influence implementations.

  • Confidence engaging at an engineering level on designs, pipelines and configurations, even where you are not the primary implementer.

  • Solid understanding of vulnerability management, including helping teams interpret findings, prioritise remediation, and manage vulnerabilities as part of business-as-usual delivery.

  • Experience facilitating threat modelling and contributing to design reviews, helping teams identify and address security risks early in the development lifecycle.

  • Ability to translate security standards and policies into clear, actionable engineering guidance, patterns, and reusable approaches.

  • Experience working in modern engineering environments (e.g. cloud platforms, APIs, microservices, or containerised systems).

  • Strong communication and stakeholder-management skills, with the ability to influence teams through collaboration rather than authority.

  • An interest in security education, enablement, and culture, including mentoring engineers and supporting security champions within teams.

  • This role does not require ownership of production platforms or central security tooling but does require the credibility to work closely with engineers and influence how security is implemented.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all