> Markdown version of [/jobs/ext/2824390-security-engineer](https://www.wearedevelopers.com/jobs/ext/2824390-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Surevine Limited - **Location:** Greater London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Amazon Web Services, Software as a Service, Cloud Computing Security, Cyber Security, Identity and Access Management, Python (Programming Language), Systems Integration, Trusted Systems, TypeScript, Data Logging, Pulumi, Data Processing, Gitlab-ci, Gsuite, Terraform - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2859572886-security-engineer ## About the Role We value diverse thinking styles and backgrounds. You don't need to match every point below perfectly; we are interested in your overall fit and potential. * 3-5 years experience in security, security risk, or a related technology role * Working knowledge of ISO 27001, Cyber Essentials and comparable frameworks as a practitioner who has implemented controls, not only assessed them * Some exposure to cloud and SaaS security; identity and access management, logging, configuration hardening etc. and an appetite to take that further * Comfortable thinking about security risk end to end; spotting it, getting it owned by the right person, tracking what happens next, and reporting it honestly to people who will act on it * Credible with engineers. You will be advising people who build secure systems for a living, so you need to be curious about how they work and specific about what you're asking for * Comfortable facilitating a room; design workshops, threat modelling sessions, risk reviews * Able to explain security trade-offs to engineers, to executives and to customers, and to adjust the explanation for each * Security-conscious pragmatism. We need someone who can tell the difference between a risk worth stopping for and a risk worth documenting and moving past * Aile to communicate effectively in a remote environment through written and verbal channels. We accommodate different communication preferences and styles, and value clarity over any particular communication approach ## Description Surevine's mission is to build and deliver secure, scalable, collaboration solutions for the most security conscious organisations, enabling collaboration on their most highly sensitive information. Our customers trust us with their most sensitive information. That trust has to be earned twice: in how we build our products, and how we run ourselves. This is a new role. Your first job is to take ownership of security across our own estate - our corporate services, our cloud environments and the standards we hold ourselves to. Your second is to work alongside our engineering teams so that what we build for customers is secure-by-design. You'll do both by getting into the detail of how we engineer, not by writing policy about it. We are not expecting you to arrive able to do all of this. This is a role with room to grow into, and we would rather hire someone with the right foundation and appetite than wait for someone who ticks every box. Security in Surevine We are a small company, so this is a broad job rather than a narrow one. You will move between looking after our own estate, working alongside our engineering teams on the security of what we build and over time, working directly with customers. ISO 27001, Cyber Essentials, Cyber Essential Plus, Defence Cyber Certification and the standards our sector demands are real and they matter. But we want them woven into how we work rather than bolted on afterwards. If your instinct when you see a gap is to write a procedure, this isn't the role. If your instinct is to work out what would actually close it and then help get that change made, it just might be. There is a path into client-facing work as you grow into the role. Our customers in government, defence and critical national infrastructure need help with secure design, security architecture, assurance evidence and integrating with their own security operations. This isn't where you'll start: the first job is our own house. But if being in the room with a customer and producing work that goes to their security authority with our name on it is somewhere you want to get to, even better. We are actively using AI tools across our development work and inside the business. That changes the security picture; new data handling questions, new governance questions that nobody has settled answers to yet. We want someone curious about that rather than defensive. What you will be doing Below are the key aspects of the role, roughly in order of priority, but we will work with you to find approaches that play to your strengths while achieving our shared goals. * Take ownership of security across our corporate estate - our SaaS applications, our identity provider, our endpoints and our AWS-hosted environments - driving the plan and getting stuck into the work alongside our InfraCare team * Make our ISO27001 and Cyber Essentials obligations business-as-usual; automated where it can be and evidenced as a by-product of how we work * Help us build the visibility we need: logging, monitoring and alerting good enough that we find out about problems ourselves rather than being told about them * Take part in security reviews and help our engineers run their own * Play a leading role when something goes wrong: running the process, knowing when to escape, and liaising with clients, internal teams and support partners * Advise our engineering teams on the security of what we build; contributing to design workshops, challenging assumptions early, and helping teams reach good security decisions without stalling delivery * Own our security risk picture and make it useful: understood by the board, owned by the people who can act on it, and reviewed often enough to mean something * Be the person who answers hard security questions from customers, prospects and their assurance teams - security questionnaires, supplier assessments, and the evidence behind our claims The environment you will be working in We don't expect experience across all of this. We do expect curiosity about it. * Our corporate estate: Google Workspace, SaaS applications, endpoints, identity and access managemen * Our cloud platforms: AWS, GCP, containerised workloads * Our delivery tooling: GitLab CI/CD, Terraform and Pulumi * Our products, built in Typescript, Python and Java, deployed to customer environments including some that are highly restricted * AI-assisted development tooling across our engineering teams, and AI tooling across the wider business ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Why segmenting your infrastructure into tiers makes your infrastructure design better](https://www.wearedevelopers.com/videos/1960-why-segmenting-your-infrastructure-into-tiers-makes-your-infrastructure-design-better) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Unleashing Potential Across Teams: The Power of Infrastructure as Code](https://www.wearedevelopers.com/videos/930-unleashing-potential-across-teams-the-power-of-infrastructure-as-code) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)