Senior Engineer, Software Security

gb Nothing
UK
2 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) Artificial Intelligence Amazon Web Services Software System Penetration Testing Microsoft Azure C++ (Programming Language) Cloud Computing Security Cyber Security Information Systems Security Architecture Professional Python (Programming Language) OAuth Software Vulnerability Management
+9 more
Google Cloud Large Language Models Software Security Backend Production Code Build Tools Static Application Security Testing Golang Dynamic Application Security Testing

Job description

  • Own security lifecycle and secure architecture for Nothing’s backend services and cloud platforms, from first design to live operations across all our CI/CD pipelines
  • Define our secure development standards and wire SAST, DAST and SBOM tooling into how we ship.
  • Own vulnerability management end to end: find issues, triage findings, and drive engineering teams to closure.
  • Design our security testing, from penetration testing to fuzzing, and build tools other engineers can run without you.
  • Ship network and server-side and data protection: API security, WAF, gateways, runtime defences, encryption in transit and at rest.
  • Partner with our mobile, OS and desktop teams on client-side security tactics and strategy.
  • Collaborate with our privacy and legal functions to help us engineer solutions to our global regulatory requirements focusing on emergent technologies such as AI
  • Lead threat modelling across authentication, data protection and input handling. Use AI and LLMs to simulate attacks before they happen, then collaborate with the various teams to build the defences.

Requirements

  • 6+ years in application security, including security architecture you’ve designed for commercial products and services and have managed the posture of ongoing production.
  • Deep threat modelling expertise. You can define the methodology for a company, not just follow one.
  • Hands-on cloud security across AWS, GCP, Azure, and other global hyperscalers. You’ve secured backend services at real scale and depth of complexity.
  • Command of the secure SDLC: SAST, DAST, SBOM and the judgement to know which findings matter.
  • Experience applying AI or LLMs to security: simulating threats, probing defences, building countermeasures.
  • Solid cryptography and identity fundamentals, including TLS, OAuth 2.0, SSO and token management. You write production-quality code in Python, Go, Java, and C++.
  • You own a domain end to end, hold a high bar, and cut through ambiguity, whether the person across the table is an engineer or a lawyer.

About the company

We’re building a different kind of technology company, one that puts design, emotion, and human creativity at the heart of everything we do. From the way our products look and feel to how we communicate and show up in culture, we believe technology should make you feel something.

Founded in London in 2020, we’ve grown from idea to global challenger in just a few years. Backed by GV (Google Ventures), EQT Ventures, and C Ventures, and investors like Tony Fadell (iPod), Casey Neistat, and Kevin Lin (Twitch), we’re now sold in 40+ markets with millions of users worldwide.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all