> Markdown version of [/jobs/ext/2972723-senior-engineer-software-security](https://www.wearedevelopers.com/jobs/ext/2972723-senior-engineer-software-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Engineer, Software Security - **Company:** gb Nothing - **Location:** UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, C++ (Programming Language), Cloud Computing Security, Cyber Security, Information Systems Security Architecture Professional, Python (Programming Language), OAuth, Software Vulnerability Management, Google Cloud, Large Language Models, Software Security, Backend, Production Code, Build Tools, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** September 18, 2026 - **Apply:** https://www.totaljobs.com/job/engineer-security/nothing-job107999918 ## About the Role * 6+ years in application security, including security architecture you've designed for commercial products and services and have managed the posture of ongoing production. * Deep threat modelling expertise. You can define the methodology for a company, not just follow one. * Hands-on cloud security across AWS, GCP, Azure, and other global hyperscalers. You've secured backend services at real scale and depth of complexity. * Command of the secure SDLC: SAST, DAST, SBOM and the judgement to know which findings matter. * Experience applying AI or LLMs to security: simulating threats, probing defences, building countermeasures. * Solid cryptography and identity fundamentals, including TLS, OAuth 2.0, SSO and token management. You write production-quality code in Python, Go, Java, and C++. * You own a domain end to end, hold a high bar, and cut through ambiguity, whether the person across the table is an engineer or a lawyer. ## Description * Own security lifecycle and secure architecture for Nothing's backend services and cloud platforms, from first design to live operations across all our CI/CD pipelines * Define our secure development standards and wire SAST, DAST and SBOM tooling into how we ship. * Own vulnerability management end to end: find issues, triage findings, and drive engineering teams to closure. * Design our security testing, from penetration testing to fuzzing, and build tools other engineers can run without you. * Ship network and server-side and data protection: API security, WAF, gateways, runtime defences, encryption in transit and at rest. * Partner with our mobile, OS and desktop teams on client-side security tactics and strategy. * Collaborate with our privacy and legal functions to help us engineer solutions to our global regulatory requirements focusing on emergent technologies such as AI * Lead threat modelling across authentication, data protection and input handling. Use AI and LLMs to simulate attacks before they happen, then collaborate with the various teams to build the defences. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)