> Markdown version of [/jobs/ext/2992906-principal-security-engineer](https://www.wearedevelopers.com/jobs/ext/2992906-principal-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Engineer - **Company:** Capco - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing Security, Code Review, Identity and Access Management, Python (Programming Language), Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Zero Trust Network Access, Secure Coding, Security Information and Event Management, Systems Integration, DevOps Tools - Open-source, Cybercrime, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 19, 2026 - **Apply:** https://job-boards.greenhouse.io/capco/jobs/8213763 ## About the Role * Strong hands-on experience with Palo Alto, Microsoft or similar security ecosystems * Deep understanding of cloud security for AWS, Azure or GCP platforms * Proven expertise in secure coding, endpoint protection, SIEM and IAM * Familiarity with frameworks and standards such as ISO 27001, NIST and OWASP, alongside an understanding of responsible AI, security guardrails and human-in-the-loop controls * Proficiency in Python, Bash, PowerShell or Go for security automation and tool development, with experience implementing Zero Trust Architecture solutions Bonus Points For * Certifications such as CISSP, CSSLP or cloud-specific credentials * Experience building or integrating AI-enabled security tooling, automation and responsible AI guardrails * Experience mentoring engineering teams and driving security awareness * Advanced knowledge of DevSecOps tools and practices * Exposure to financial services security and regulatory requirements, with a passion for staying current with cyber trends and emerging threat landscapes ## Description As a Principal Security Engineer at Capco, you'll lead the design and implementation of secure systems and processes across cloud and on-premise platforms. You'll collaborate closely with engineering and client teams to embed security-by-design principles throughout the SDLC, integrate automated security tooling, and ensure resilience against evolving cyber threats. You'll also use approved AI tools and AI-enabled workflows where appropriate to improve the speed, quality and effectiveness of security engineering, while maintaining human judgement, responsible AI guardrails and appropriate review and escalation. What You'll Do * Design and implement enterprise-wide security controls and frameworks, using approved AI and automation where appropriate to improve security outcomes * Embed security controls into CI/CD pipelines (SAST, SCA, DAST, container scanning) and enable secure SDLC practices * Collaborate across teams to champion secure development practices and responsible use of AI-enabled security workflows * Lead vulnerability assessments, code reviews and security audits across infrastructure and applications, maintaining appropriate human review, audit trails and escalation pathways * Develop and evolve security standards, engineering patterns and data protection strategies ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)