> Markdown version of [/jobs/ext/3020205-security-engineer](https://www.wearedevelopers.com/jobs/ext/3020205-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Jobposting - **Location:** UK (Remote available) - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Cloud Computing, Cloud Computing Security, Continuous Integration, PostgreSQL, TypeScript, ReactJS, Software Security, Build Management, Vulnerability Analysis, Golang - **Published:** September 21, 2026 - **Apply:** https://startup.jobs/security-engineer-incident-io-8117853 ## About the Role * You've got a track record across application security, cloud, or infrastructure, whether that's vulnerability research, penetration testing, red teaming, or hardening systems at scale * You're comfortable moving between different parts of the stack, application code, cloud infrastructure, CI/CD, tooling, rather than staying in one lane * You know your way around modern web stacks, React, Go, TypeScript, Postgres or similar, well enough to spot where things go wrong before they do * You're genuinely comfortable embedding inside a product team and influencing design decisions, not just reviewing them after the fact * You've got real cloud security experience, ideally GCP, and you know how to focus on what actually reduces risk rather than chasing every theoretical issue * You communicate well, you can deliver a hard piece of feedback to an engineer and have them thank you for it * You've got grit, you're building this function from nothing, and the hard days, the scary find in production, the process that doesn't exist yet, don't put you off * You live and breathe security, this isn't just the day job for you, it's something you genuinely geek out on ## Description We're looking for our second Security Engineer, someone with a real passion for application security who thrives embedded within product teams rather than sitting apart from them. You'll be part of building this function out to a team of five this year, and you'll work side by side with engineers to design and build secure systems from the start, not swoop in at the end with a checklist. The work is greenfield and you'll be deciding how security gets done at incident from first principles, not inheriting someone else's process. There's very little process here today, and that's deliberate, it means you can move quickly rather than fight your way through approval chains. You'll have real autonomy over how you approach the work. The engineers you'll be working with are excellent, and they've already dealt with the easy problems. What's left for you is the genuinely hard stuff, the kind of work that's interesting precisely because it hasn't been solved yet. The role spans a bit of application security, a bit of infrastructure, a bit of tech ops, we're looking for a generalist at heart, with application security as the strongest focus. We think of security as something that helps the business move, not something that slows it down. That means saying yes wherever we genuinely can, while still having the authority to block a release when something matters enough. We're heavy adopters of AI, and this role sits right in the middle of that. You'll have an unlimited Claude token budget to speed up your own work, review, testing, threat modelling, and you'll also be responsible for securing the AI features and AI driven workflows we're shipping into the product. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Optimizing Discovery: PostgreSQL's Role in Transforming GetYourGuide's Search](https://www.wearedevelopers.com/videos/1647-optimizing-discovery-postgresql-s-role-in-transforming-getyourguide-s-search) - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)