Principal Product Security Engineer

CFC
London, UK
13 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Clean Code Principles Artificial Intelligence Application Testing Cloud Computing Cloud Computing Security Cloud Engineering Continuous Integration Systems Integration Policy as Code Software Security Infrastructure Automation Frameworks Software Version Control
+1 more
Devsecops

Job description

At CFC, technology is at the heart of everything we do. We are looking for a Principal Product Security Engineer to lead the strategy and hands-on delivery of security across cloud platforms, code and CI/CD pipelines. This is a lead individual contributor role for an engineer who solves unique, high-impact problems, advises across disciplines and helps shape functional strategy. You will lead the build and operation of the product-security toolchain, create secure-by-default patterns and influence how security is embedded across engineering. You will also help CFC adopt AI-assisted and agentic product engineering safely. As these practices develop, you will use proportionate guardrails, controlled experimentation and evidence-led assurance rather than assume settled industry practice., * Design, implement and operate the product-security toolchain across source control, CI/CD, cloud and runtime environments

  • Integrate and tune code, dependency, secrets, infrastructure-as-code, container and cloud security testing
  • Build policy-as-code, pipeline controls and automation that prevent material weaknesses reaching production
  • Secure the software supply chain through trusted dependencies, SBOMs, artefact signing, provenance and workload identity
  • Lead threat modelling and security design reviews for complex products and platforms
  • Diagnose vulnerabilities and misconfigurations, reduce false positives and work directly with engineers on prevention, remediation and recoverability
  • Create reusable secure cloud, application and pipeline patterns that engineering teams can adopt by default
  • Define and test guardrails for AI-assisted coding and agentic workflows, including identity, delegated authority, data, tools and auditability
  • Measure security coverage, control effectiveness, developer experience and remediation velocity
  • Act as a senior technical authority, advising stakeholders and coaching engineers setting the standard for security and data protection excellence across the wider technology organisation

Requirements

We are interested in engineers who combine principal-level judgement with sustained hands-on delivery. You’ll likely bring:

  • Deep experience in product, application, cloud and DevOps security
  • Proven experience implementing security tooling in production engineering environments
  • Strong knowledge of CI/CD, cloud-native architecture, Infrastructure as Code and software supply-chain security
  • Practical experience with application testing, dependency analysis, secrets detection, container and cloud posture tooling
  • Ability to write maintainable code, scripts, integrations and policy-as-code
  • Experience leading threat modelling and resolving complex security design trade-offs
  • Ability to assess emerging AI and agentic engineering practices pragmatically and establish proportionate controls
  • Ability to influence senior technical and non-technical stakeholders through evidence and technical credibility

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:32 min

Decoupling business logic with policy as code

Anderson Dadario +1 · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all