> Markdown version of [/jobs/ext/3320687-principal-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/3320687-principal-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Engineer - **Company:** CFC - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Artificial Intelligence, Application Testing, Cloud Computing, Cloud Computing Security, Cloud Engineering, Continuous Integration, Systems Integration, Policy as Code, Software Security, Infrastructure Automation Frameworks, Software Version Control, Devsecops - **Published:** September 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=05d8de42535f1b1d ## About the Role We are interested in engineers who combine principal-level judgement with sustained hands-on delivery. You'll likely bring: * Deep experience in product, application, cloud and DevOps security * Proven experience implementing security tooling in production engineering environments * Strong knowledge of CI/CD, cloud-native architecture, Infrastructure as Code and software supply-chain security * Practical experience with application testing, dependency analysis, secrets detection, container and cloud posture tooling * Ability to write maintainable code, scripts, integrations and policy-as-code * Experience leading threat modelling and resolving complex security design trade-offs * Ability to assess emerging AI and agentic engineering practices pragmatically and establish proportionate controls * Ability to influence senior technical and non-technical stakeholders through evidence and technical credibility ## Description At CFC, technology is at the heart of everything we do. We are looking for a Principal Product Security Engineer to lead the strategy and hands-on delivery of security across cloud platforms, code and CI/CD pipelines. This is a lead individual contributor role for an engineer who solves unique, high-impact problems, advises across disciplines and helps shape functional strategy. You will lead the build and operation of the product-security toolchain, create secure-by-default patterns and influence how security is embedded across engineering. You will also help CFC adopt AI-assisted and agentic product engineering safely. As these practices develop, you will use proportionate guardrails, controlled experimentation and evidence-led assurance rather than assume settled industry practice., * Design, implement and operate the product-security toolchain across source control, CI/CD, cloud and runtime environments * Integrate and tune code, dependency, secrets, infrastructure-as-code, container and cloud security testing * Build policy-as-code, pipeline controls and automation that prevent material weaknesses reaching production * Secure the software supply chain through trusted dependencies, SBOMs, artefact signing, provenance and workload identity * Lead threat modelling and security design reviews for complex products and platforms * Diagnose vulnerabilities and misconfigurations, reduce false positives and work directly with engineers on prevention, remediation and recoverability * Create reusable secure cloud, application and pipeline patterns that engineering teams can adopt by default * Define and test guardrails for AI-assisted coding and agentic workflows, including identity, delegated authority, data, tools and auditability * Measure security coverage, control effectiveness, developer experience and remediation velocity * Act as a senior technical authority, advising stakeholders and coaching engineers setting the standard for security and data protection excellence across the wider technology organisation ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Policy as [versioned] code - you're doing it wrong](https://www.wearedevelopers.com/videos/532-policy-as-versioned-code-you-re-doing-it-wrong) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)