Product Security Engineer (we have office locations in Cambridge, Leeds & London) at Genomics England | GB | Rezi

Product Security Engineer (we have office locations in Cambridge, Leeds & London) at Genomics England

Product Security Engineer (we have office locations in Cambridge, Leeds & London)

Genomics England · GB

1 weeks ago

Product Security Engineer (we have office locations in Cambridge, Leeds & London)

Genomics England · GB

10 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

As a Product Security Engineer, you will integrate security into day-to-day delivery by partnering closely with engineering squads and product teams. The purpose of this role is to bring security closer to where engineering decisions are made, enabling teams to adopt security standards in a practical and scalable way. You will support teams to shift security left by contributing to secure design and development from the outset, helping them implement security testing in CI/CD pipelines, improve vulnerability management, and ensure security issues are addressed as part of normal delivery. You will act as a bridge between central security and delivery teams, translating security policies into actionable engineering practices and contributing to threat modelling, design discussions, and security reviews.

Responsibilities

  • Integrate security into day-to-day delivery by partnering closely with engineering squads and product teams.
  • Bring security closer to where engineering decisions are made, enabling teams to adopt security standards.
  • Support teams to shift security left by contributing to secure design and development.
  • Help teams implement security testing in CI/CD pipelines.
  • Improve vulnerability management within squads.
  • Ensure security issues are addressed as part of normal delivery.
  • Translate security policies and risk expectations into clear, actionable engineering practices.
  • Contribute to threat modelling, design discussions, and security reviews.
  • Enable and scale security capability through the Security Champions programme.
  • Support and grow the Security Champions community.
  • Help champions build security knowledge and embed good practices within their teams.
  • Evolve Genomics England towards a model where security is owned by engineering teams.

Requirements

  • A strong foundation in cyber security engineering, including secure design principles and risk-based decision making.
  • Practical experience embedding security into software development, including supporting shift-left practices across design, development, and delivery.
  • Experience working hands-on with engineering teams, with the ability to understand application architectures, review code or designs, and help troubleshoot security issues.
  • Experience integrating security controls into CI/CD pipelines, including code, dependency, and infrastructure-as-code scanning, with an emphasis on automation and developer experience.
  • Practical familiarity with public cloud environments, particularly AWS, including common security patterns and risks.
  • Experience working alongside Infrastructure-as-Code and delivery pipelines (e.g. Terraform, GitLab CI/CD or equivalent), with the ability to review and influence implementations.
  • Confidence engaging at an engineering level on designs, pipelines and configurations.
  • Solid understanding of vulnerability management, including helping teams interpret findings, prioritise remediation, and manage vulnerabilities as part of business-as-usual delivery.
  • Experience facilitating threat modelling and contributing to design reviews, helping teams identify and address security risks early in the development lifecycle.
  • Ability to translate security standards and policies into clear, actionable engineering guidance, patterns, and reusable approaches.
  • Experience working in modern engineering environments (e.g. cloud platforms, APIs, microservices, or containerised systems).
  • Strong communication and stakeholder-management skills, with the ability to influence teams through collaboration rather than authority.
  • An interest in security education, enablement, and culture, including mentoring engineers and supporting security champions within teams.
  • Practical experience working with engineering teams and embedding security into delivery is far more important than formal qualifications.
  • Equivalent real-world experience enabling teams to adopt secure development practices, integrate security into CI/CD pipelines, and manage vulnerabilities effectively is considered equally valuable.

Skills

  • Secure design principles
  • Risk-based decision making
  • Shift-left practices
  • CI/CD pipeline security integration
  • Vulnerability management
  • Threat modelling
  • Design reviews
  • Public cloud environments (AWS)
  • Infrastructure-as-Code (Terraform, GitLab CI/CD)
  • Modern engineering environments (cloud platforms, APIs, microservices, containerised systems)
  • Communication
  • Stakeholder management
  • Security education
  • Security enablement
  • Security culture
  • Mentoring engineers
  • Supporting security champions

Location

  • Canary Wharf
  • Cambridge
  • Leeds
  • London

Work Type

  • Blended working model
  • Hybrid working

Experience Level

  • Practical experience embedding security into software development
  • Experience working hands-on with engineering teams
  • Experience integrating security controls into CI/CD pipelines
  • Practical familiarity with public cloud environments
  • Experience working alongside Infrastructure-as-Code and delivery pipelines
  • Experience facilitating threat modelling and contributing to design reviews
  • Experience working in modern engineering environments
  • Equivalent real-world experience enabling teams to adopt secure development practices

Education Level

  • Certifications or training in secure software development or application security (e.g. secure coding, secure SDLC, or application security practices).
  • Knowledge of cloud security principles, whether through formal certification or hands-on experience.
  • Training in threat modelling, secure design, or security architecture.
  • Exposure to DevSecOps practices, including integrating security into CI/CD pipelines.
  • Evidence of ongoing professional development in cyber security or software security.

Salary/Compensations

  • From: £78,850

Benefits

  • 30 days’ holiday, plus bank holidays, plus additional leave for long service
  • Option to apply for up to 30 days of remote working abroad annually (approval required)
  • Blended working arrangements
  • Flexible working
  • Enhanced maternity, paternity and shared parental leave benefits
  • Defined contribution pension (Genomics England double-matches up to 10%)
  • Life Assurance (3x salary)
  • Electric Vehicle salary sacrifice scheme
  • Give As You Earn scheme
  • Individual learning budgets
  • Support for training and certifications
  • Reimbursement for one annual professional subscription (approval required)
  • Employee recognition programme
  • Referral scheme
  • Subsidised gym membership
  • Free Headspace account
  • Access to an Employee Assistance Programme
  • Eye tests
  • Flu jabs

About the Company

  • Genomics England is a global leader in enabling genomic medicine and research, focused on creating a world where everyone benefits from genomic healthcare.
  • Building on the 100,000 Genomes Project, we support the NHS’s world-first national whole genome sequencing service and run the growing National Genomic Research Library, alongside delivering numerous major genomics initiatives.
  • By connecting research and clinical care at national scale, we enable immediate healthcare benefits and advances for the future.
  • Our mission is to provide the evidence and digital systems so that by 2035 genomics could play a role in up to half of all healthcare interactions, whilst securing the UK’s position as the best place to discover, prove and benefit from genomic innovations.
  • We are accelerating our impact and working with patients, doctors, scientists, government and industry to improve genomic testing, and help researchers access the health data and technology they need to make new medical discoveries and create more effective, targeted medicines for everybody.
  • Behind the Healthcare and Research outcomes, Genomics England delivers through designing, developing and operating complex healthcare software systems.
  • We're on the cusp of big changes with the real prospect of genomics becoming the fabric of everyday healthcare through the lifetime - from birth to old age.

Equal Opportunity

  • Genomics England is actively committed to providing and supporting an inclusive environment that promotes equity, diversity and inclusion best practice both within our community and in any other area where we have influence.
  • We are proud of our diverse community where everyone can come to work and feel welcomed and treated with respect regardless of any disability, ethnicity, gender, gender identity, religion, sexual orientation, or social background.
  • Genomics England’s policies of non-discrimination and equity and will be applied fairly to all people, regardless of age, disability, gender identity or reassignment, marital or civil partnership status, being pregnant or recently becoming a parent, race, religion or beliefs, sex or sexual orientation, length of service, whether full or part-time or employed under a permanent or a fixed-term contract or any other relevant factor.
  • Genomics England does not tolerate any form of discrimination, harassment, victimisation or bullying at work.
  • Our People policies outline our commitment to inclusivity.
  • We aim to remove barriers in our recruitment processes and to be flexible with our interview processes.
  • Should you require any adjustments that may help you to fully participate in the recruitment process, we encourage you to discuss this with us.