Senior Engineer, Software Security at Nothing | GB | Rezi

Senior Engineer, Software Security at Nothing

Senior Engineer, Software Security

Nothing · GB

1 weeks ago

Senior Engineer, Software Security

Nothing · GB

7 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Senior Engineer, Software Security role.

Rezi rewrites your resume against Nothing's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Senior Engineer, Software Security posting at Nothing — free, in seconds.

About the Role

We are seeking an engineer to define and implement security standards, tooling, and strategies for Nothing's backend services and cloud platforms. The role involves owning the security lifecycle, from design to live operations, and ensuring secure development practices without hindering progress.

Responsibilities

  • Own security lifecycle and secure architecture for backend services and cloud platforms, from design to live operations across CI/CD pipelines.
  • Define secure development standards and integrate SAST, DAST, and SBOM tooling.
  • Manage vulnerability management end-to-end, including issue identification, triage, and driving closure with engineering teams.
  • Design security testing methodologies, including penetration testing and fuzzing, and build engineer-runnable tools.
  • Implement network and server-side security, including API security, WAF, gateways, runtime defenses, and data encryption.
  • Partner with mobile, OS, and desktop teams on client-side security tactics and strategy.
  • Collaborate with privacy and legal teams to engineer solutions for global regulatory requirements, focusing on emergent technologies like AI.
  • Lead threat modeling for authentication, data protection, and input handling, utilizing AI and LLMs to simulate attacks and build defenses.

Requirements

  • 6+ years in application security, with experience in designing security architecture for commercial products and services.
  • Experience managing the security posture of ongoing production environments.
  • Deep threat modeling expertise, capable of defining company-wide methodologies.
  • Hands-on cloud security experience across AWS, GCP, Azure, and other global hyperscalers.
  • Experience securing backend services at scale and complexity.
  • Proficiency in the secure SDLC, including SAST, DAST, and SBOM, with the judgment to prioritize findings.
  • Experience applying AI or LLMs to security tasks such as threat simulation, defense probing, and countermeasure building.
  • Solid cryptography and identity fundamentals, including TLS, OAuth 2.0, SSO, and token management.
  • Ability to write production-quality code in Python, Go, Java, and C++.
  • Ability to own a domain end-to-end, maintain a high standard, and navigate ambiguity with technical and legal stakeholders.

Skills

  • Application Security
  • Security Architecture
  • Cloud Security (AWS, GCP, Azure)
  • Secure SDLC
  • SAST
  • DAST
  • SBOM
  • Vulnerability Management
  • Penetration Testing
  • Fuzzing
  • Network Security
  • Server-side Security
  • Data Protection
  • API Security
  • WAF
  • Encryption
  • Threat Modeling
  • AI/LLMs in Security
  • Cryptography
  • Identity Management
  • TLS
  • OAuth 2.0
  • SSO
  • Token Management
  • Python
  • Go
  • Java
  • C++

Location

  • London, UK

Work Type

  • Full-time
  • Onsite

Experience Level

  • 6+ years

About the Company

  • Nothing exists to make tech feel exciting again.
  • We’re building a different kind of technology company, one that puts design, emotion, and human creativity at the heart of everything we do.
  • Founded in London in 2020, we’ve grown from idea to global challenger in just a few years.
  • Backed by GV (Google Ventures), EQT Ventures, and C Ventures, and investors like Tony Fadell (iPod), Casey Neistat, and Kevin Lin (Twitch), we’re now sold in 40+ markets with millions of users worldwide.