7 дней назад
Principal Security Software Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Security Software Engineer (Cybersecurity): Improving secure software development processes for endpoint security products with an accent on EU Cyber Resilience Act compliance, static analysis, vulnerability management, and security-by-design. Focus on integrating security tools into development workflows, strengthening software assurance, and solving complex security problems across Windows, Linux, virtualization, and isolation components.
Location: Cambridge, Cambridgeshire, United Kingdom; hybrid working with a minimum of three onsite days per week
Company
Develops endpoint security products that combine hardware, firmware, software, cloud-connected services, and micro-virtualization to protect devices and data from advanced malware.
What you will do
- Lead improvements to the secure software development lifecycle in line with European Union Cyber Resilience Act expectations.
- Integrate and improve static analysis tools across development and build workflows, including rules, policies, triage, false-positive management, and remediation tracking.
- Promote security-by-design and secure-by-default practices through threat modelling, design reviews, architecture guidance, and secure coding.
- Improve vulnerability identification, assessment, documentation, remediation, and measurement throughout the software development lifecycle.
- Provide technical leadership on complex security problems, make engineering trade-offs, and mentor engineers through constructive reviews.
- Help scale a virtualization platform and develop isolation technology used across endpoint security products.
Requirements
- Significant experience building, securing, and maintaining production software, ideally endpoint, security, or systems software.
- Strong programming experience in C, C++, Rust, Python, PowerShell, or comparable languages.
- Experience developing for Windows and/or Linux, including operating-system, virtualization, isolation, or other security-sensitive components.
- Strong experience with code review, debugging, unit and integration testing, continuous integration, build, and release workflows.
- Practical experience selecting, integrating, configuring, or improving static analysis tools and resolving their findings.
- Ability to work from the Cambridge office at least three days per week.
Nice to have
- Experience with secure software development lifecycle practices, threat modelling, secure design, vulnerability management, and release governance.
- Experience with vulnerability disclosure, severity assessment, remediation planning, and security updates.
- Experience leading technical initiatives and influencing teams without direct line-management authority.
- Excellent written and verbal communication skills with a collaborative and pragmatic approach.
Culture & Benefits
- Work within a highly skilled engineering and research-and-development organisation.
- Regular in-person collaboration is encouraged for this senior role.
- Modern Cambridge office with ergonomic workspaces and kitchen facilities.
- Work on security technology protecting millions of endpoints worldwide.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Software Engineering Specialist (Security)
12 дней назад
Application Security Engineer (Cybersecurity)
9 дней назад
Application Security Engineer (AI)
180 000 - 280 000$
12 дней назад
Senior Engineer, Software Security (AI)
10 дней назад
Staff Product Security Engineer (AI)
158 400 - 247 500CAD
14 дней назад