Назад
Company hidden
7 дней назад

Principal Security Software Engineer (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security Software Engineer (Cybersecurity): Improving secure software development processes for endpoint security products with an accent on EU Cyber Resilience Act compliance, static analysis, vulnerability management, and security-by-design. Focus on integrating security tools into development workflows, strengthening software assurance, and solving complex security problems across Windows, Linux, virtualization, and isolation components.

Location: Cambridge, Cambridgeshire, United Kingdom; hybrid working with a minimum of three onsite days per week

Company

Develops endpoint security products that combine hardware, firmware, software, cloud-connected services, and micro-virtualization to protect devices and data from advanced malware.

What you will do

  • Lead improvements to the secure software development lifecycle in line with European Union Cyber Resilience Act expectations.
  • Integrate and improve static analysis tools across development and build workflows, including rules, policies, triage, false-positive management, and remediation tracking.
  • Promote security-by-design and secure-by-default practices through threat modelling, design reviews, architecture guidance, and secure coding.
  • Improve vulnerability identification, assessment, documentation, remediation, and measurement throughout the software development lifecycle.
  • Provide technical leadership on complex security problems, make engineering trade-offs, and mentor engineers through constructive reviews.
  • Help scale a virtualization platform and develop isolation technology used across endpoint security products.

Requirements

  • Significant experience building, securing, and maintaining production software, ideally endpoint, security, or systems software.
  • Strong programming experience in C, C++, Rust, Python, PowerShell, or comparable languages.
  • Experience developing for Windows and/or Linux, including operating-system, virtualization, isolation, or other security-sensitive components.
  • Strong experience with code review, debugging, unit and integration testing, continuous integration, build, and release workflows.
  • Practical experience selecting, integrating, configuring, or improving static analysis tools and resolving their findings.
  • Ability to work from the Cambridge office at least three days per week.

Nice to have

  • Experience with secure software development lifecycle practices, threat modelling, secure design, vulnerability management, and release governance.
  • Experience with vulnerability disclosure, severity assessment, remediation planning, and security updates.
  • Experience leading technical initiatives and influencing teams without direct line-management authority.
  • Excellent written and verbal communication skills with a collaborative and pragmatic approach.

Culture & Benefits

  • Work within a highly skilled engineering and research-and-development organisation.
  • Regular in-person collaboration is encouraged for this senior role.
  • Modern Cambridge office with ergonomic workspaces and kitchen facilities.
  • Work on security technology protecting millions of endpoints worldwide.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →