Junior Product Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Junior Product Security Engineer (Cybersecurity): Embedding security into the product development lifecycle and assisting with vulnerability management with an accent on secure-by-default practices and shift-left security. Focus on integrating security checks into CI/CD workflows, triaging automated tool findings, and collaborating with engineering teams to remediate risks.
Location: Hybrid (London) — Minimum 60% office attendance required over a 12-week period
Salary: £45,000 – £50,000
Company
Europe’s leading rail app enabling millions of travellers to book sustainable travel across 40+ countries.
What you will do
- Integrate security practices such as SAST, SCA, and secret scanning into CI/CD workflows to identify risks early.
- Triage and analyze security findings from automated tools and bug reports, partnering with developers for remediation.
- Participate in threat modeling sessions and maintain security documentation.
- Promote secure coding principles and support internal training for engineering teams.
- Align product security with frameworks such as OWASP, NIST, ISO 27001, GDPR, and PCI DSS.
Requirements
- Relevant education or practical experience in cybersecurity or software engineering.
- Understanding of security risks affecting applications, APIs, and distributed systems.
- Familiarity with SDLC, secure coding principles, and threat modeling concepts.
- Exposure to security testing approaches like SAST or DAST.
- Basic programming or scripting skills in Python, JavaScript, or similar.
- Ability to collaborate with engineers and communicate security concerns clearly.
Nice to have
- Bachelor's degree in Computer Science, Cybersecurity, or a related technical field.
- Experience with tools such as Burp Suite, OWASP ZAP, Semgrep, Checkmarx, or Snyk.
- Familiarity with AWS and API security testing.
- Exposure to AI or martech ecosystems.
Culture & Benefits
- Private healthcare and dental insurance.
- Work from abroad policy allowing up to 28 days per year.
- Personal learning budgets, regular learning days, and professional development opportunities.
- 2-for-1 share purchase plans and an EV Scheme.
- Extra festive time off and family-friendly benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →