Назад
Company hidden
обновлено 3 дня назад

Senior Product Security Engineer

90 000 - 100 000GBP
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (Application, Mobile and API Security): Defining and delivering product security roadmaps, vulnerability management, threat modeling, and security testing for web, mobile, and API services with an accent on secure-by-design engineering and resilience. Focus on securing iOS and Android applications, automating SAST/DAST and vulnerability scanning, managing penetration tests, and embedding security practices across CI/CD and cloud-native environments.

Location: London, United Kingdom; hybrid, with office attendance required for a minimum of 60% of working time over a 12-week period

Salary: £90K–£100K per year

Company

hirify.global is a European rail and coach booking platform connecting travellers with rail carriers, fares, and journey options through its app, website, and B2B partner channels.

What you will do

  • Define and own the product security roadmap, aligning priorities with business goals and influencing engineering leadership.
  • Establish and manage application security vulnerability management, including triage, prioritisation, remediation tracking, MTTR reporting, and security testing coverage.
  • Perform threat modelling and security reviews for web, mobile, and API services, identifying risks and implementing countermeasures.
  • Assess application and API security through code reviews, SAST, DAST, vulnerability scanning, and third-party penetration testing.
  • Strengthen iOS and Android applications and their APIs, including authentication, authorisation, secure data storage, API gateway controls, and abuse prevention.
  • Automate security tooling, mentor engineering teams, support secure coding practices, and grow a security champions programme.

Requirements

  • Significant experience identifying, assessing, and mitigating security risks across application design, code, and deployed products.
  • Experience delivering product or application security roadmaps, influencing engineering leaders, and using metrics to demonstrate risk reduction.
  • Experience securing mobile applications and APIs, including iOS and Android testing and OAuth 2.0 or OpenID Connect.
  • Hands-on experience with SAST, DAST, vulnerability scanning, threat modelling, security reviews, and third-party penetration testing.
  • Experience embedding secure coding and technical controls into CI/CD workflows, preferably in cloud-native, containerised, and IaC environments.
  • Familiarity with OWASP, PCI DSS, ISO 27001, GDPR, and related security frameworks.

Nice to have

  • Experience with mobile application security testing and API security testing tools.
  • Experience establishing or growing a security champions programme.
  • Experience with risk assessments and regulatory compliance standards.

Culture & Benefits

  • Hybrid working with a 28-day work-from-abroad policy.
  • Private healthcare and dental insurance, family-friendly benefits, and extra festive time off.
  • Personal learning budgets, regular learning days, clear career paths, and transparent pay bands.
  • Two-for-one share purchase plans and an electric vehicle scheme.
  • Inclusive working environment focused on diversity, collaboration, ownership, and sustainable travel.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →