This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a security-minded engineer to join our Tech Foundations team. This isn't a traditional InfoSec role where you'll be auditing from the outside. Instead, your mission is to be the security champion within the Platform team. The Foundation teams build the "paved road" for all engineers at our company, creating the tools and infrastructure that empower our product teams to ship secure software, fast with very little friction. You will be a builder, embedding security directly into the fabric of our platform and making "shifting left" a practical reality. This is a unique opportunity to own the security from the ground up, ensuring our tools and infrastructure are secure by default. You'll get to partner closely with our central InfoSec team for strategic guidance while being technically responsible for implementing security solutions as a member of the Platform team. You’ll help the team spot potential vulnerabilities before they reach production and coach engineers on secure coding practices.
Job Responsibility:
Architect Secure Foundations: help the platform team to own the security of our developer platform, including designing, building, and maintaining security controls and services within our CI/CD pipelines
Secure Our Infrastructure as Code (IaC): Partner with your Platform teammates to be the subject matter expert for securing our Terraform modules and cloud environments (AWS, Azure), focusing on preventing misconfigurations before they're deployed
Incident Response and Operations: Participate in the team's on-call rotation, including out-of-hours coverage to support platform availability and security, assist in troubleshooting critical issues, lead the response for security-specific incidents, drive post-mortems focused on learning and preventing recurrence
Build a Secure "Paved Road": Seamlessly integrate and orchestrate security testing (SAST, DAST, SCA, container scanning) into developer workflows
Enable Vulnerability Remediation: Develop tools and processes to help engineering teams triage, prioritise, and remediate vulnerabilities
Implement Platform-Level Detection: Leverage our cloud security and observability platforms to build robust, automated threat detection and response capabilities for the platform itself
Be a Security Partner: In partnership with Infosec team, act as a primary security consultants for our developers, provide expert guidance on secure coding (Elixir, TypeScript/Node, Python), secret management, and securing our event-driven architecture and AI services
Govern Emerging Technologies: Help architect and implement our AI Management System, ensuring our innovative AI services are built on a secure foundation that meets governance standards like ISO42001
Requirements:
A "Builder" Mindset: strong coding and scripting skills (e.g., Python, TypeScript/Node) and a passion for automating everything
Cloud & Infrastructure Experience: experience building and securing modern cloud-native infrastructure, including CI/CD pipelines (like GitHub Actions), cloud environments (AWS/Azure), and Infrastructure as Code (like Terraform)
Application Security Knowledge: solid understanding of the AppSec landscape and practical experience integrating tools (SAST, DAST, SCA) into developer workflows
A Collaborative Partner: excellent communication skills, enjoy collaborating with engineering teams and translating complex security concepts into clear guidance
Observability-Driven: experience using security and monitoring platforms (like Datadog) to detect and respond to threats
Familiarity with securing AI/ML pipelines or services
Relevant industry certifications (e.g., AWS Certified Security - Specialty, AZ-500)
What we offer:
Time off - 27 days holiday, plus 5 additional days off: 1 life event day, 2 volunteer days, 2 company-wide wellbeing days (M-Powered Weekend) and 8 bank holidays per year
Health & Wellness- private medical Insurance with Bupa, a medical cashback scheme, life insurance, gym membership & wellness resources through Wellhub and access to Spill - all in one mental health support
Hybrid work offering - for most roles we collaborate in the office three days per week
Work-from-anywhere scheme - you'll have the opportunity to work from anywhere, up to 10 days per year
Space to connect: Beyond the desk, we make time for weekly catch-ups, seasonal celebrations, and have a kitchen that’s always stocked!