What we are looking for
You are first and foremost a strong engineer.
You have significant experience building or securing production software and distributed systems. You are comfortable reading and writing production code, designing systems and working directly with Engineering teams.
You have deep security engineering expertise and strong experience in several of the following areas:
Application and Product Security
API Security
IAM, authentication and authorization
OAuth2 / OIDC, WebAuthn / FIDO2
RBAC / ABAC and privilege management
Cloud security
Cryptography, KMS / HSM and envelope encryption
Tokenisation and secrets management
Data Security and Privacy Engineering
Threat modelling and secure software architecture
Security monitoring and detection
Stronger attacker mindset
You naturally ask:
What happens if this employee becomes malicious?
What happens if this backend is compromised?
What happens if someone dumps this database?
Can this endpoint be called directly?
How much data can one account access before we notice?
Where else does this information get replicated?
Why do we have this data at all?
You think in terms of attack paths, blast radius and least privilege, not just compliance requirements.
Pragmatism
You know that security engineering is a prioritisation problem.
You can distinguish between:
something that needs to be fixed this week;
something that requires an architectural redesign;
something cryptographically elegant but operationally unnecessary.
You are comfortable deploying simple, high-impact controls quickly while designing stronger long-term foundations.
What would make you stand out
Experience with:
large-scale SaaS or fintech platforms;
highly sensitive or regulated data;
multi-tenant architectures;
insider risk or data-loss prevention;
advanced cryptographic or privacy-enhancing technologies.
What success looks like
Sensitive data is exposed to fewer systems and people.
Access to sensitive resources is increasingly scoped, attributable and auditable.
Compromising a single account or service has a limited blast radius.
Security controls are increasingly enforced by the platform rather than by process.
Product teams can build secure systems faster and with less friction.
What this role is not
This is not primarily a GRC, SOC, compliance, policy-writing or penetration-testing role.
Those disciplines are important, but this role exists to change how our products and systems are engineered.
We expect this person to design systems, write code, influence architecture and ship security capabilities into production.