Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
BibliU

Senior Security Engineer

BibliU

. Own the engineering implementation and continuous improvement of security controls supporting SOC 2 Type II .

Posted 10/9/2026full-timeRemote • United KingdomSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in security engineering with a focus on SOC 2 Type II controls, cloud security (AWS), and compliance with GDPR and PCI DSS. Proficient in penetration testing, secure architecture, and integrating security practices into the software development lifecycle.

Highest-signal resume keywords
SOC 2 Type II ControlsCloud Security (AWS)Penetration TestingGDPR CompliancePCI DSS Requirements

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Penetration TestingSecure ArchitectureThreat ModellingApplication SecurityCloud SecurityContainer SecurityInfrastructure-as-CodeSecurity AutomationSecurity ToolingIncident Response
Soft Skills
Clear Written CommunicationInfluencing Without Authority
Tools & Technologies
SASTDASTCI/CDKubernetesOpenTofuSIEMLogging ToolsSecurity Automation Tools
Certifications & Qualifications
OSCPOSWEGWAPT
Industry Keywords
GDPRPCI DSSISO 27001SaaSAI SecurityIncident SimulationsChaos Engineering

Tech Stack

Tools & technologies
AWSCloudKubernetesSDLC

About the role

Key responsibilities & impact
  • Own the engineering implementation and continuous improvement of security controls supporting SOC 2 Type II
  • Work with IT on evidence collection and external audits
  • Act as the security partner in architecture and design reviews
  • Set secure-by-default patterns for new services, data flows, and integrations
  • Design and tune sandboxing and isolation models for AI-assisted and AI-generated code
  • Own offensive security testing across applications, cloud, and infrastructure
  • Validate remediation of internal and third-party findings
  • Maintain and extend GDPR and PCI DSS control posture
  • Collaborate with Legal, Finance, Engineering, and Platform Engineering on compliance and security controls
  • Tune security tooling and automation across the SDLC, including SAST, DAST, dependency and container scanning, IaC policy checks, and CI/CD gates
  • Lead threat modelling for high-risk services and AI features
  • Improve detection and response through logging coverage, alerting, runbooks, and incident response participation
  • Support customer and prospect security reviews, questionnaires, and due diligence
  • Raise the security baseline across engineering through guidance, tooling, and enablement

Requirements

What you’ll need
  • 5+ years in a security engineering, application security, or cloud security role, with meaningful time spent hands-on rather than purely advisory
  • Direct experience operating or contributing to SOC 2 Type II controls in a live environment, sustaining and evidencing controls over time
  • Practical penetration testing skills: web application, API, and cloud infrastructure testing
  • Strong cloud security background (AWS): IAM design, network segmentation, encryption, secrets management, and workload isolation
  • Working knowledge of PCI DSS requirements and how to scope, segment, and evidence a cardholder-data environment
  • Solid grasp of GDPR as it applies to engineering: lawful basis, data minimisation, retention, subject rights, cross-border transfers, and sub-processor management
  • Secure architecture and threat modelling experience across distributed, service-based systems
  • Strong hands-on engineering ability: reading application code, writing scripts and automation, and integrating security checks into CI/CD
  • Experience securing containerised workloads and infrastructure-as-code (Kubernetes, OpenTofu, or equivalents)
  • Ability to influence engineers and product teams without authority and make pragmatic risk trade-offs
  • Clear written communication for control documentation, findings, and customer-facing security responses
  • Experience securing AI/LLM systems, including prompt injection, tool-use and agent permissions, model and data exfiltration risks, RAG pipeline security, and evaluation of AI-generated code
  • Good to have: exposure to ISO 27001 or multi-framework compliance programmes
  • Good to have: offensive security certifications (OSCP, OSWE, GWAPT) or equivalent demonstrable experience
  • Good to have: detection engineering and SIEM experience
  • Good to have: familiarity with OWASP Top 10 for LLM Applications, NIST AI RMF, or ISO/IEC 42001
  • Good to have: experience in high-growth SaaS handling sensitive personal data at scale
  • Good to have: EdTech, accessibility, FERPA, or institutional procurement security review experience
  • Good to have: controlled security experiments, incident simulations, chaos engineering, or similar experience
  • Good to have: prior involvement in incident response for a real production incident
  • UK location/work authorization is implied by the stated UK remote location, but no explicit authorization requirement is provided

Benefits

Comp & perks
  • 35 days holiday per year (excluding public holidays!)
  • Your birthday off
  • 12 scheduled company wellness Fridays off per year
  • Enhanced maternity & paternity allowance
  • Flexible working hours
  • Work-from-home allowance
  • Cycle-to-work scheme (UK)
  • Life Insurance up to 4 x salary
  • Private health insurance
  • Annual eye test and up to £100 towards frames for glasses required for DSE work