Product Security Engineer

Product Security Engineer

Vollzeit 63000 - 77000 € / Jahr (geschätzt) Homeoffice (teilweise)
G

Auf einen Blick

  • Aufgaben: Arbeite mit Engineering-Teams zusammen, um Sicherheit in den Entwicklungsprozess zu integrieren.
  • Unternehmen: Genomics England, ein führendes Unternehmen im Bereich der Genommedizin.
  • Vorteile: 30 Tage Urlaub, flexible Arbeitszeiten und individuelle Lernbudgets.
  • Weitere Informationen: Dynamisches Arbeitsumfeld mit Möglichkeiten zur beruflichen Weiterentwicklung.
  • Warum dieser Job: Gestalte die Zukunft der Gesundheitsversorgung durch innovative Sicherheitslösungen.
  • Qualifikationen: Praktische Erfahrung in der Softwareentwicklung und Sicherheitsintegration.

Das prognostizierte Gehalt liegt zwischen 63000 - 77000 € pro Jahr.

As a Product Security Engineer, you will work as part of the Cyber Security team at Genomics England, partnering closely with engineering squads and product teams to integrate security into day‑to‑day delivery.

The purpose of this role is to bring security closer to where engineering decisions are made, enabling teams to adopt Genomics England's security standards in a practical and scalable way.

You will work directly with squads as a trusted partner, helping them build and deliver secure systems rather than acting as a central gatekeeper.

You will support teams to shift security left by contributing to secure design and development from the outset.

This includes helping teams implement security testing in CI/CD pipelines, improving vulnerability management within squads, and ensuring security issues are addressed as part of normal delivery.

Acting as a bridge between central security and delivery teams, you will translate security policies and risk expectations into clear, actionable engineering practices.

You will contribute to threat modelling, design discussions, and security reviews, helping teams break down complex security challenges into pragmatic technical solutions.

This is a hands‑on, product-embedded security role.

While it is not a platform or site reliability engineering position, it requires strong practical familiarity with cloud‑native systems, CI/CD pipelines and infrastructure‑as‑code to credibly influence design and implementation decisions within squads.

A key part of the role is enabling and scaling security capability through the Security Champions programme.

You will support and grow this community, helping champions build security knowledge and embed good practices within their teams.

Through this role, you will help evolve Genomics England towards a model where security is owned by engineering teams, with Cyber Security providing guidance, expertise, and enablement.

  • A strong foundation in cyber security engineering, including secure design principles and risk‑based decision making.
  • Practical experience embedding security into software development, including supporting shift‑left practices across design, development, and delivery.
  • Experience working hands‑on with engineering teams, with the ability to understand application architectures, review code or designs, and help troubleshoot security issues.
  • Experience integrating security controls into CI/CD pipelines, including code, dependency, and infrastructure‑as‑code scanning, with an emphasis on automation and developer experience.
  • Practical familiarity with public cloud environments, particularly AWS, including common security patterns and risks.
  • Experience working alongside Infrastructure‑as‑Code and delivery pipelines (e. g.

Terraform, Git Lab CI/CD or equivalent), with the ability to review and influence implementations.

  • Confidence engaging at an engineering level on designs, pipelines and configurations, even where you are not the primary implementer.
  • Solid understanding of vulnerability management, including helping teams interpret findings, prioritise remediation, and manage vulnerabilities as part of business‑as‑usual delivery.
  • Experience facilitating threat modelling and contributing to design reviews, helping teams identify and address security risks early in the development lifecycle.
  • Ability to translate security standards and policies into clear, actionable engineering guidance, patterns, and reusable approaches.
  • Experience working in modern engineering environments (e. g. cloud platforms, APIs, microservices, or containerised systems).
  • Strong communication and stakeholder‑management skills, with the ability to influence teams through collaboration rather than authority.
  • An interest in security education, enablement, and culture, including mentoring engineers and supporting security champions within teams.
  • This role does not require ownership of production platforms or central security tooling but does require the credibility to work closely with engineers and influence how security is implemented.

Qualifications are not essential for this role; practical experience working with engineering teams and embedding security into delivery is far more important.

  • However, the following certifications or areas of formal training may be beneficial:
  • Certifications or training in secure software development or application security (e. g. secure coding, secure SDLC, or application security practices).
  • Knowledge of cloud security principles, whether through formal certification or hands‑on experience.
  • Training in threat modelling, secure design, or security architecture.
  • Exposure to Dev Sec Ops practices, including integrating security into CI/CD pipelines.
  • Evidence of ongoing professional development in cyber security or software security, such as learning new tools, techniques, or contributing to security practices within teams.

Equivalent real-world experience enabling teams to adopt secure development practices, integrate security into CI/CD pipelines, and manage vulnerabilities effectively is considered equally valuable.

Genomics England is a global leader in enabling genomic medicine and research, focused on creating a world where everyone benefits from genomic healthcare.

Building on the 100,000 Genomes Project, we support the NHS's world‑first national whole genome sequencing service and run the growing National Genomic Research Library, alongside delivering numerous major genomics initiatives.

By connecting research and clinical care at national scale, we enable immediate healthcare benefits and advances for the future.

Our mission is to provide the evidence and digital systems so that by 2035 genomics could play a role in up to half of all healthcare interactions, whilst securing the UK's position as the best place to discover, prove and benefit from genomic innovations.

We are accelerating our impact and working with patients, doctors, scientists, government and industry to improve genomic testing, and help researchers access the health data and technology they need to make new medical discoveries and create more effective, targeted medicines for everybody.

We have four key behaviours that represent what we would like Genomics England to feel like and the culture we want to encourage, in order for us to achieve our mission.

These behaviours help us all work well together, deliver on our outcomes, celebrate our successes and share feedback with each other.

You can read about these and other aspects of our culture here Culture | Genomics England.

Genomics England operates a blended working model as we know our people appreciate the flexibility that hybrid working can bring.

We expect most people to come into the office a minimum of 2 times each month.

However, this will vary according to role and will be agreed with your team leader.

There is no expectation that people will return to the office full time unless they want to, however, some of our roles require full time on site attendance e. g., lab teams, reception team.

Our teams and squads have, and will continue to reflect on what works best for them to work together successfully and have the freedom to design working patterns to suit, beyond the minimum.

Our office locations are: Canary Wharf, Cambridge and Leeds.

Being an integral part of such a meaningful mission is extremely rewarding in itself, but in order to support our people, we're continually improving our benefits package.

We pride ourselves on investing in our people and supporting them to achieve their career goals, as well as offering a benefits package including:

  • Generous

Leave: 30 days' holiday, plus bank holidays, plus additional leave for long service, and also the option to apply for up to 30 days of remote working abroad annually (approval required).

  • Family‑Friendly: Blended working arrangements, flexible working, enhanced maternity, paternity and shared parental leave benefits.
  • Pension & Financial: Defined contribution pension (Genomics England double‑matches up to 10%, however you can contribute more if you wish), Life Assurance (3x salary), an Electric Vehicle salary sacrifice scheme and a Give As You Earn scheme.
  • Learning & Development: Individual learning budgets, support for training and certifications, and reimbursement for one annual professional subscription (approval required).
  • Recognition & Rewards: Employee recognition programme and referral scheme.
  • Health & Wellbeing: Subsidised gym membership, a free Headspace account, and access to an Employee Assistance Programme, eye tests, flu jabs.

Equal opportunities and our commitment to a diverse and inclusive workplace Genomics England is actively committed to providing and supporting an inclusive environment that promotes equity, diversity and inclusion best practice both within our community and in any other area where we have influence.

We are proud of our diverse community where everyone can come to work and feel welcomed and treated with respect regardless of any disability, ethnicity, gender, gender identity, religion, sexual orientation, or social background.

Genomics England's policies of non‑discrimination and equity and will be applied fairly to all people, regardless of age, disability, gender identity or reassignment, marital or civil partnership status, being pregnant or recently becoming a parent, race, religion or beliefs, sex or sexual orientation, length of service, whether full or part‑time or employed under a permanent or a fixed‑term contract or any other relevant factor.

Genomics England does not tolerate any form of discrimination, harassment, victimisation or bullying at work.

Such behaviour undermines our mission and core values and diminishes the dignity, respect and integrity of all parties.

Our People policies outline our commitment to inclusivity.

We aim to remove barriers in our recruitment processes and to be flexible with our interview processes.

Should you require any adjustments that may help you to fully participate in the recruitment process, we encourage you to discuss this with us.

#J-18808-Ljbffr

Product Security Engineer Arbeitgeber: Genomics England

Genomics England ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern die Möglichkeit bietet, an einer bedeutenden Mission im Bereich der Genommedizin und -forschung teilzuhaben. Mit einem flexiblen Arbeitsmodell, großzügigen Urlaubsregelungen und umfangreichen Weiterbildungsangeboten fördert das Unternehmen eine positive Arbeitskultur, in der Teamarbeit und persönliche Entwicklung im Vordergrund stehen. Die engagierte Unterstützung für Vielfalt und Inklusion sowie die Möglichkeit, in einem dynamischen Umfeld zu arbeiten, machen Genomics England zu einem attraktiven Arbeitsplatz für alle, die einen sinnvollen Beitrag leisten möchten.

G

Kontaktdaten:

Genomics England Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Product Security Engineer erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Genomics England kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Genomics England zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Genomics England.

Wir glauben, dass du diese Fähigkeiten brauchst, um Product Security Engineer mit Bravour zu bestehen

Communication Skills
SQL
Python
Problem-Solving Skills
Automation
Attention to Detail
Data Engineering

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei Genomics England vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Genomics England könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Genomics England sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird Genomics England auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!