Product Security Engineer

Role Summary

We are looking for a senior, hands-on security engineer to own the security of our AIVR product stack end to end. You will spend your time thinking like an attacker, finding weaknesses in our systems before anyone else does, and then coordinating with the engineering teams to remediate.

You will pull the architecture apart, work out the realistic attack paths, test them, prove what’s exploitable, explain the impact to the engineers who own them, help them work out a sensible fix, and then verify the fix.

This is a technical role in a team that likes getting things done. It is not a compliance or GRC position.

Your job is to make the product secure by continuously scouting for vulnerabilities and red teaming the AIVR product.

What You’ll Be Securing

  • Edge devices on trains. Embedded Linux devices with cameras and other sensors, fitted to in-service rolling stock. They are remote, physically outside our control, and connect back to us over 4G/5G.
  • AWS cloud platform. A comprehensive and complex data processing platform, including serverless and containerised services developed predominantly in Python and hosting 7+ PB of data.
  • Web applications. The AIVR web applications used across the rail industry, with multi-tenant workspaces, sharing tools and integrations.
  • Machine learning infrastructure. Training and inference workloads running in a 3rd party datacentre.

Responsibilities

  • Continuously red team our product stack: threat modelling, penetration testing, code and configuration review, and adversarial thinking applied across devices, cloud, applications and ML infrastructure.
  • Highlight findings and their impact. Work with the team that owns the system to explain findings and validate fixes.
  • Input into AWS security architecture with the Platform team: IAM, organisation and account structure, networking, encryption, logging and detection.
  • Evaluate device-side security with the Device team: secure boot and update signing, credential and certificate lifecycle, remote access, tamper and theft scenarios.
  • Harden the software supply chain: dependency and container vulnerability management, SBOMs, CI/CD pipeline integrity, and CVE exposure.
  • Build security into the way we ship: static and dynamic analysis, IaC and container scanning, secrets detection, and secure coding guidance that engineers will actually use.
  • Improve detection and response: make sure the right things are logged and alerted on and contribute hands-on when there is an incident. Incident response here is an all-hands affair; depending on the incident you may lead it or support whoever does.
  • Scope, run and challenge third party penetration tests, and triage reports that arrive through our vulnerability disclosure policy.
  • Document what you find and what you change in clear technical writing that engineers can act on and that feeds naturally into our ISO 27001 evidence and customer security assurance, without you having to run that process.
  • Raise the bar across the team through code review, threat modelling sessions and mentoring, so that security knowledge spreads rather than bottlenecking on you.

We want someone who is comfortable ranging across cloud, embedded, web and infrastructure in a single week. Nobody will have depth in every area below; we would rather have real depth in two or three and the curiosity to pick up the rest.

Essentials
  • Substantial hands-on security engineering experience (five or more years) in teams that ship software, with a strong offensive mindset.
  • Real software engineering ability. Comfortable in Python, and able to read and reason about C/C++ and JavaScript/TypeScript.
  • Deep, practical AWS security knowledge: IAM and Organizations, S3, VPC networking, CloudTrail, and infrastructure as code.
  • Strong Linux fundamentals, on both servers and embedded devices.
  • The ability to explain risk to developers, prioritise pragmatically, and be persistent when it matters.
Capability Areas

These describe the kinds of problems you will work on.

  • Cloud & Platform Security: AWS IAM design and review, permissions, SSO, credentials, secrets management, account segmentation, VPC and network controls, S3 data protection at scale, WAF, container and serverless security, infrastructure as code, CI/CD security, ransomware resilience and recovery testing.
  • Edge Device & Embedded Security: Embedded Linux hardening (Yocto or similar), secure boot, over-the-air updates, disk encryption, device identity and PKI, certificate lifecycle, VPN and remote access design, cellular connectivity, edge API security, physical attack and tamper scenarios, firmware analysis, OT security principles, secure device provisioning and decommissioning.
  • Application Security: OWASP Top 10 and beyond, authentication and session management, authorisation and multi-tenant isolation, API security, share link and token design, secure code review, browser security controls,SSO/OIDC integration.
  • Supply Chain & ML Infrastructure: Dependency and container vulnerability management, SBOM generation and tracking, CVE triage and prioritisation, artifact signing and provenance, pipeline integrity, datacentre network segmentation, ML framework exposure, data flows between datacentre and cloud.
  • Detection & Response: Logging strategy, alerting and SIEM concepts, threat hunting, incident response, forensics fundamentals, tabletop exercises, backup and recovery testing.
Nice to Have
  • Certifications such as OSCP, OSWE, CRTO or AWS Certified Security Specialty are welcome, but we care far more about demonstrable work than certifications.
  • Experience in rail, transport, utilities or other national infrastructure, and familiarity with the NCSC Cyber Assessment Framework, NIS regulations, ISO 27001 or IEC 62443.
  • Public evidence of your craft: CVEs, write-ups, open source tooling, bug bounty history or conference talks.

Personal Attributes

  • Curious and persistent: you enjoy working out how something can be made to misbehave.
  • Practical and delivery-focused, balancing security rigour with the reality of a relatively small team shipping frequent product updates.
  • Direct and constructive: you can tell an engineer their design is broken in a way that makes them want to fix it with you.
  • Self-motivated, comfortable owning an area without close supervision, and happy to flex across responsibilities in a growing company.
  • Strong written communication, able to produce findings and documentation that stand on their own.

You would be a valued part of a small but growing team where your ideas and opinions are valued as we continue the exciting journey of One Big Circle.

Company Benefits

How to Apply

Join an award-winning team, named ‘The Sunday Times Best Medium-sized Technology Company 2025’. At One Big Circle, you’ll be part of a fast-growing team where your ideas and contributions are truly valued.

Please send your CV and covering letter to jobs@onebigcircle.co.uk

By applying for this role, you understand that we will process your personal information in accordance with our privacy policy, accessible at https://onebigcircle.co.uk/privacy-policy/

Successful applicants will be required to pass a BPSS (Baseline Personnel Security Standard) check.