Cambridge University Press & Assessment
Cambridge, UK
Security Assurance Lead
Salary: £54,800 - £73,250
Location: Cambridge/ Hybrid with 2 days a week minimum in the office
Contract: Permanent
Hours: 35 hours per week
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role.
We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.
About the role
As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working.
This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment.
Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement.
Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure.
Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery.
Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported.
Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST.
Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders.
Support incident preparedness, including investigations and exercises that test our ability to respond effectively.
Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation.
This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition.
About You
We are looking for someone with extensive knowledge and 5+ years of experience in security testing and assurance, and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks (e.g. ISO 27001, NIST) and risk management practices.
You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing.
You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management.
You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously.
If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria:
Development and maintained a supply chain risk register within a similar sized organisation
Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc
Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure
Experience of reporting risks to senior leadership
For a detailed job description, please refer to the link at the bottom of the advert on our careers site.
We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition.
Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for.
Rewards and benefits
We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including:
28 days annual leave plus bank holidays
Private medical and Permanent Health Insurance
Discretionary annual bonus
Group personal pension scheme
Life assurance up to 4 x annual salary
Green travel schemes
Ready to pursue your potential? Apply now.
We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after.
The application and interview process consists of:
3 role related questions with brief answers
A 15-minute screening call with the Hiring Manager.
First stage virtual interview via MS Teams.
Final stage interview: in-person at our offices in Cambridge.
If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs.
Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.
We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter.
Why join us
Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe – for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration.
Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background.
We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Security Assurance Lead
Salary: £54,800 - £73,250
Location: Cambridge/ Hybrid with 2 days a week minimum in the office
Contract: Permanent
Hours: 35 hours per week
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role.
We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.
About the role
As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working.
This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment.
Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement.
Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure.
Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery.
Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported.
Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST.
Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders.
Support incident preparedness, including investigations and exercises that test our ability to respond effectively.
Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation.
This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition.
About You
We are looking for someone with extensive knowledge and 5+ years of experience in security testing and assurance, and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks (e.g. ISO 27001, NIST) and risk management practices.
You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing.
You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management.
You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously.
If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria:
Development and maintained a supply chain risk register within a similar sized organisation
Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc
Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure
Experience of reporting risks to senior leadership
For a detailed job description, please refer to the link at the bottom of the advert on our careers site.
We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition.
Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for.
Rewards and benefits
We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including:
28 days annual leave plus bank holidays
Private medical and Permanent Health Insurance
Discretionary annual bonus
Group personal pension scheme
Life assurance up to 4 x annual salary
Green travel schemes
Ready to pursue your potential? Apply now.
We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after.
The application and interview process consists of:
3 role related questions with brief answers
A 15-minute screening call with the Hiring Manager.
First stage virtual interview via MS Teams.
Final stage interview: in-person at our offices in Cambridge.
If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs.
Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.
We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter.
Why join us
Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe – for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration.
Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background.
We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
AllegisCyber Capital
Synack's Penetration Testing as a Service platform manages customers' attack surfaces by discovering new assets, pentesting for critical vulnerabilities and gaining visibility into the root causes of security risks. We are committed to making the world more secure by harnessing a talented, vetted community of security researchers to deliver continuous penetration testing and vulnerability management, with actionable results. Synack's PTaaS platform has uncovered more than 71,000 exploitable vulnerabilities to date, protecting a growing list of Global 2000 customers and U.S. agencies in a FedRAMP Moderate Authorized environment. For more information, please visit . We are looking for a Senior Software Engineer (AI), where you'll design and ship AI agents that plan, reason, drive security tooling and surface exploitable vulnerabilities, running autonomously inside sandboxed environments. It's a hands on senior role spanning applied AI and cybersecurity. You'll own systems end to end and raise the technical bar for the team around you. Sounds interesting? Keep reading Please note: This is a remote position based in the UK. We can only hire citizens of the United Kingdom for this role. Given the nature of the work, the role may be subject to nationality, residency and security clearance checks. Here's what you'll do Build AI agents that automate penetration testing: planning, tool use, reasoning over findings, and acting safely within scope. Stand up and run the sandboxed cyber lab and range infrastructure, containerised on Kubernetes, where these agents execute offensive tooling. Ship features from ideation through production, including evals, guardrails and monitoring. Improve how our agents work: prompting, tool orchestration, evaluation, and cost. Lead code reviews and design sessions, and help the engineers around you grow. Work closely with our security researchers to translate how they hack into how our agents operate. Here's what you'll need 4+ years of software engineering experience Proven ability to build and scale production systems Strong Python, polyglot codebase Fluent or willing to learn Go Hands-on experience building and operating production AI applications using LLMs and agentic frameworks (e.g., RAG, MCP, LangGraph or similar), including tool integration, prompt design, evaluation, guardrails, and token/cost optimization. Demonstrate ability to create reliable agents (prompting, evaluation, guardrails, understanding of token and cost optimization Capable leveraging Docker, Kubernetes, isolated sandbox, cloud experience GCP preferred Brings a disciplined testing approach to microservices gPRC, API design, async messaging (Pub/Sub, Kafka) Passionate desire to understand how systems get compromised Clear communication Collaborative ability to partner across teams Nice To Have Offensive security experience: penetration testing, red teaming, CTF, or security tooling. Experience driving security tools programmatically or automating an attack chain. Startup experience, where scope is broad and priorities move fast. Ready to join us? Synack is committed to embracing diversity. Our people are our strength. Each addition to our team is an opportunity to grow and diversify our ideas, experiences, and viewpoints. We strive to be inclusive of Race, Ethnicity, Religion, Sex, LGBTQ+, Veterans, Disabilities, and Age. Synack welcomes you! As a candidate, Synack cares about your privacy. Please view our candidate privacy policy. This position has responsibility to ensure Synack's security and privacy posture is maintained. Salary is determined by a combination of factors including location, level, relevant experience, and skills. The compensation package for this position may also include equity, and benefits. For more details about our benefits, please see our benefits overview. Then for the Employer code, enter: synack
Synack's Penetration Testing as a Service platform manages customers' attack surfaces by discovering new assets, pentesting for critical vulnerabilities and gaining visibility into the root causes of security risks. We are committed to making the world more secure by harnessing a talented, vetted community of security researchers to deliver continuous penetration testing and vulnerability management, with actionable results. Synack's PTaaS platform has uncovered more than 71,000 exploitable vulnerabilities to date, protecting a growing list of Global 2000 customers and U.S. agencies in a FedRAMP Moderate Authorized environment. For more information, please visit . We are looking for a Senior Software Engineer (AI), where you'll design and ship AI agents that plan, reason, drive security tooling and surface exploitable vulnerabilities, running autonomously inside sandboxed environments. It's a hands on senior role spanning applied AI and cybersecurity. You'll own systems end to end and raise the technical bar for the team around you. Sounds interesting? Keep reading Please note: This is a remote position based in the UK. We can only hire citizens of the United Kingdom for this role. Given the nature of the work, the role may be subject to nationality, residency and security clearance checks. Here's what you'll do Build AI agents that automate penetration testing: planning, tool use, reasoning over findings, and acting safely within scope. Stand up and run the sandboxed cyber lab and range infrastructure, containerised on Kubernetes, where these agents execute offensive tooling. Ship features from ideation through production, including evals, guardrails and monitoring. Improve how our agents work: prompting, tool orchestration, evaluation, and cost. Lead code reviews and design sessions, and help the engineers around you grow. Work closely with our security researchers to translate how they hack into how our agents operate. Here's what you'll need 4+ years of software engineering experience Proven ability to build and scale production systems Strong Python, polyglot codebase Fluent or willing to learn Go Hands-on experience building and operating production AI applications using LLMs and agentic frameworks (e.g., RAG, MCP, LangGraph or similar), including tool integration, prompt design, evaluation, guardrails, and token/cost optimization. Demonstrate ability to create reliable agents (prompting, evaluation, guardrails, understanding of token and cost optimization Capable leveraging Docker, Kubernetes, isolated sandbox, cloud experience GCP preferred Brings a disciplined testing approach to microservices gPRC, API design, async messaging (Pub/Sub, Kafka) Passionate desire to understand how systems get compromised Clear communication Collaborative ability to partner across teams Nice To Have Offensive security experience: penetration testing, red teaming, CTF, or security tooling. Experience driving security tools programmatically or automating an attack chain. Startup experience, where scope is broad and priorities move fast. Ready to join us? Synack is committed to embracing diversity. Our people are our strength. Each addition to our team is an opportunity to grow and diversify our ideas, experiences, and viewpoints. We strive to be inclusive of Race, Ethnicity, Religion, Sex, LGBTQ+, Veterans, Disabilities, and Age. Synack welcomes you! As a candidate, Synack cares about your privacy. Please view our candidate privacy policy. This position has responsibility to ensure Synack's security and privacy posture is maintained. Salary is determined by a combination of factors including location, level, relevant experience, and skills. The compensation package for this position may also include equity, and benefits. For more details about our benefits, please see our benefits overview. Then for the Employer code, enter: synack
JPMorgan Chase & Co.
Embrace this pivotal role as an essential member of a high performing team dedicated to reaching new heights in data engineering. Your contributions will be instrumental in shaping the future of one of the world's largest and most influential companies. As a Senior Lead Data Engineer at JPMorganChase within the Behavioral Insights Team, you will turn operational signals and platform data into actionable insights that improve reliability, risk/control health, and delivery efficiency. You will own the reliability and performance of reporting and analytics pipelines, define and govern SLIs/SLOs and error budgets, and automate data products (dashboards, scheduled reporting, and near-real-time views) that serve engineering, risk, and business stakeholders. You will also manage and mentor team members and uphold rigorous data management practices and controls. Job Responsibilities Change and release health - Track deployment frequency, change failure rate, lead time, and rollbacks; correlate changes to incidents/SLO impact; influence safer release practices. Capacity, performance, and scalability - Produce capacity forecasts, headroom and hotspot reporting; partner with engineering to validate scaling policies and performance budgets. FinOps and cost observability - Report spend by service/team/env; track unit economics (e.g., cost per transaction), rightsizing opportunities, commitment utilization, and tag compliance; highlight reliability-cost tradeoffs. Risk and controls compliance - Evidence guardrail adherence and control health (backup/restore posture, DR testing, patch/vulnerability closure, config drift); ensure metrics lineage and audit readiness. Uses enterprise-authorized AI capabilities within the work environment to accelerate data platform and design analysis and technical documentation, validating outputs and handling data according to sensitivity and security requirements. Data risk and controls - Monitor adherence to risk and control guidelines for data access and use. Data quality, reliability, and lineage - Define data contracts for telemetry sources; implement validation, anomaly detection, and reconciliation; document definitions (e.g., formulas, thresholds) and end-to-end data lineage from raw signals to KPIs and insights. Automation and self service - Deliver automated pipelines for scheduled reporting and near-real-time dashboards; enable RBAC controlled self service for teams and leadership. Stakeholder cadences and communication - Lead weekly reliability reviews and monthly leadership reviews; maintain action logs to closure; escalate risks early with data driven recommendations. People leadership - oversee workflow, prioritization, and delivery for junior data engineers and visualization researchers; mentor and support upskilling and career development. Applies reuse-first, AI-assisted practices within delivery and operational routines (e.g., validation automation and access control review support), ensuring traceability/auditability and alignment to resiliency and security expectations. Required qualifications, capabilities, and skills Formal training or certification on data engineering concepts and advanced applied experience in data analytics/BI/ operations analytics. Strong SQL skills (CTEs, window functions, performance-aware querying). Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support data engineering workflows with strong validation habits and awareness of data sensitivity. Ability to review and validate AI-assisted outputs (e.g., model and design summaries or validation recommendations) before use, escalating when uncertain and following data handling requirements. Hands-on experience building dashboards in Tableau/Power BI/Looker (or similar). Experience working with ITSM tools (e.g., ServiceNow or similar) and understanding incident/change/problem concepts. Strong data storytelling skills; ability to translate operational findings into practical improvements. Preferred qualifications Experience working with AWS and core concepts (accounts, regions, IAM, networking, compute/storage, tagging). Python for analytics/automation (e.g., pandas) and building repeatable pipelines. Experience with cloud data platforms (e.g., Snowflake/Redshift/BigQuery) and ELT tooling (e.g., dbt).
Embrace this pivotal role as an essential member of a high performing team dedicated to reaching new heights in data engineering. Your contributions will be instrumental in shaping the future of one of the world's largest and most influential companies. As a Senior Lead Data Engineer at JPMorganChase within the Behavioral Insights Team, you will turn operational signals and platform data into actionable insights that improve reliability, risk/control health, and delivery efficiency. You will own the reliability and performance of reporting and analytics pipelines, define and govern SLIs/SLOs and error budgets, and automate data products (dashboards, scheduled reporting, and near-real-time views) that serve engineering, risk, and business stakeholders. You will also manage and mentor team members and uphold rigorous data management practices and controls. Job Responsibilities Change and release health - Track deployment frequency, change failure rate, lead time, and rollbacks; correlate changes to incidents/SLO impact; influence safer release practices. Capacity, performance, and scalability - Produce capacity forecasts, headroom and hotspot reporting; partner with engineering to validate scaling policies and performance budgets. FinOps and cost observability - Report spend by service/team/env; track unit economics (e.g., cost per transaction), rightsizing opportunities, commitment utilization, and tag compliance; highlight reliability-cost tradeoffs. Risk and controls compliance - Evidence guardrail adherence and control health (backup/restore posture, DR testing, patch/vulnerability closure, config drift); ensure metrics lineage and audit readiness. Uses enterprise-authorized AI capabilities within the work environment to accelerate data platform and design analysis and technical documentation, validating outputs and handling data according to sensitivity and security requirements. Data risk and controls - Monitor adherence to risk and control guidelines for data access and use. Data quality, reliability, and lineage - Define data contracts for telemetry sources; implement validation, anomaly detection, and reconciliation; document definitions (e.g., formulas, thresholds) and end-to-end data lineage from raw signals to KPIs and insights. Automation and self service - Deliver automated pipelines for scheduled reporting and near-real-time dashboards; enable RBAC controlled self service for teams and leadership. Stakeholder cadences and communication - Lead weekly reliability reviews and monthly leadership reviews; maintain action logs to closure; escalate risks early with data driven recommendations. People leadership - oversee workflow, prioritization, and delivery for junior data engineers and visualization researchers; mentor and support upskilling and career development. Applies reuse-first, AI-assisted practices within delivery and operational routines (e.g., validation automation and access control review support), ensuring traceability/auditability and alignment to resiliency and security expectations. Required qualifications, capabilities, and skills Formal training or certification on data engineering concepts and advanced applied experience in data analytics/BI/ operations analytics. Strong SQL skills (CTEs, window functions, performance-aware querying). Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support data engineering workflows with strong validation habits and awareness of data sensitivity. Ability to review and validate AI-assisted outputs (e.g., model and design summaries or validation recommendations) before use, escalating when uncertain and following data handling requirements. Hands-on experience building dashboards in Tableau/Power BI/Looker (or similar). Experience working with ITSM tools (e.g., ServiceNow or similar) and understanding incident/change/problem concepts. Strong data storytelling skills; ability to translate operational findings into practical improvements. Preferred qualifications Experience working with AWS and core concepts (accounts, regions, IAM, networking, compute/storage, tagging). Python for analytics/automation (e.g., pandas) and building repeatable pipelines. Experience with cloud data platforms (e.g., Snowflake/Redshift/BigQuery) and ELT tooling (e.g., dbt).
Entrust Corporation
Cambridge, Cambridgeshire
Position Overview The Staff Product Security Engineer is a senior technical leader responsible for defining and driving the security strategy, architecture, and engineering practices across Entrust's cryptographic product portfolio. This role provides technical leadership beyond individual products, influencing security decisions across multiple engineering teams and ensuring security is embedded throughout the entire product lifecycle. The Staff Product Security Engineer serves as a recognized security subject matter expert, partnering with product management, engineering leadership, certification teams, and executive stakeholders to establish security roadmaps, enhance security capabilities, and address emerging threats. This role combines deep technical expertise in software, hardware, and cryptographic security with strong leadership and mentoring capabilities. You will lead complex security initiatives, establish engineering standards, drive security architecture reviews, and guide teams in adopting secure-by-design principles. You will also represent security engineering in customer engagements, security audits, certification activities, and interactions with external security researchers and industry experts. A strong background in mathematics, engineering, computer science, or information security is essential. The successful candidate will demonstrate a proven ability to influence technical direction, solve highly complex security challenges, and drive security excellence across the organization. Responsibilities Technical Leadership & Strategy Define and drive product security strategy, architecture principles, and security engineering roadmaps across multiple products and platforms. Lead the security architecture review process for new products, major feature developments, and platform changes. Establish and evolve secure development standards, security design patterns, and engineering best practices. Serve as the primary technical authority for complex security architecture decisions and risk-based security trade-off discussions. Drive strategic security initiatives that improve security posture, development efficiency, and regulatory readiness across the organization. Anticipate emerging threats, industry trends, and regulatory requirements and translate these into actionable engineering improvements. Product Security Engineering Collaborate with cross-functional teams to integrate security requirements into product design, development, deployment, and maintenance processes. Lead threat modeling activities for critical systems, products, and architectures. Conduct and oversee advanced security assessments, vulnerability investigations, attack surface analyses, and risk evaluations. Design, implement, and review security controls, cryptographic protections, and system hardening mechanisms. Lead investigations of critical security issues and provide technical direction for remediation efforts. Guide secure design reviews and code review activities for business-critical products. Security Tooling & Automation Define and drive the security tooling strategy across software and hardware development environments. Lead the development and adoption of advanced security testing capabilities, including fuzzing, software composition analysis (SCA), static analysis, dynamic analysis, memory safety validation, and vulnerability discovery tooling. Partner with DevOps and engineering teams to embed security automation and policy enforcement into CI/CD processes. Improve vulnerability detection, triage, and remediation workflows through automation and data-driven approaches. Security Governance & Risk Management Establish scalable approaches for vulnerability management, risk assessment, and security assurance across multiple product lines. Provide technical leadership during security incidents, vulnerability disclosures, and coordinated remediation efforts. Support product compliance and certification initiatives including FIPS 140-3, Common Criteria, PCI HSM, Cyber Resilience Act (CRA), and other applicable security standards. Review and approve security exceptions, risk acceptance decisions, and compensating controls where appropriate. Collaboration & External Engagement Act as a trusted advisor to engineering leaders, architects, product managers, and executive stakeholders. Represent Entrust in customer security discussions, security reviews, certification engagements, and external assessments. Collaborate with external researchers, independent laboratories, certification bodies, and security consultants. Contribute to industry working groups, standards development efforts, and security communities where appropriate. Mentoring & Organizational Impact Mentor senior engineers and security practitioners, fostering technical excellence across the organization. Lead technical communities of practice focused on secure development and product security. Influence engineering culture by promoting security-first thinking and secure-by-design principles. Provide technical leadership during strategic planning, architecture reviews, and product roadmap discussions. Help identify security skill gaps and contribute to workforce development initiatives. Technical Knowledge / Skills and Experience Required Extensive experience in product security, security architecture, or security engineering roles. Demonstrated experience providing technical leadership across multiple teams, products, or business units. Deep expertise in applied cryptography, cryptographic protocols, and security architectures. Strong understanding of secure software development and software assurance practices. Strong understanding of hardware security, embedded systems security, trusted execution environments, and FPGA security concepts. Advanced knowledge of threat modeling methodologies and risk assessment frameworks. Experience leading large-scale vulnerability management and remediation programs. Expertise with security assessment methodologies, penetration testing techniques, and offensive security concepts. Experience building or deploying security tooling integrated into modern software development pipelines. Strong programming capability in Python, C/C++, Go, Rust, Java, or similar languages. Experience supporting or leading security certification activities including FIPS 140-3, Common Criteria, PCI HSM, or equivalent frameworks. Strong understanding of modern regulatory and compliance requirements impacting product security, including CRA, NIS2, and secure development frameworks. Excellent communication skills with demonstrated ability to influence executive stakeholders and technical teams. Proven ability to drive organizational change through technical leadership and influence. Qualifications: Bachelor's degree in Computer Science, Information Security, Electrical Engineering, Mathematics, or related discipline. Master's degree preferred. Relevant security certifications (CISSP, CSSLP, OSCP, GIAC, CCSP, SABSA, or similar) are desirable. Demonstrated track record of leading complex security initiatives with organization-wide impact. At Entrust, we don't just offer jobs - we offer career journeys. Here is what you can expect when you join our team: Career Growth: Whether you're a budding developer or a seasoned expert, we're invested in your professional journey. With learning-forward initiatives and exciting challenges, your growth is our priority. Flexibility: Life is all about balance. Whether you're remote, hybrid, or on-site, we offer flexible options that fit your lifestyle. Collaboration: Here, your voice matters. Our teams thrive on sharing ideas, brainstorming solutions, and working together to build a better tomorrow. We believe in securing identities-but it doesn't stop there. At Entrust, we're passionate about valuing all identities. Our culture is built on diversity, inclusion, and respect. From unconscious bias training for our leaders to global affinity groups that connect colleagues across the globe, we're creating a community where everyone is encouraged to be themselves. Ready to Make an Impact? If you're excited by the prospect of innovating, growing your career, and collaborating in a dynamic environment, Entrust is the place for you. Join us in making a difference. Let's build a more secure world-together. Apply today! For more information, visit . Follow us on, LinkedIn, Facebook, Instagram, and YouTube For US roles, or where applicable: Entrust is an EEO/AA/Disabled/Veterans Employer For Canadian roles, or where applicable: Entrust values diversity and inclusion and we are committed to building a diverse workforce with wide perspectives and innovative ideas. We welcome applications from qualified individuals of all backgrounds, and we strive to provide an accessible experience for candidates of all abilities. If you require an accommodation, contact . Recruiter: Jack Steib Entrust is an innovative leader in identity-centric security solutions, providing an integrated platform of scalable, AI-enabled security offerings. We enable organizations to safeguard their operations, evolve without compromise, and protect their interactions in an interconnected world - so they can transform their businesses with confidence. Entrust supports customers in 150+ countries and works with a global partner network, we are trusted by the world most trusted organizations.
Position Overview The Staff Product Security Engineer is a senior technical leader responsible for defining and driving the security strategy, architecture, and engineering practices across Entrust's cryptographic product portfolio. This role provides technical leadership beyond individual products, influencing security decisions across multiple engineering teams and ensuring security is embedded throughout the entire product lifecycle. The Staff Product Security Engineer serves as a recognized security subject matter expert, partnering with product management, engineering leadership, certification teams, and executive stakeholders to establish security roadmaps, enhance security capabilities, and address emerging threats. This role combines deep technical expertise in software, hardware, and cryptographic security with strong leadership and mentoring capabilities. You will lead complex security initiatives, establish engineering standards, drive security architecture reviews, and guide teams in adopting secure-by-design principles. You will also represent security engineering in customer engagements, security audits, certification activities, and interactions with external security researchers and industry experts. A strong background in mathematics, engineering, computer science, or information security is essential. The successful candidate will demonstrate a proven ability to influence technical direction, solve highly complex security challenges, and drive security excellence across the organization. Responsibilities Technical Leadership & Strategy Define and drive product security strategy, architecture principles, and security engineering roadmaps across multiple products and platforms. Lead the security architecture review process for new products, major feature developments, and platform changes. Establish and evolve secure development standards, security design patterns, and engineering best practices. Serve as the primary technical authority for complex security architecture decisions and risk-based security trade-off discussions. Drive strategic security initiatives that improve security posture, development efficiency, and regulatory readiness across the organization. Anticipate emerging threats, industry trends, and regulatory requirements and translate these into actionable engineering improvements. Product Security Engineering Collaborate with cross-functional teams to integrate security requirements into product design, development, deployment, and maintenance processes. Lead threat modeling activities for critical systems, products, and architectures. Conduct and oversee advanced security assessments, vulnerability investigations, attack surface analyses, and risk evaluations. Design, implement, and review security controls, cryptographic protections, and system hardening mechanisms. Lead investigations of critical security issues and provide technical direction for remediation efforts. Guide secure design reviews and code review activities for business-critical products. Security Tooling & Automation Define and drive the security tooling strategy across software and hardware development environments. Lead the development and adoption of advanced security testing capabilities, including fuzzing, software composition analysis (SCA), static analysis, dynamic analysis, memory safety validation, and vulnerability discovery tooling. Partner with DevOps and engineering teams to embed security automation and policy enforcement into CI/CD processes. Improve vulnerability detection, triage, and remediation workflows through automation and data-driven approaches. Security Governance & Risk Management Establish scalable approaches for vulnerability management, risk assessment, and security assurance across multiple product lines. Provide technical leadership during security incidents, vulnerability disclosures, and coordinated remediation efforts. Support product compliance and certification initiatives including FIPS 140-3, Common Criteria, PCI HSM, Cyber Resilience Act (CRA), and other applicable security standards. Review and approve security exceptions, risk acceptance decisions, and compensating controls where appropriate. Collaboration & External Engagement Act as a trusted advisor to engineering leaders, architects, product managers, and executive stakeholders. Represent Entrust in customer security discussions, security reviews, certification engagements, and external assessments. Collaborate with external researchers, independent laboratories, certification bodies, and security consultants. Contribute to industry working groups, standards development efforts, and security communities where appropriate. Mentoring & Organizational Impact Mentor senior engineers and security practitioners, fostering technical excellence across the organization. Lead technical communities of practice focused on secure development and product security. Influence engineering culture by promoting security-first thinking and secure-by-design principles. Provide technical leadership during strategic planning, architecture reviews, and product roadmap discussions. Help identify security skill gaps and contribute to workforce development initiatives. Technical Knowledge / Skills and Experience Required Extensive experience in product security, security architecture, or security engineering roles. Demonstrated experience providing technical leadership across multiple teams, products, or business units. Deep expertise in applied cryptography, cryptographic protocols, and security architectures. Strong understanding of secure software development and software assurance practices. Strong understanding of hardware security, embedded systems security, trusted execution environments, and FPGA security concepts. Advanced knowledge of threat modeling methodologies and risk assessment frameworks. Experience leading large-scale vulnerability management and remediation programs. Expertise with security assessment methodologies, penetration testing techniques, and offensive security concepts. Experience building or deploying security tooling integrated into modern software development pipelines. Strong programming capability in Python, C/C++, Go, Rust, Java, or similar languages. Experience supporting or leading security certification activities including FIPS 140-3, Common Criteria, PCI HSM, or equivalent frameworks. Strong understanding of modern regulatory and compliance requirements impacting product security, including CRA, NIS2, and secure development frameworks. Excellent communication skills with demonstrated ability to influence executive stakeholders and technical teams. Proven ability to drive organizational change through technical leadership and influence. Qualifications: Bachelor's degree in Computer Science, Information Security, Electrical Engineering, Mathematics, or related discipline. Master's degree preferred. Relevant security certifications (CISSP, CSSLP, OSCP, GIAC, CCSP, SABSA, or similar) are desirable. Demonstrated track record of leading complex security initiatives with organization-wide impact. At Entrust, we don't just offer jobs - we offer career journeys. Here is what you can expect when you join our team: Career Growth: Whether you're a budding developer or a seasoned expert, we're invested in your professional journey. With learning-forward initiatives and exciting challenges, your growth is our priority. Flexibility: Life is all about balance. Whether you're remote, hybrid, or on-site, we offer flexible options that fit your lifestyle. Collaboration: Here, your voice matters. Our teams thrive on sharing ideas, brainstorming solutions, and working together to build a better tomorrow. We believe in securing identities-but it doesn't stop there. At Entrust, we're passionate about valuing all identities. Our culture is built on diversity, inclusion, and respect. From unconscious bias training for our leaders to global affinity groups that connect colleagues across the globe, we're creating a community where everyone is encouraged to be themselves. Ready to Make an Impact? If you're excited by the prospect of innovating, growing your career, and collaborating in a dynamic environment, Entrust is the place for you. Join us in making a difference. Let's build a more secure world-together. Apply today! For more information, visit . Follow us on, LinkedIn, Facebook, Instagram, and YouTube For US roles, or where applicable: Entrust is an EEO/AA/Disabled/Veterans Employer For Canadian roles, or where applicable: Entrust values diversity and inclusion and we are committed to building a diverse workforce with wide perspectives and innovative ideas. We welcome applications from qualified individuals of all backgrounds, and we strive to provide an accessible experience for candidates of all abilities. If you require an accommodation, contact . Recruiter: Jack Steib Entrust is an innovative leader in identity-centric security solutions, providing an integrated platform of scalable, AI-enabled security offerings. We enable organizations to safeguard their operations, evolve without compromise, and protect their interactions in an interconnected world - so they can transform their businesses with confidence. Entrust supports customers in 150+ countries and works with a global partner network, we are trusted by the world most trusted organizations.