We have an opportunity to impact your career and provide an adventure where you can push the limits of what's possible. As a Lead Software Engineer at JPMorganChase within the Corporate Global Tax Technology team, you are an integral part of an agile team that works to enhance, build, and deliver trusted market-leading technology products in a secure, stable, and scalable way. Job responsibilities Design, develop, and implement cloud-based applications and services. Collaborate with architects and engineers to ensure design solutions are aligned with business goals. Optimize applications for performance, scalability, and security. Participate in code reviews and provide constructive feedback to peers. Stay up to date with emerging Cloud and AI/ML technologies and industry trends to drive innovation and continuous improvement Lead communities of practice across Software Engineering to promote awareness and adoption of new and leading-edge technologies Drives team adoption of enterprise-authorized AI-assisted engineering practices within the work environment to improve code quality, delivery speed, and operational outcomes (e.g., AI-assisted code review/refactoring, test strategy acceleration, incident/root-cause analysis support), while establishing consistent validation standards (secure coding, peer review, automated testing) and promoting reuse of effective patterns across the team. Applies knowledge of tools within the Software Development Life Cycle toolchain, including enterprise-authorized AI-assisted development and automation capabilities, to improve the value realized by automation Executes creative software solutions, design, development, and technical troubleshooting with ability to think beyond routine or conventional approaches to build solutions or break down technical problems Develops secure high-quality production code, and reviews and debugs code written by others Identifies opportunities to eliminate or automate remediation of recurring issues to improve overall operational stability of software applications and systems Required qualifications, capabilities, and skills Formal training or certification on software engineering concepts and applied experience Experienced in cloud development (AWS), with a focus on application design and development. Experience with AI/ML model integration, Prompt engineering, LLM APIs (OpenAI, Bedrock) and Generative AI Advanced in Java and Python Strong experience with cloud platforms like AWS, Azure, or Google Cloud Platform. Experience building RESTful APIs and working with event-drivenorserverless architectures. Demonstrated experience leading effective use of approved AI-assisted software development tools (e.g., for coding, code review, test acceleration, troubleshooting) with the ability to set team expectations for validating AI outputs for correctness, performance, and security. Proficiency in automation and continuous delivery methods Proficient in all aspects of the Software Development Life Cycle Advanced understanding of agile methodologies such as CI/CD, Application Resiliency, and Security Experience in Infrastructure as code (IAC) such as Terraform or equivalent Preferred qualifications, capabilities, and skills Experience in automation in any scripting languages. Relevant certifications such as AWS Certified Developer, Microsoft Certified: Azure Developer, or Google Professional Cloud Developer Familiarity with database technologies such as SQL, NoSQL, and cloud-native databases. Familiarity with containerization technologies such as Docker and Kubernetes. Experience with building out loosely coupled software and familiarity with SOA/Microservice architectures
28/07/2026
Full time
We have an opportunity to impact your career and provide an adventure where you can push the limits of what's possible. As a Lead Software Engineer at JPMorganChase within the Corporate Global Tax Technology team, you are an integral part of an agile team that works to enhance, build, and deliver trusted market-leading technology products in a secure, stable, and scalable way. Job responsibilities Design, develop, and implement cloud-based applications and services. Collaborate with architects and engineers to ensure design solutions are aligned with business goals. Optimize applications for performance, scalability, and security. Participate in code reviews and provide constructive feedback to peers. Stay up to date with emerging Cloud and AI/ML technologies and industry trends to drive innovation and continuous improvement Lead communities of practice across Software Engineering to promote awareness and adoption of new and leading-edge technologies Drives team adoption of enterprise-authorized AI-assisted engineering practices within the work environment to improve code quality, delivery speed, and operational outcomes (e.g., AI-assisted code review/refactoring, test strategy acceleration, incident/root-cause analysis support), while establishing consistent validation standards (secure coding, peer review, automated testing) and promoting reuse of effective patterns across the team. Applies knowledge of tools within the Software Development Life Cycle toolchain, including enterprise-authorized AI-assisted development and automation capabilities, to improve the value realized by automation Executes creative software solutions, design, development, and technical troubleshooting with ability to think beyond routine or conventional approaches to build solutions or break down technical problems Develops secure high-quality production code, and reviews and debugs code written by others Identifies opportunities to eliminate or automate remediation of recurring issues to improve overall operational stability of software applications and systems Required qualifications, capabilities, and skills Formal training or certification on software engineering concepts and applied experience Experienced in cloud development (AWS), with a focus on application design and development. Experience with AI/ML model integration, Prompt engineering, LLM APIs (OpenAI, Bedrock) and Generative AI Advanced in Java and Python Strong experience with cloud platforms like AWS, Azure, or Google Cloud Platform. Experience building RESTful APIs and working with event-drivenorserverless architectures. Demonstrated experience leading effective use of approved AI-assisted software development tools (e.g., for coding, code review, test acceleration, troubleshooting) with the ability to set team expectations for validating AI outputs for correctness, performance, and security. Proficiency in automation and continuous delivery methods Proficient in all aspects of the Software Development Life Cycle Advanced understanding of agile methodologies such as CI/CD, Application Resiliency, and Security Experience in Infrastructure as code (IAC) such as Terraform or equivalent Preferred qualifications, capabilities, and skills Experience in automation in any scripting languages. Relevant certifications such as AWS Certified Developer, Microsoft Certified: Azure Developer, or Google Professional Cloud Developer Familiarity with database technologies such as SQL, NoSQL, and cloud-native databases. Familiarity with containerization technologies such as Docker and Kubernetes. Experience with building out loosely coupled software and familiarity with SOA/Microservice architectures
Our Team the company is building the world's most trusted information network for financial professionals. We protect the company. We partner with internal departments to ensure the confidentiality, integrity, and availability of the company systems and the data we process. We aim to ensure that our clients see us as a trusted partner. Our Chief Information Security Office (CISO) owns the technical aspects of this mission by ensuring the company products, systems, networks and commercial applications are built and maintained with security in mind. What's the role? We are seeking a Product Security Engineer to help ensure that the company software is built securely. You will be responsible for building and maintaining automated security capabilities across the software development lifecycle. You will also engage with engineering partners to provide remediation guidance and enhance security testing to deliver high-fidelity, actionable results. As a member of the Product Security Enablement team, you will help provide automated security testing solutions for the company, including SAST, DAST, SCA, Secret searching and LLM-based assessments. Our team's goal is to create preventative security capabilities that integrate into development pipelines and help detect issues early in the software development lifecycle. An engineering skillset is required for this role. You will be responsible for prototyping new tools, integrating security testing tools and capabilities into the software development lifecycle, and developing custom security capabilities to deliver scalable testing solutions to our engineering teams. This role will routinely challenge your technical background and critical thinking. You will be expected to collaborate with different stakeholders in a fast paced environment across many technology stacks and services. We'll trust you to: Partner with engineering stakeholders to understand the company's development landscape and security needs. Develop automated security solutions that integrate into development pipelines. Maintain and enhance existing security automation processes and security capabilities. Understand and research technical details of core technology stacks and develop or enhance custom code analysis queries. Communicate vulnerability landscape and work on mitigations with stakeholders across the business. Actively monitor the latest news and trends in automated security capabilities, secure development, and AI-assisted security workflows. Develop and enhance operational runbooks. Perform ad hoc vulnerability discovery, including code review and static analysis for key engineering teams, applications and services. Build or adopt new security capabilities to address issues at scale, such as Software Composition Analysis, Secret searching, and other automated security testing techniques. Use LLMs and AI-assisted workflows as part of security assessments, vulnerability research, secure code review, developer enablement, and security automation. Explore, evaluate, and build automation using modern LLM tooling and integration patterns, including custom skills, MCP servers, agentic workflows, retrieval augmented workflows, and integrations with development and security tooling. You'll need to have: A strong core engineering background with a proven track record. 3+ years of experience in software development. Strong programming experience, with working knowledge of at least one of: C/C++, Python, JavaScript/TypeScript. Knowledge and experience with DevOps and software used in development pipelines (e.g. GitHub, Jenkins). Working knowledge of build systems, package managers, and development tooling (such as CMake, npm, Maven, Gradle, etc). A core understanding of common security vulnerabilities, such as OWASP Top 10 issues and language specific vulnerabilities. Experience using, evaluating, or building with LLMs or AI assisted tooling in technical workflows. Ability to combine technical knowledge with an understanding of core aspects of an information security program. Motivation to keep up with latest trends and techniques in the information security community. Excellent written and verbal communication skills. We'd love to see (not required, but nice to have!): Experience or familiarity with running, maintaining, and customizing static analysis security testing tools such as CodeQL and Semgrep. Broad familiarity with programming language ecosystems and frameworks, particularly C++, JavaScript/TypeScript, Python, Java as well as modern systems and infrastructure languages such as Go and Rust. Experience using LLMs or AI assisted tools for security assessments, vulnerability research, secure code review, developer enablement, or security automation. Familiarity with LLM automation concepts and tooling, such as custom skills, MCP servers, agentic workflows, retrieval augmented workflows, or integrations with development and security tooling. Knowledge of open source software component management, Software Composition Analysis, and related security tools. Knowledge of core concepts in public cloud providers such as AWS, GCP, and Azure. Familiarity with container orchestration technologies such as Kubernetes and Docker, and cloud deployment orchestration. Technical information security certifications, such as CISSP, CSSLP, or SANS certifications. Prior experience integrating security testing into DevOps pipelines. Equal Opportunity the company is an equal opportunity employer and prohibits discrimination in employment. It is the company's policy to provide equal opportunity and access for all persons, and the Company is committed to attracting, retaining, developing, and promoting the most qualified individuals without regard to age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, self identified or perceived sex, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy, childbirth or related medical conditions, or parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law (each, a "Protected Characteristic"). the company prohibits treating applicants or employees less favorably in connection with the terms and conditions of employment, in all phases of the employment process, because of one or more Protected Characteristics.
27/07/2026
Full time
Our Team the company is building the world's most trusted information network for financial professionals. We protect the company. We partner with internal departments to ensure the confidentiality, integrity, and availability of the company systems and the data we process. We aim to ensure that our clients see us as a trusted partner. Our Chief Information Security Office (CISO) owns the technical aspects of this mission by ensuring the company products, systems, networks and commercial applications are built and maintained with security in mind. What's the role? We are seeking a Product Security Engineer to help ensure that the company software is built securely. You will be responsible for building and maintaining automated security capabilities across the software development lifecycle. You will also engage with engineering partners to provide remediation guidance and enhance security testing to deliver high-fidelity, actionable results. As a member of the Product Security Enablement team, you will help provide automated security testing solutions for the company, including SAST, DAST, SCA, Secret searching and LLM-based assessments. Our team's goal is to create preventative security capabilities that integrate into development pipelines and help detect issues early in the software development lifecycle. An engineering skillset is required for this role. You will be responsible for prototyping new tools, integrating security testing tools and capabilities into the software development lifecycle, and developing custom security capabilities to deliver scalable testing solutions to our engineering teams. This role will routinely challenge your technical background and critical thinking. You will be expected to collaborate with different stakeholders in a fast paced environment across many technology stacks and services. We'll trust you to: Partner with engineering stakeholders to understand the company's development landscape and security needs. Develop automated security solutions that integrate into development pipelines. Maintain and enhance existing security automation processes and security capabilities. Understand and research technical details of core technology stacks and develop or enhance custom code analysis queries. Communicate vulnerability landscape and work on mitigations with stakeholders across the business. Actively monitor the latest news and trends in automated security capabilities, secure development, and AI-assisted security workflows. Develop and enhance operational runbooks. Perform ad hoc vulnerability discovery, including code review and static analysis for key engineering teams, applications and services. Build or adopt new security capabilities to address issues at scale, such as Software Composition Analysis, Secret searching, and other automated security testing techniques. Use LLMs and AI-assisted workflows as part of security assessments, vulnerability research, secure code review, developer enablement, and security automation. Explore, evaluate, and build automation using modern LLM tooling and integration patterns, including custom skills, MCP servers, agentic workflows, retrieval augmented workflows, and integrations with development and security tooling. You'll need to have: A strong core engineering background with a proven track record. 3+ years of experience in software development. Strong programming experience, with working knowledge of at least one of: C/C++, Python, JavaScript/TypeScript. Knowledge and experience with DevOps and software used in development pipelines (e.g. GitHub, Jenkins). Working knowledge of build systems, package managers, and development tooling (such as CMake, npm, Maven, Gradle, etc). A core understanding of common security vulnerabilities, such as OWASP Top 10 issues and language specific vulnerabilities. Experience using, evaluating, or building with LLMs or AI assisted tooling in technical workflows. Ability to combine technical knowledge with an understanding of core aspects of an information security program. Motivation to keep up with latest trends and techniques in the information security community. Excellent written and verbal communication skills. We'd love to see (not required, but nice to have!): Experience or familiarity with running, maintaining, and customizing static analysis security testing tools such as CodeQL and Semgrep. Broad familiarity with programming language ecosystems and frameworks, particularly C++, JavaScript/TypeScript, Python, Java as well as modern systems and infrastructure languages such as Go and Rust. Experience using LLMs or AI assisted tools for security assessments, vulnerability research, secure code review, developer enablement, or security automation. Familiarity with LLM automation concepts and tooling, such as custom skills, MCP servers, agentic workflows, retrieval augmented workflows, or integrations with development and security tooling. Knowledge of open source software component management, Software Composition Analysis, and related security tools. Knowledge of core concepts in public cloud providers such as AWS, GCP, and Azure. Familiarity with container orchestration technologies such as Kubernetes and Docker, and cloud deployment orchestration. Technical information security certifications, such as CISSP, CSSLP, or SANS certifications. Prior experience integrating security testing into DevOps pipelines. Equal Opportunity the company is an equal opportunity employer and prohibits discrimination in employment. It is the company's policy to provide equal opportunity and access for all persons, and the Company is committed to attracting, retaining, developing, and promoting the most qualified individuals without regard to age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, self identified or perceived sex, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy, childbirth or related medical conditions, or parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law (each, a "Protected Characteristic"). the company prohibits treating applicants or employees less favorably in connection with the terms and conditions of employment, in all phases of the employment process, because of one or more Protected Characteristics.
We have continuously refined our software development processes and expanded our offerings to include SaaS products in the aviation sector. As we look to enhance our current solutions and broaden our software capabilities, we are seeking a skilled Technical Consultant to play a key role in bridging our data engineers, data scientists, and subject matter experts (SMEs) with our software development team. We specialise in engineering and logistics within the aviation industry, leveraging deep expertise and a strong network of industry professionals. In this role, you will work closely with third-party developers where needed and ensure seamless integration between business requirements and technical execution. A key part of this role will be engaging with client stakeholders to understand project scope, gather technical requirements, and define clear objectives. You will work closely with internal teams to translate business needs into scalable, high-performing technical solutions that align with our customers operational goals. As part of a small but dynamic company, you will have end-to-end involvement in the software development lifecycle, as well as opportunities to contribute to business development and operational improvements. Your primary focus will be on delivering innovative software applications and digital modules tailored to our aviation customers. You will collaborate with the inhouse development team, work closely with Project Managers, to drive multiple projects forward, ensuring solutions are technically robust, scalable, and aligned with customer expectations 1. Code Review & Best Practices Conduct in-depth reviews of codebases to identify issues, inefficiencies, and potential security vulnerabilities. Provide recommendations on best practices, including coding standards, design patterns, and maintainability improvements. Support performance optimisation through refactoring and improved architecture. Support testing and QA process. 2. Cloud Infrastructure Support & Design Assist in designing, implementing, and optimising cloud infrastructure (predominantly Azure) Provide guidance on cloud security, scalability, and cost optimisation. Ensure security best practices are followed and compliance with industry standards. 3. Technical Recommendations & Roadmaps Develop and present technology roadmaps aligned with business goals. Provide recommendations on system architecture, tools, and frameworks. Identify opportunities for automation and process improvements. 4. Software Architecture & Development Strategy Advise on scalable and efficient system architectures Support API design, integrations, and data flow strategies. Recommend suitable technology stacks for new projects or modernisation efforts. 5. Security & Compliance Assess application security risks and provide remediation strategies. Ensure compliance with industry standards (ISO 27001, GDPR, SOC 2, etc.). Implement best practices for secure software development (OWASP, encryption, IAM, etc.). 6. Performance Optimisation & Scaling Analyse system bottlenecks and recommend performance tuning strategies. Support database optimisations, caching mechanisms, and load balancing strategies. Assist in designing auto-scaling solutions to handle peak loads efficiently. 7. DevOps & CI/CD Implementation Support the implementation of CI/CD pipelines for automated testing and deployment. Provide recommendations on DevOps practices, including containerisation (Docker, Kubernetes). Assist in improving monitoring, logging, and alerting solutions. 8. Technology & Tooling Selection Assess and recommend programming languages, frameworks, and development tools based on business needs. Guide the selection of database technologies (SQL, NoSQL, time-series databases, etc.). Help teams adopt emerging technologies such as AI / ML when relevant. 9. Stakeholder Communication & Knowledge Transfer Provide technical workshops and training sessions for development teams. Act as a bridge between technical and non-technical stakeholders, translating complex concepts into business value. Support decision-making through clear, data-driven insights. Train clients on new solutions, including developing training materials, conducting hands on training sessions, and providing ongoing support to ensure successful adoption
27/07/2026
Full time
We have continuously refined our software development processes and expanded our offerings to include SaaS products in the aviation sector. As we look to enhance our current solutions and broaden our software capabilities, we are seeking a skilled Technical Consultant to play a key role in bridging our data engineers, data scientists, and subject matter experts (SMEs) with our software development team. We specialise in engineering and logistics within the aviation industry, leveraging deep expertise and a strong network of industry professionals. In this role, you will work closely with third-party developers where needed and ensure seamless integration between business requirements and technical execution. A key part of this role will be engaging with client stakeholders to understand project scope, gather technical requirements, and define clear objectives. You will work closely with internal teams to translate business needs into scalable, high-performing technical solutions that align with our customers operational goals. As part of a small but dynamic company, you will have end-to-end involvement in the software development lifecycle, as well as opportunities to contribute to business development and operational improvements. Your primary focus will be on delivering innovative software applications and digital modules tailored to our aviation customers. You will collaborate with the inhouse development team, work closely with Project Managers, to drive multiple projects forward, ensuring solutions are technically robust, scalable, and aligned with customer expectations 1. Code Review & Best Practices Conduct in-depth reviews of codebases to identify issues, inefficiencies, and potential security vulnerabilities. Provide recommendations on best practices, including coding standards, design patterns, and maintainability improvements. Support performance optimisation through refactoring and improved architecture. Support testing and QA process. 2. Cloud Infrastructure Support & Design Assist in designing, implementing, and optimising cloud infrastructure (predominantly Azure) Provide guidance on cloud security, scalability, and cost optimisation. Ensure security best practices are followed and compliance with industry standards. 3. Technical Recommendations & Roadmaps Develop and present technology roadmaps aligned with business goals. Provide recommendations on system architecture, tools, and frameworks. Identify opportunities for automation and process improvements. 4. Software Architecture & Development Strategy Advise on scalable and efficient system architectures Support API design, integrations, and data flow strategies. Recommend suitable technology stacks for new projects or modernisation efforts. 5. Security & Compliance Assess application security risks and provide remediation strategies. Ensure compliance with industry standards (ISO 27001, GDPR, SOC 2, etc.). Implement best practices for secure software development (OWASP, encryption, IAM, etc.). 6. Performance Optimisation & Scaling Analyse system bottlenecks and recommend performance tuning strategies. Support database optimisations, caching mechanisms, and load balancing strategies. Assist in designing auto-scaling solutions to handle peak loads efficiently. 7. DevOps & CI/CD Implementation Support the implementation of CI/CD pipelines for automated testing and deployment. Provide recommendations on DevOps practices, including containerisation (Docker, Kubernetes). Assist in improving monitoring, logging, and alerting solutions. 8. Technology & Tooling Selection Assess and recommend programming languages, frameworks, and development tools based on business needs. Guide the selection of database technologies (SQL, NoSQL, time-series databases, etc.). Help teams adopt emerging technologies such as AI / ML when relevant. 9. Stakeholder Communication & Knowledge Transfer Provide technical workshops and training sessions for development teams. Act as a bridge between technical and non-technical stakeholders, translating complex concepts into business value. Support decision-making through clear, data-driven insights. Train clients on new solutions, including developing training materials, conducting hands on training sessions, and providing ongoing support to ensure successful adoption
At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology. Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and a year ago we split out as a separate business. Starling Bank has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success. Hybrid Working We have a Hybrid approach to working here at Engine - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. About the Role We are looking for an experienced Penetration Tester who can bridge the gap between deep technical exploitation and real-world business risk. This isn't just about running scanners and handing over a PDF; it's about adversarial empathy, understanding how our systems and services work so you can show us how they may be compromised. While you will sit within the Information Security team, you won't be siloed; you will be "dropped in" to test across various business domains, working side-by-side with Infrastructure Engineers and Software Developers and in collaboration with all parts of the Information Security Team. Your approach is to move beyond finding 'bugs' to helping out teams build inherently resilient systems. As an early member of our internal Pentesting capability, you won't just follow a manual, you will help write it. A key aspect of this role involves: Collaborating with your peers to design a continuous testing framework that evolves with our tech stack. Sharing knowledge with the wider technical faculty to elevate our collective security posture. Additionally, we understand the importance of knowledge and expertise remaining current and you shall support the continued advancement of our penetration testing through research, design and implementation of new solutions, including automation. Responsibilities End-to-End Assessments: Conducting penetration tests on our core banking platform, focusing on Cloud and Application Security. Code Review: Performing manual secure code reviews to identify logic flaws and security anti-patterns. Threat Modelling: Participate in sessions with different teams to identify design flaws before code is written. Risk Contextualisation: Contextualising technical vulnerabilities into "Real-World Risk" scenarios to demonstrate business impact to non-technical executives and within Engine's risk management framework. Cloud Security: Collaborating with Infrastructure teams to audit and secure cloud configurations. Autonomous Execution: Acting as an independent operator within the team, managing your own testing scope and timelines across different business domains. Remediation: Providing clear, actionable remediation advice that balances security requirements with engineering velocity. Strategic Reporting: Translate complex technical exploits into actionable business risk summaries for non-technical stakeholders and executive leadership. Requirements We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. Technical Skills Ideally, we would like: Experience: 5+ years experience in penetration testing with a focus on cloud native infrastructure, web applications, APIs. Tooling: Expert-level proficiency with industry-standard tools and the ability to "go manual" when scanners fail. Cloud Native: Experience with Cloud Security, (AWS/GCP) specifically AWS/EKS. Code Fluency: Ability to conduct code reviews in multiple languages, primarily Java and Go. Mobile: Experience testing Mobile Applications (iOS and Android). SDLC: You have a working understanding of how software is architected, built and deployed. Scripting: You have the ability to write your own scripts and tooling to aid in pentesting and improve efficiency. Golang, Python etc. Soft Skills Communication: Exceptional written and spoken communication skills: the ability to communicate complex technical issues to engineers and business risk to executives. Proactivity: A self-starting nature. You don't wait for a ticket to find a vulnerability. Got downtime? You're digging into codebases, closing off retesting items and generally getting it done. Independence: Ability to work independently while remaining a collaborative partner to the wider engineering team. Adaptability: Engine is evolving. You are able to evolve and develop as our requirements shift over time. Nice to have Infrastructure as Code (IaC): Experience auditing Terraform or CloudFormation templates. DevSecOps: Familiarity with integrating security tooling (DAST/SAST) into CI/CD pipelines. 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra day's holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton Generous family-friendly policies Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing About Us You may be put off applying for a role because you don't tick every box. Forget that! While we can't accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren't sure if you're 100% there yet, get in touch anyway. We're on a mission to radically reshape banking - and that starts with our brilliant team. Whatever came before, we're proud to bring together people of all backgrounds and experiences who love working together to solve problems. Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.
27/07/2026
Full time
At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology. Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and a year ago we split out as a separate business. Starling Bank has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success. Hybrid Working We have a Hybrid approach to working here at Engine - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. About the Role We are looking for an experienced Penetration Tester who can bridge the gap between deep technical exploitation and real-world business risk. This isn't just about running scanners and handing over a PDF; it's about adversarial empathy, understanding how our systems and services work so you can show us how they may be compromised. While you will sit within the Information Security team, you won't be siloed; you will be "dropped in" to test across various business domains, working side-by-side with Infrastructure Engineers and Software Developers and in collaboration with all parts of the Information Security Team. Your approach is to move beyond finding 'bugs' to helping out teams build inherently resilient systems. As an early member of our internal Pentesting capability, you won't just follow a manual, you will help write it. A key aspect of this role involves: Collaborating with your peers to design a continuous testing framework that evolves with our tech stack. Sharing knowledge with the wider technical faculty to elevate our collective security posture. Additionally, we understand the importance of knowledge and expertise remaining current and you shall support the continued advancement of our penetration testing through research, design and implementation of new solutions, including automation. Responsibilities End-to-End Assessments: Conducting penetration tests on our core banking platform, focusing on Cloud and Application Security. Code Review: Performing manual secure code reviews to identify logic flaws and security anti-patterns. Threat Modelling: Participate in sessions with different teams to identify design flaws before code is written. Risk Contextualisation: Contextualising technical vulnerabilities into "Real-World Risk" scenarios to demonstrate business impact to non-technical executives and within Engine's risk management framework. Cloud Security: Collaborating with Infrastructure teams to audit and secure cloud configurations. Autonomous Execution: Acting as an independent operator within the team, managing your own testing scope and timelines across different business domains. Remediation: Providing clear, actionable remediation advice that balances security requirements with engineering velocity. Strategic Reporting: Translate complex technical exploits into actionable business risk summaries for non-technical stakeholders and executive leadership. Requirements We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. Technical Skills Ideally, we would like: Experience: 5+ years experience in penetration testing with a focus on cloud native infrastructure, web applications, APIs. Tooling: Expert-level proficiency with industry-standard tools and the ability to "go manual" when scanners fail. Cloud Native: Experience with Cloud Security, (AWS/GCP) specifically AWS/EKS. Code Fluency: Ability to conduct code reviews in multiple languages, primarily Java and Go. Mobile: Experience testing Mobile Applications (iOS and Android). SDLC: You have a working understanding of how software is architected, built and deployed. Scripting: You have the ability to write your own scripts and tooling to aid in pentesting and improve efficiency. Golang, Python etc. Soft Skills Communication: Exceptional written and spoken communication skills: the ability to communicate complex technical issues to engineers and business risk to executives. Proactivity: A self-starting nature. You don't wait for a ticket to find a vulnerability. Got downtime? You're digging into codebases, closing off retesting items and generally getting it done. Independence: Ability to work independently while remaining a collaborative partner to the wider engineering team. Adaptability: Engine is evolving. You are able to evolve and develop as our requirements shift over time. Nice to have Infrastructure as Code (IaC): Experience auditing Terraform or CloudFormation templates. DevSecOps: Familiarity with integrating security tooling (DAST/SAST) into CI/CD pipelines. 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra day's holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton Generous family-friendly policies Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing About Us You may be put off applying for a role because you don't tick every box. Forget that! While we can't accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren't sure if you're 100% there yet, get in touch anyway. We're on a mission to radically reshape banking - and that starts with our brilliant team. Whatever came before, we're proud to bring together people of all backgrounds and experiences who love working together to solve problems. Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.
Inspired Thinking Group (ITG)
Birmingham, Staffordshire
We are looking for an enthusiastic and detail-oriented Vulnerability Management Analyst to join our information security and data protection team. This is an ideal opportunity for someone with real-world experience in information security and data protection. It's a great opportunity to get hands-on with the tools and processes that keep all our products secure, and to make a genuinely visible difference to how we manage risk day to day. The Role: The Vulnerability Management Analyst will help us find, prioritise, and fix security vulnerabilities across our global business and all our products. You'll configure and tune our vulnerability tools, risk assessing detections, and prioritising findings for fix. You'll cover code vulnerabilities (SAST, DAST, SCA, OSS licencing), Cloud Security Posture Management (CSPM), Internal Vulnerability Scanning (IVS), and penetration testing. You'll also help design and report on our detection and remediation activities. This is a full-time position. Occasional after-hours work may be required for incident response or urgent security tasks. Successful candidates will be enrolled on a fully funded training pathway and will be provided with mentoring support to help them grow and learn. Responsibilities: 1. Configuring and tuning our tools Help configure, tune, and maintain our vulnerability tooling across scanning tools, working with platform and engineering teams to keep coverage accurate Support day-to-day scanning schedules and tooling integrations, including ticketing and CI/CD pipelines Look for opportunities to automate reporting, validation, and other repetitive tasks across the whole vulnerability lifecycle 2. Triage and risk assessment Triage findings from vulnerability sources, confirming genuine issues and filtering out false positives Risk-assess confirmed findings against severity, exploitability, and business context, to prioritise fixes Apply a consistent risk-scoring approach so findings are prioritised effectively, regardless of source Stay on top of current threats and trends (e.g. threat actors, new vulnerabilities etc.) to inform vulnerability management activities 3. Designing secure benchmarks and guidelines Develop and maintain secure configuration benchmarks and hardening guidelines for our software, infrastructure, and tooling Align benchmarks and guidelines to recognised industry frameworks for business Work with the right teams to help implement the secure configurations, providing practical advice, and facilitating deviations within our broader risk management framework 4. Working with Developers and Engineers Act as a primary contact point for Developers and Engineers to help them understand and fix issues Track remediation progress, chase owners on overdue items, escalate where necessary Support teams with practical remediation guidance, drawing on the OWASP Top 10, the Mitre Att&ck Framework, and our secure coding standards 5. Coordinating IVS, web application testing, and penetration testing Organise our externally delivered IVS and Penetration Testing programmes, from scheduling and scoping, through to day-to-day contact with our testing partners Help manage our relationships with testing providers, including engagement administration and reporting 6. SLAs, outcome driven metrics, and reporting Help design and report on remediation SLAs across vulnerability classes, severities, and products Produce regular reporting (monthly, quarterly, and ad-hoc) on SLA performance, open findings, and trends Feed data and insight into our wider security metrics and reporting processes 7. Continuous improvement and team support Suggest ways to improve how we manage vulnerabilities and the tools we use to do it Support the rollout of new scanning tools or process changes across our global product estate Help create and maintain our vulnerability management policies, standards, and procedures Requirements: 2+ years' experience in vulnerability management, security operations, development, or a related security/IT role Hands-on experience with vulnerability scanning and management tooling (e.g. SAST, DAST, SCA, CSPM, or IVS) Solid understanding of common vulnerability types and remediation approaches, including familiarity with the Mitre ATT&CK Framework and OWASP Top 10 Experience triaging and risk-assessing security findings, helping teams to prioritise remediation based on severity and business impact Comfortable coordinating third-party engagements, such as scheduling and scoping penetration tests Comfortable explaining technical findings to both Developers and non-technical stakeholders Organised enough to manage several scanning programmes, testing engagements, and remediation workstreams in parallel Comfortable working across a global, multi-product environment Comfortable working within an agile enterprise environment Ability to read and understand common coding languages is essential, the ability to write scripts and/or code is preferred Relevant certifications (e.g. CompTIA Security+, CompTIA CySA+, GIAC GFACT/GPEN, or CEH) are preferred but not essential Strong analytical and problem-solving mindset, with real attention to detail Ability to work autonomously, use good judgement, and know when to escalate Perks at ITG - alongside a competitive salary, here's what you can look forward to: Time off that works for you - 25 days' holiday + bank holidays, a paid Wellbeing Day, flexible bank holidays to honour cultural or religious observances, and the option to buy or carry over up to 5 extra days. Family & life milestones - Enhanced family friendly leave, 3 extra days for your wedding/honeymoon, and an Employee Assistance Programme whenever you need support. Financial perks - Pension scheme, Corporate Medical Cash Plan, electric car salary sacrifice scheme, and tax-efficient payroll giving to your favourite charities. Growth & recognition - Funding for professional qualifications, monthly Employee of the Month awards (£250 bonus), and referral bonuses of up to £1,500. Community & wellbeing - Regular Wellbeing Workshops, 30+ Wellbeing Champions, a paid Volunteer Day, and an online perks platform with discounts on top brands, days out, and gym memberships. What next? Like what you see? Drop us your application and someone from our team will be in touch. We Value Diversity We champion and welcome diversity in our workforce and ensure all job applicants receive equal and fair treatment, regardless of age, race, gender or gender identity, religion, sexual orientation, disability, or nationality. We are not only committed to increasing the visibility and recognition of talent from under-represented groups within our organisation, but the wider industry too. At the end of the day, we make sure we take time to look after ourselves, each other, and the planet, because we're always stronger together. ITG have a number of community groups available to employees and exist to offer a safe space for like-minded colleagues, with shared interests to connect, socialise and check in with each other. What next? If you found yourself interested in knowing more, drop us your application and someone from our team will be in touch.
27/07/2026
Full time
We are looking for an enthusiastic and detail-oriented Vulnerability Management Analyst to join our information security and data protection team. This is an ideal opportunity for someone with real-world experience in information security and data protection. It's a great opportunity to get hands-on with the tools and processes that keep all our products secure, and to make a genuinely visible difference to how we manage risk day to day. The Role: The Vulnerability Management Analyst will help us find, prioritise, and fix security vulnerabilities across our global business and all our products. You'll configure and tune our vulnerability tools, risk assessing detections, and prioritising findings for fix. You'll cover code vulnerabilities (SAST, DAST, SCA, OSS licencing), Cloud Security Posture Management (CSPM), Internal Vulnerability Scanning (IVS), and penetration testing. You'll also help design and report on our detection and remediation activities. This is a full-time position. Occasional after-hours work may be required for incident response or urgent security tasks. Successful candidates will be enrolled on a fully funded training pathway and will be provided with mentoring support to help them grow and learn. Responsibilities: 1. Configuring and tuning our tools Help configure, tune, and maintain our vulnerability tooling across scanning tools, working with platform and engineering teams to keep coverage accurate Support day-to-day scanning schedules and tooling integrations, including ticketing and CI/CD pipelines Look for opportunities to automate reporting, validation, and other repetitive tasks across the whole vulnerability lifecycle 2. Triage and risk assessment Triage findings from vulnerability sources, confirming genuine issues and filtering out false positives Risk-assess confirmed findings against severity, exploitability, and business context, to prioritise fixes Apply a consistent risk-scoring approach so findings are prioritised effectively, regardless of source Stay on top of current threats and trends (e.g. threat actors, new vulnerabilities etc.) to inform vulnerability management activities 3. Designing secure benchmarks and guidelines Develop and maintain secure configuration benchmarks and hardening guidelines for our software, infrastructure, and tooling Align benchmarks and guidelines to recognised industry frameworks for business Work with the right teams to help implement the secure configurations, providing practical advice, and facilitating deviations within our broader risk management framework 4. Working with Developers and Engineers Act as a primary contact point for Developers and Engineers to help them understand and fix issues Track remediation progress, chase owners on overdue items, escalate where necessary Support teams with practical remediation guidance, drawing on the OWASP Top 10, the Mitre Att&ck Framework, and our secure coding standards 5. Coordinating IVS, web application testing, and penetration testing Organise our externally delivered IVS and Penetration Testing programmes, from scheduling and scoping, through to day-to-day contact with our testing partners Help manage our relationships with testing providers, including engagement administration and reporting 6. SLAs, outcome driven metrics, and reporting Help design and report on remediation SLAs across vulnerability classes, severities, and products Produce regular reporting (monthly, quarterly, and ad-hoc) on SLA performance, open findings, and trends Feed data and insight into our wider security metrics and reporting processes 7. Continuous improvement and team support Suggest ways to improve how we manage vulnerabilities and the tools we use to do it Support the rollout of new scanning tools or process changes across our global product estate Help create and maintain our vulnerability management policies, standards, and procedures Requirements: 2+ years' experience in vulnerability management, security operations, development, or a related security/IT role Hands-on experience with vulnerability scanning and management tooling (e.g. SAST, DAST, SCA, CSPM, or IVS) Solid understanding of common vulnerability types and remediation approaches, including familiarity with the Mitre ATT&CK Framework and OWASP Top 10 Experience triaging and risk-assessing security findings, helping teams to prioritise remediation based on severity and business impact Comfortable coordinating third-party engagements, such as scheduling and scoping penetration tests Comfortable explaining technical findings to both Developers and non-technical stakeholders Organised enough to manage several scanning programmes, testing engagements, and remediation workstreams in parallel Comfortable working across a global, multi-product environment Comfortable working within an agile enterprise environment Ability to read and understand common coding languages is essential, the ability to write scripts and/or code is preferred Relevant certifications (e.g. CompTIA Security+, CompTIA CySA+, GIAC GFACT/GPEN, or CEH) are preferred but not essential Strong analytical and problem-solving mindset, with real attention to detail Ability to work autonomously, use good judgement, and know when to escalate Perks at ITG - alongside a competitive salary, here's what you can look forward to: Time off that works for you - 25 days' holiday + bank holidays, a paid Wellbeing Day, flexible bank holidays to honour cultural or religious observances, and the option to buy or carry over up to 5 extra days. Family & life milestones - Enhanced family friendly leave, 3 extra days for your wedding/honeymoon, and an Employee Assistance Programme whenever you need support. Financial perks - Pension scheme, Corporate Medical Cash Plan, electric car salary sacrifice scheme, and tax-efficient payroll giving to your favourite charities. Growth & recognition - Funding for professional qualifications, monthly Employee of the Month awards (£250 bonus), and referral bonuses of up to £1,500. Community & wellbeing - Regular Wellbeing Workshops, 30+ Wellbeing Champions, a paid Volunteer Day, and an online perks platform with discounts on top brands, days out, and gym memberships. What next? Like what you see? Drop us your application and someone from our team will be in touch. We Value Diversity We champion and welcome diversity in our workforce and ensure all job applicants receive equal and fair treatment, regardless of age, race, gender or gender identity, religion, sexual orientation, disability, or nationality. We are not only committed to increasing the visibility and recognition of talent from under-represented groups within our organisation, but the wider industry too. At the end of the day, we make sure we take time to look after ourselves, each other, and the planet, because we're always stronger together. ITG have a number of community groups available to employees and exist to offer a safe space for like-minded colleagues, with shared interests to connect, socialise and check in with each other. What next? If you found yourself interested in knowing more, drop us your application and someone from our team will be in touch.
United States Digital Space LLC is hiring a Staff+ Engineer to set the technical direction for safeguarding Claude at scale. You will own the architecture for detection, containment, and remediation of account compromise across Claude and the Claude Developer Platform, while guiding multi-month projects in adversarial environments. You will lead investigations, build durable automated defenses, and drive alignment with Security, Product, and Policy teams to protect users globally.
27/07/2026
Full time
United States Digital Space LLC is hiring a Staff+ Engineer to set the technical direction for safeguarding Claude at scale. You will own the architecture for detection, containment, and remediation of account compromise across Claude and the Claude Developer Platform, while guiding multi-month projects in adversarial environments. You will lead investigations, build durable automated defenses, and drive alignment with Security, Product, and Policy teams to protect users globally.
About the company - the company's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role the company's Safeguards organization builds the systems that keep Claude safe to use at scale. The Account Compromise team owns one specific slice of that work: protecting the people and organizations who use Claude from losing control of their accounts, and preventing compromised accounts and credentials from being used to abuse our platform. Account takeover, credential stuffing, phishing-driven session theft, leaked API keys, and resold access all cause real harm - to the customers whose accounts are hijacked, and to the wider ecosystem when stolen access is used to route abusive traffic through legitimate accounts. We are looking for a staff+ engineer to set the technical direction for this work. You will own the architecture of how we detect, contain, and remediate account compromise across Claude and the Claude Developer Platform, making the design decisions that other engineers and teams build on top of. You will move between deep technical work and adversarial problem-solving: threat modelling how attackers will adapt, scoping multi-month projects from ambiguous starting points, and leading complex live investigations when they escalate. This is a hard problem space. Attackers iterate quickly, the signals separating a compromised account from an unusual but legitimate one are subtle, and every defence carries a cost to real users if it fires incorrectly. You will be building the playbook, and the judgement calls about where to draw those lines will largely be yours to make and defend. You will operate with high autonomy - owning detection coverage and incident leadership, driving alignment with Security, Product, and Policy teams, and shaping how the company approaches this problem globally rather than executing against someone else's roadmap. Key responsibilities Set the technical direction and own the architecture for account compromise detection, response, and remediation across Claude and the Claude Developer Platform Independently scope and lead complex, multi-month engineering projects from an ambiguous starting point through to production systems that operate reliably under adversarial pressure Build and evolve detection systems that identify account takeover, credential abuse, and compromised API keys in near real time Design automated response flows that cut off attacker access while minimising disruption to legitimate users Lead investigations into significant compromise incidents end to end, then convert what you learn into durable, automated defences Threat model how attackers are likely to adapt, and prioritise the team's work against that view rather than only against incidents already observed Drive cross-organisational alignment on account security direction with Security, Product, Support, Policy and other partners. Define how the team measures success and hold the work to those measures Set technical standards for the domain and raise the bar for other engineers through code review, design review, and mentorship Surface patterns from compromise cases to research and product teams so that protections improve upstream Minimum qualifications 10 + years experience designing, building, and operating detection, anti-fraud, anti-abuse, or security systems in production A track record of independently scoping and delivering complex, ambiguous, multi-month technical projects Experience making architectural decisions in an adversarial domain that other engineers and teams then build on Proficiency in Python and SQL, with strong software engineering fundamentals and hands-on coding ability Experience leading investigations into account-based abuse or security incidents, and translating findings into automated detection Ability to reason rigorously about large behavioural or telemetry datasets, and to distinguish attacker behaviour from unusual but legitimate use Strong written communication and a track record of driving alignment across multiple teams and stakeholders Sound judgement about the tradeoff between stopping bad actors and disrupting legitimate users, and the ability to explain and defend where you have drawn that line Preferred qualifications Significant engineering experience in trust and safety, platform integrity, fraud, or detection and response, including time as a technical lead or mentor Deep familiarity with account attack techniques Experience with authentication and identity systems, including OAuth, single sign-on, multi-factor authentication, device binding, and risk-based authentication Experience applying machine learning to fraud or abuse detection, alongside a clear sense of when simpler rules-based approaches are the better choice Experience with cloud data tooling such as BigQuery, Spark, dbt, Airflow or similar Experience building tooling for operational or investigative teams, and partnering closely with the people who use it Interest in AI safety, and in the specific ways account compromise intersects with model misuse Representative projects - Design the architecture for real-time login risk scoring, and get agreement across Security, Product, and Safeguards on where step-up authentication should and should not fire Design detection for compromised API keys, together with security controls to limit exposure Rebuild product features to regain access quickly when customers get compromised Write the threat model that sets the team's roadmap for the next year, and bring the rest of the organisation along with it Instrument a false positive review loop that measures how often the team's defences affect legitimate users, and drive that number down The annual compensation range for this role is listed below. For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. Annual Salary: £325,000 - £390,000 GBP Logistics Minimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this. We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team. Your safety matters to us. To protect yourself from potential scams, remember that the company recruiters only contact you email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of the company. Be cautious of emails from other domains. Legitimate the company recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links-visit the directly for confirmed position openings. How we're different - We're different We believe that the highest-impact AI research will be big science. At the company we work as a single cohesive team on just a few large-scale research efforts. And we value impact - advancing our long-term goals of steerable, trustworthy AI - rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills. The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to the company, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute . click apply for full job details
27/07/2026
Full time
About the company - the company's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role the company's Safeguards organization builds the systems that keep Claude safe to use at scale. The Account Compromise team owns one specific slice of that work: protecting the people and organizations who use Claude from losing control of their accounts, and preventing compromised accounts and credentials from being used to abuse our platform. Account takeover, credential stuffing, phishing-driven session theft, leaked API keys, and resold access all cause real harm - to the customers whose accounts are hijacked, and to the wider ecosystem when stolen access is used to route abusive traffic through legitimate accounts. We are looking for a staff+ engineer to set the technical direction for this work. You will own the architecture of how we detect, contain, and remediate account compromise across Claude and the Claude Developer Platform, making the design decisions that other engineers and teams build on top of. You will move between deep technical work and adversarial problem-solving: threat modelling how attackers will adapt, scoping multi-month projects from ambiguous starting points, and leading complex live investigations when they escalate. This is a hard problem space. Attackers iterate quickly, the signals separating a compromised account from an unusual but legitimate one are subtle, and every defence carries a cost to real users if it fires incorrectly. You will be building the playbook, and the judgement calls about where to draw those lines will largely be yours to make and defend. You will operate with high autonomy - owning detection coverage and incident leadership, driving alignment with Security, Product, and Policy teams, and shaping how the company approaches this problem globally rather than executing against someone else's roadmap. Key responsibilities Set the technical direction and own the architecture for account compromise detection, response, and remediation across Claude and the Claude Developer Platform Independently scope and lead complex, multi-month engineering projects from an ambiguous starting point through to production systems that operate reliably under adversarial pressure Build and evolve detection systems that identify account takeover, credential abuse, and compromised API keys in near real time Design automated response flows that cut off attacker access while minimising disruption to legitimate users Lead investigations into significant compromise incidents end to end, then convert what you learn into durable, automated defences Threat model how attackers are likely to adapt, and prioritise the team's work against that view rather than only against incidents already observed Drive cross-organisational alignment on account security direction with Security, Product, Support, Policy and other partners. Define how the team measures success and hold the work to those measures Set technical standards for the domain and raise the bar for other engineers through code review, design review, and mentorship Surface patterns from compromise cases to research and product teams so that protections improve upstream Minimum qualifications 10 + years experience designing, building, and operating detection, anti-fraud, anti-abuse, or security systems in production A track record of independently scoping and delivering complex, ambiguous, multi-month technical projects Experience making architectural decisions in an adversarial domain that other engineers and teams then build on Proficiency in Python and SQL, with strong software engineering fundamentals and hands-on coding ability Experience leading investigations into account-based abuse or security incidents, and translating findings into automated detection Ability to reason rigorously about large behavioural or telemetry datasets, and to distinguish attacker behaviour from unusual but legitimate use Strong written communication and a track record of driving alignment across multiple teams and stakeholders Sound judgement about the tradeoff between stopping bad actors and disrupting legitimate users, and the ability to explain and defend where you have drawn that line Preferred qualifications Significant engineering experience in trust and safety, platform integrity, fraud, or detection and response, including time as a technical lead or mentor Deep familiarity with account attack techniques Experience with authentication and identity systems, including OAuth, single sign-on, multi-factor authentication, device binding, and risk-based authentication Experience applying machine learning to fraud or abuse detection, alongside a clear sense of when simpler rules-based approaches are the better choice Experience with cloud data tooling such as BigQuery, Spark, dbt, Airflow or similar Experience building tooling for operational or investigative teams, and partnering closely with the people who use it Interest in AI safety, and in the specific ways account compromise intersects with model misuse Representative projects - Design the architecture for real-time login risk scoring, and get agreement across Security, Product, and Safeguards on where step-up authentication should and should not fire Design detection for compromised API keys, together with security controls to limit exposure Rebuild product features to regain access quickly when customers get compromised Write the threat model that sets the team's roadmap for the next year, and bring the rest of the organisation along with it Instrument a false positive review loop that measures how often the team's defences affect legitimate users, and drive that number down The annual compensation range for this role is listed below. For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. Annual Salary: £325,000 - £390,000 GBP Logistics Minimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this. We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team. Your safety matters to us. To protect yourself from potential scams, remember that the company recruiters only contact you email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of the company. Be cautious of emails from other domains. Legitimate the company recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links-visit the directly for confirmed position openings. How we're different - We're different We believe that the highest-impact AI research will be big science. At the company we work as a single cohesive team on just a few large-scale research efforts. And we value impact - advancing our long-term goals of steerable, trustworthy AI - rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills. The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to the company, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute . click apply for full job details
Out of the successful launch of Chase in 2021, we're a new team, with a new mission. We're creating products that solve real world problems and put customers at the center - all in an environment that nurtures skills and helps you realize your potential. Our team is key to our success. We're people first. We value collaboration, curiosity and commitment. As a Senior Lead Software Engineer (Platform) at JPMorgan Chase within the Accelerator Business Platform Team, you are the heart of this venture, focused on getting smart ideas into the hands of our customers. You have a curious mindset, thrive in collaborative squads, and are passionate about new technology. By your nature, you are also solution oriented, commercially savvy and have a head for fintech. You thrive in working in tribes and squads that focus on specific products and projects - and depending on your strengths and interests, you'll have the opportunity to move between them. In this senior lead role, you set technical direction across squads, raise engineering standards, and mentor and grow other technical leaders. While we're looking for professional skills, culture is just as important to us. We understand that everyone's unique - and that diversity of thought, experience and background is what makes a good team, great. By bringing people with different points of view together, we can represent everyone and truly reflect the communities we serve. This way, there's scope for you to make a huge difference - on us as a company, and on our clients and business partners around the world. Job responsibilities Sets technical direction for platform engineering across squads, aligning architecture, delivery, and operational excellence to business outcomes and risk controls. Develops secure high quality production code, and reviews and debugs code written by others; establishes engineering standards and best practices. Designs and develops composable infrastructure systems and capabilities, with a focus on scalable platform services. Designs, builds, and operates Kubernetes based platform services; automates developer self service and CI/CD; improves reliability and operational readiness; strengthens platform security and controls via IaC, policy as code, and hardening standards. Identifies opportunities to eliminate or automate remediation of recurring issues to improve overall operational stability of software applications and systems. Provides operational support and leadership for production systems in a "you build it you run it" culture, including incident response, post incident learning, and continuous reliability improvements. Leads evaluation sessions with external vendors, startups, and internal teams to drive outcomes oriented probing of architectural designs, technical credentials, and applicability for use within existing systems and information architecture. Leads and grows communities of practice across Software Engineering to drive awareness, adoption, and use of new and leading edge technologies. Coaches and mentors engineers, developing technical leadership capability and supporting high performance across teams. Adds to team culture of diversity, equity, inclusion, and respect. Required qualifications, capabilities, and skills Formal training or certification on software engineering concepts, such as Certified Kubernetes Application Developer (CKAD), Google Associate Cloud Engineer Certification, or AWS Certified Solutions Architect, or equivalent experience. Hands on practical experience delivering system design, application development, testing, and operational stability, including leading technical delivery in complex environments. Advanced in one or more programming language(s), such as Go, Java or Kotlin. Advanced understanding of agile methodologies, CI/CD, application resiliency, and security, including setting standards and driving adoption across teams. Demonstrated proficiency in software applications and processes within a technical domain, such as cloud, artificial intelligence, machine learning, mobile, etc. Practical cloud native experience, deploying Kubernetes applications on a cloud service provider, such as Google Cloud, Amazon Web Services, or Microsoft Azure, at meaningful scale. Preferred qualifications, capabilities, and skills Expertise in the Kubernetes operator pattern. Expertise deploying infrastructure as code, using Crossplane, Terraform, or equivalent. Experience with GitOps workflows. ABOUT US J.P.Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first class business in a first class way approach to serving clients drives everything we do. We strive to build trusted, long term partnerships to help our clients achieve their business objectives. We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation. ABOUT THE TEAM Our Corporate Technology team relies on smart, driven people like you to develop applications and provide tech support for all our corporate functions across our network. Your efforts will touch lives all over the financial spectrum and across all our divisions: Global Finance, Corporate Treasury, Risk Management, Human Resources, Compliance, Legal, and within the Corporate Administrative Office. You'll be part of a team specifically built to meet and exceed our evolving technology needs, as well as our technology controls agenda.
26/07/2026
Full time
Out of the successful launch of Chase in 2021, we're a new team, with a new mission. We're creating products that solve real world problems and put customers at the center - all in an environment that nurtures skills and helps you realize your potential. Our team is key to our success. We're people first. We value collaboration, curiosity and commitment. As a Senior Lead Software Engineer (Platform) at JPMorgan Chase within the Accelerator Business Platform Team, you are the heart of this venture, focused on getting smart ideas into the hands of our customers. You have a curious mindset, thrive in collaborative squads, and are passionate about new technology. By your nature, you are also solution oriented, commercially savvy and have a head for fintech. You thrive in working in tribes and squads that focus on specific products and projects - and depending on your strengths and interests, you'll have the opportunity to move between them. In this senior lead role, you set technical direction across squads, raise engineering standards, and mentor and grow other technical leaders. While we're looking for professional skills, culture is just as important to us. We understand that everyone's unique - and that diversity of thought, experience and background is what makes a good team, great. By bringing people with different points of view together, we can represent everyone and truly reflect the communities we serve. This way, there's scope for you to make a huge difference - on us as a company, and on our clients and business partners around the world. Job responsibilities Sets technical direction for platform engineering across squads, aligning architecture, delivery, and operational excellence to business outcomes and risk controls. Develops secure high quality production code, and reviews and debugs code written by others; establishes engineering standards and best practices. Designs and develops composable infrastructure systems and capabilities, with a focus on scalable platform services. Designs, builds, and operates Kubernetes based platform services; automates developer self service and CI/CD; improves reliability and operational readiness; strengthens platform security and controls via IaC, policy as code, and hardening standards. Identifies opportunities to eliminate or automate remediation of recurring issues to improve overall operational stability of software applications and systems. Provides operational support and leadership for production systems in a "you build it you run it" culture, including incident response, post incident learning, and continuous reliability improvements. Leads evaluation sessions with external vendors, startups, and internal teams to drive outcomes oriented probing of architectural designs, technical credentials, and applicability for use within existing systems and information architecture. Leads and grows communities of practice across Software Engineering to drive awareness, adoption, and use of new and leading edge technologies. Coaches and mentors engineers, developing technical leadership capability and supporting high performance across teams. Adds to team culture of diversity, equity, inclusion, and respect. Required qualifications, capabilities, and skills Formal training or certification on software engineering concepts, such as Certified Kubernetes Application Developer (CKAD), Google Associate Cloud Engineer Certification, or AWS Certified Solutions Architect, or equivalent experience. Hands on practical experience delivering system design, application development, testing, and operational stability, including leading technical delivery in complex environments. Advanced in one or more programming language(s), such as Go, Java or Kotlin. Advanced understanding of agile methodologies, CI/CD, application resiliency, and security, including setting standards and driving adoption across teams. Demonstrated proficiency in software applications and processes within a technical domain, such as cloud, artificial intelligence, machine learning, mobile, etc. Practical cloud native experience, deploying Kubernetes applications on a cloud service provider, such as Google Cloud, Amazon Web Services, or Microsoft Azure, at meaningful scale. Preferred qualifications, capabilities, and skills Expertise in the Kubernetes operator pattern. Expertise deploying infrastructure as code, using Crossplane, Terraform, or equivalent. Experience with GitOps workflows. ABOUT US J.P.Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first class business in a first class way approach to serving clients drives everything we do. We strive to build trusted, long term partnerships to help our clients achieve their business objectives. We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation. ABOUT THE TEAM Our Corporate Technology team relies on smart, driven people like you to develop applications and provide tech support for all our corporate functions across our network. Your efforts will touch lives all over the financial spectrum and across all our divisions: Global Finance, Corporate Treasury, Risk Management, Human Resources, Compliance, Legal, and within the Corporate Administrative Office. You'll be part of a team specifically built to meet and exceed our evolving technology needs, as well as our technology controls agenda.
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
26/07/2026
Full time
Lead Software Security Engineer Salary: Up to £150,000 + Benefits Location: London (Hybrid - 3 days per week in the office) We are currently looking for a Lead Software Security Engineer to join a fast-growing, innovative technology business operating at the forefront of AI and data-driven products. This is an exciting opportunity to join a highly collaborative, engineering-led environment where security is viewed as a key enabler of innovation. Reporting to the Head of Engineering, the Lead Security Engineer will play a pivotal role in shaping the organisation's security posture, working closely with software engineers, platform teams and technical leadership to embed security throughout the software development lifecycle. This is not a traditional SOC or operational security position. Instead, the Security Engineer will focus on securing applications, cloud infrastructure and development practices, helping the business build secure products at scale whilst influencing security strategy across the wider organisation. The Opportunity As the Lead Security Engineer, you'll work at the intersection of software engineering, cloud infrastructure and cyber security, helping to build and maintain a secure by design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers to promote secure coding practices Reviewing cloud infrastructure and architecture from a security perspective Supporting incident response and remediation activities when required Defining and promoting security standards, policies and best practices Influencing technical decision-making across engineering and leadership teams This role offers the opportunity to make a genuine impact within a growing technology organisation where security is a strategic priority rather than an afterthought. What's in it for you? Salary up to £150,000 Hybrid working model Opportunity to work on cutting edge AI and technology products High level of autonomy and influence Collaborative engineering culture Career progression opportunities as the business continues to scale Ongoing learning and professional development Pension scheme Generous holiday allowance Skills and Experience Commercial experience as a Security Engineer, Application Security Engineer, Product Security Engineer or DevSecOps Engineer Strong understanding of application security principles and secure software development practices Experience working closely with software engineering teams Hands on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note that candidates must have full, unrestricted right to work in the UK. Unfortunately, sponsorship is not available for this position.
National Gas Transmission PLC
Warwick, Warwickshire
Select how often (in days) to receive an alert: Vulnerability Analyst/ Cyber Security Data Analyst Warwick, Hybrid flexible working At National Gas, the work we do matters. As Britain's national gas network, we help keep the lights on, businesses running, and homes warm by maintaining the critical infrastructure that transports gas across Great Britain. While providing the energy security Britain relies on today, we're also helping transform the network for a clean energy future. Join us and help secure Britain's energy. About the role: The Attack Surface Reduction (ASR) team within Cyber Security is responsible for identifying, measuring and reducing security risk across National Gas by proactively testing, assessing and challenging the resilience of our technology and operational environments. The Vulnerability Analyst (or Cyber Security Data Analyst) helps to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. For this role we can consider a strong Data Analyst (MS Excel, Power BI) to manipulate and present data and confidently and clearly manage internal stakeholders. A strong interest and broad knowledge of Cyber Security would be highly regarded. What you'll be doing: Vulnerability Assessment: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications. Vulnerability Reporting: Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders. Vulnerability Management: Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritization, tracking, and reporting. Risk Analysis: Analysing the impact and severity of identified vulnerabilities Remediation Planning: Collaborating with system administrators, developers, and other stakeholders Patch Management: Working closely with IT teams to ensure that security patches and updates are applied promptly Security Awareness: Providing guidance and training to employees. What you'll bring: Strong analytical and investigative skills, using MS Excel and PowerBI confidently Effective communication (written and verbal) and collaboration across different teams. Critical thinking and problem-solving abilities. Prioritisation: working in a rapidly changing environment, you'll need to be able to prioritise multiple activities. Initiative: the ability to work on your own initiative and take responsibility for your and team deliverables. Positive attitude: having a willingness to learn and develop yourself. Relevant University degree in Computer / Cyber Security / Engineering and Security certifications will be an advantage e.g. CISSP, CISM, SEC+, GIAC Security Essentials (GSEC). Knowledge of cybersecurity, physical security, and risk management principles as well as Operational Technology (OT) and Critical National Infrastructure (CNI). Ability to adapt to evolving threat landscapes. Detailed knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems. Security Clearance: This role is subject to National Security Vetting (NSV). Candidates must be eligible to obtain and maintain Security Clearance (SC) throughout their employment. For further information, visit (UK Security Vetting: Clearance Levels). What we can offer you: Double-match pension (up to 12% company contribution) Annual performance bonus up to 6% Salary sacrifice car scheme 10x salary life assurance and income protection Flexible benefits including healthcare, dental, and technology options Family-friendly policies, wellbeing support, and professional development opportunities Inclusive recruitment: We're building a workforce that reflects the communities we serve, championing diversity, and creating an inclusive workplace where everyone is valued for their unique contribution. We support reasonable adjustments throughout the recruitment process and beyond. National Gas is a Disability Confident employer and signatory of the Armed Forces Covenant. More Information Advert close: 29th July 2026, with interviews soon after
26/07/2026
Full time
Select how often (in days) to receive an alert: Vulnerability Analyst/ Cyber Security Data Analyst Warwick, Hybrid flexible working At National Gas, the work we do matters. As Britain's national gas network, we help keep the lights on, businesses running, and homes warm by maintaining the critical infrastructure that transports gas across Great Britain. While providing the energy security Britain relies on today, we're also helping transform the network for a clean energy future. Join us and help secure Britain's energy. About the role: The Attack Surface Reduction (ASR) team within Cyber Security is responsible for identifying, measuring and reducing security risk across National Gas by proactively testing, assessing and challenging the resilience of our technology and operational environments. The Vulnerability Analyst (or Cyber Security Data Analyst) helps to deliver a comprehensive programme of security testing, including vulnerability scanning and security configuration reviews, ensuring weaknesses are identified early and accurately. For this role we can consider a strong Data Analyst (MS Excel, Power BI) to manipulate and present data and confidently and clearly manage internal stakeholders. A strong interest and broad knowledge of Cyber Security would be highly regarded. What you'll be doing: Vulnerability Assessment: Conducting regular vulnerability assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications. Vulnerability Reporting: Generating detailed vulnerability assessment reports, including findings, recommendations, and risk assessments, to communicate the status of vulnerabilities to management and stakeholders. Vulnerability Management: Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritization, tracking, and reporting. Risk Analysis: Analysing the impact and severity of identified vulnerabilities Remediation Planning: Collaborating with system administrators, developers, and other stakeholders Patch Management: Working closely with IT teams to ensure that security patches and updates are applied promptly Security Awareness: Providing guidance and training to employees. What you'll bring: Strong analytical and investigative skills, using MS Excel and PowerBI confidently Effective communication (written and verbal) and collaboration across different teams. Critical thinking and problem-solving abilities. Prioritisation: working in a rapidly changing environment, you'll need to be able to prioritise multiple activities. Initiative: the ability to work on your own initiative and take responsibility for your and team deliverables. Positive attitude: having a willingness to learn and develop yourself. Relevant University degree in Computer / Cyber Security / Engineering and Security certifications will be an advantage e.g. CISSP, CISM, SEC+, GIAC Security Essentials (GSEC). Knowledge of cybersecurity, physical security, and risk management principles as well as Operational Technology (OT) and Critical National Infrastructure (CNI). Ability to adapt to evolving threat landscapes. Detailed knowledge of the hardware and software systems in use across both IT and OT domains and the architectural arrangements in place to support management and operation of systems. Security Clearance: This role is subject to National Security Vetting (NSV). Candidates must be eligible to obtain and maintain Security Clearance (SC) throughout their employment. For further information, visit (UK Security Vetting: Clearance Levels). What we can offer you: Double-match pension (up to 12% company contribution) Annual performance bonus up to 6% Salary sacrifice car scheme 10x salary life assurance and income protection Flexible benefits including healthcare, dental, and technology options Family-friendly policies, wellbeing support, and professional development opportunities Inclusive recruitment: We're building a workforce that reflects the communities we serve, championing diversity, and creating an inclusive workplace where everyone is valued for their unique contribution. We support reasonable adjustments throughout the recruitment process and beyond. National Gas is a Disability Confident employer and signatory of the Armed Forces Covenant. More Information Advert close: 29th July 2026, with interviews soon after
Senior Application Security Engineer (SCA/SAST) Scale Security. Empower Engineers. Shape the Future. Location: UK - Remote The Mission At Trimble, we aren't just building software; we're transforming the way the world works. We are looking for a Senior Application Security Engineer who is more than a technical expert-you are a strategist and a catalyst for secure innovation. You will lead the charge in open-source security (SCA) and static analysis (SAST) across a massive global footprint, ensuring that security is a seamless part of the developer experience. Why This Role? Global Influence: You won't just be "fixing bugs." You will be the architect of a global security strategy that impacts 99% of our engineering teams. Strategic Autonomy: Lead the vision for our SCA and SAST roadmaps. You have the seat at the table to decide how we evolve. Innovation at Scale: Work across diverse tech stacks-from .NET and Java to Go and Python-integrating security directly into the heartbeat of our CI/CD pipelines. How You'll Make an Impact Strategic Leadership Act as the global SME for SCA and SAST, turning complex security requirements into scalable, automated solutions. Optimize our security tooling to be "developer-first," slashing false positives and focusing engineering energy on what truly matters. Shape the organizational approach to open-source security and license compliance. Engineering Excellence Embed security into the DNA of the SDLC by collaborating with architects and product owners worldwide. Automate everything. You'll build the "guardrails" that allow our developers to move fast without breaking things. Mentor the next generation of security talent and lead through influence across cross functional teams. Vision & Advisory Stay ahead of the curve. You'll evaluate emerging security tech and proactively keep Trimble at the cutting edge. Conduct threat modeling and architectural reviews to kill vulnerabilities before they are ever coded. The Profile We're Looking For The Architect: 5+ years in AppSec with a deep, battle tested mastery of SCA and SAST implementation at an enterprise level. The Polyglot: You speak the language of developers. Whether it's Java, C#, Python, or Go, you can read the code and provide real remediation paths. The Integrator: You live in the pipeline. You have hands on experience with GitHub Actions, Jenkins, Azure DevOps, or GitLab CI. The Communicator: You can translate "security risk" into "business value" for stakeholders and "clear action" for engineers. Education: Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. How to Apply: Please submit an online application for this position by clicking on the "Apply Now" button located in this posting. Join a Values-Driven Team: Belong, Grow, Innovate. At Trimble, our core values of Belong, Grow, and Innovate aren't just words-they're the foundation of our culture. We foster an environment where you are seen, heard, and valued (Belong); where you have an opportunity to build a career and drive our collective growth (Grow); and where your innovative ideas shape the future (Innovate). We believe in empowering local teams to create impactful strategies, ensuring our global vision resonates with every individual. Become part of a team where your contributions truly matter. Trimble's Privacy Policy If you need assistance or would like to request an accommodation in connection with the application process, please contact .
26/07/2026
Full time
Senior Application Security Engineer (SCA/SAST) Scale Security. Empower Engineers. Shape the Future. Location: UK - Remote The Mission At Trimble, we aren't just building software; we're transforming the way the world works. We are looking for a Senior Application Security Engineer who is more than a technical expert-you are a strategist and a catalyst for secure innovation. You will lead the charge in open-source security (SCA) and static analysis (SAST) across a massive global footprint, ensuring that security is a seamless part of the developer experience. Why This Role? Global Influence: You won't just be "fixing bugs." You will be the architect of a global security strategy that impacts 99% of our engineering teams. Strategic Autonomy: Lead the vision for our SCA and SAST roadmaps. You have the seat at the table to decide how we evolve. Innovation at Scale: Work across diverse tech stacks-from .NET and Java to Go and Python-integrating security directly into the heartbeat of our CI/CD pipelines. How You'll Make an Impact Strategic Leadership Act as the global SME for SCA and SAST, turning complex security requirements into scalable, automated solutions. Optimize our security tooling to be "developer-first," slashing false positives and focusing engineering energy on what truly matters. Shape the organizational approach to open-source security and license compliance. Engineering Excellence Embed security into the DNA of the SDLC by collaborating with architects and product owners worldwide. Automate everything. You'll build the "guardrails" that allow our developers to move fast without breaking things. Mentor the next generation of security talent and lead through influence across cross functional teams. Vision & Advisory Stay ahead of the curve. You'll evaluate emerging security tech and proactively keep Trimble at the cutting edge. Conduct threat modeling and architectural reviews to kill vulnerabilities before they are ever coded. The Profile We're Looking For The Architect: 5+ years in AppSec with a deep, battle tested mastery of SCA and SAST implementation at an enterprise level. The Polyglot: You speak the language of developers. Whether it's Java, C#, Python, or Go, you can read the code and provide real remediation paths. The Integrator: You live in the pipeline. You have hands on experience with GitHub Actions, Jenkins, Azure DevOps, or GitLab CI. The Communicator: You can translate "security risk" into "business value" for stakeholders and "clear action" for engineers. Education: Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. How to Apply: Please submit an online application for this position by clicking on the "Apply Now" button located in this posting. Join a Values-Driven Team: Belong, Grow, Innovate. At Trimble, our core values of Belong, Grow, and Innovate aren't just words-they're the foundation of our culture. We foster an environment where you are seen, heard, and valued (Belong); where you have an opportunity to build a career and drive our collective growth (Grow); and where your innovative ideas shape the future (Innovate). We believe in empowering local teams to create impactful strategies, ensuring our global vision resonates with every individual. Become part of a team where your contributions truly matter. Trimble's Privacy Policy If you need assistance or would like to request an accommodation in connection with the application process, please contact .
To define solution architecture based on business requirements and established standards in line with the defined future state enterprise IT landscape. Key Responsibilities 1. To assess the domain IT landscape assessment and Application portfolio optimization for gap analysis 2. Creation of solution and architectural views (logical conceptual development execution infrastructure & operations architecture) 3. To study and define system requirements addressing stakeholder portfolio concerns 4. To ensure knowledge up-gradation and work with new and emerging products/technologies 5. To manage Non Functional Requirement adaption for the solution 6. To contribute towards white/technical papers and knowledge base Skill Requirements Strong Application Security or DevSecOps Engineer with hands-on experience implementing Secure SDLC for Java/Spring Boot and React/Angular applications. Experience integrating enterprise application security tools such as SonarQube, CodeQL, Checkmarx, Fortify, Veracode, Trivy and OWASP ZAP into CI/CD pipelines. Strong understanding of secure coding practices, OWASP Top 10, threat modeling and vulnerability remediation for modern web applications. Working knowledge of React, Angular and Spring Boot application architecture to effectively identify vulnerabilities and recommend secure code fixes. Proficient in Python-based automation and API integrations. Hands-on experience using GitHub Copilot and/or Gemini Code Assist for AI-assisted secure code review and remediation. Experience deploying and supporting enterprise applications on Google Cloud Platform (GCP) and Red Hat OpenShift. Passion for applying AI to improve application security, automate vulnerability management and enhance developer productivity. At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first. HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026totaled $14.8billion.
26/07/2026
Full time
To define solution architecture based on business requirements and established standards in line with the defined future state enterprise IT landscape. Key Responsibilities 1. To assess the domain IT landscape assessment and Application portfolio optimization for gap analysis 2. Creation of solution and architectural views (logical conceptual development execution infrastructure & operations architecture) 3. To study and define system requirements addressing stakeholder portfolio concerns 4. To ensure knowledge up-gradation and work with new and emerging products/technologies 5. To manage Non Functional Requirement adaption for the solution 6. To contribute towards white/technical papers and knowledge base Skill Requirements Strong Application Security or DevSecOps Engineer with hands-on experience implementing Secure SDLC for Java/Spring Boot and React/Angular applications. Experience integrating enterprise application security tools such as SonarQube, CodeQL, Checkmarx, Fortify, Veracode, Trivy and OWASP ZAP into CI/CD pipelines. Strong understanding of secure coding practices, OWASP Top 10, threat modeling and vulnerability remediation for modern web applications. Working knowledge of React, Angular and Spring Boot application architecture to effectively identify vulnerabilities and recommend secure code fixes. Proficient in Python-based automation and API integrations. Hands-on experience using GitHub Copilot and/or Gemini Code Assist for AI-assisted secure code review and remediation. Experience deploying and supporting enterprise applications on Google Cloud Platform (GCP) and Red Hat OpenShift. Passion for applying AI to improve application security, automate vulnerability management and enhance developer productivity. At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first. HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026totaled $14.8billion.
Senior Web Security Engineer (ProdSec) at iProov Senior Web Security Engineer About iProov iProov provides science-based biometric solutions that enable the world's most security-conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Our award-winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, GovTech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance. This global trust is built not only on our technology but on the strength of the people behind it. For us, diversity at iProov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together. We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose. The Role Reports to: Head of Red Team Location: UK (Flexible) Comp: Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK iProov Benefits We're looking for an experienced Senior Web Security Engineer to design, build, and secure high-performance web applications that run in some of the world's most demanding environments. How you can make an impact Develop techniques to protect client-side code from tampering, reverse engineering, debugging, automation, and exploitation. Design and implement anti-tamper, integrity verification, and runtime protection mechanisms. Build high-performance WebAssembly modules using C++, Rust, or AssemblyScript. Research emerging attack techniques targeting web applications and develop practical mitigations. Collaborate closely with developers, product, and red teams to integrate security into the development lifecycle. Investigate vulnerabilities, perform root-cause analysis, and develop long-term remediation strategies. Contribute to technical architecture and mentor other engineers on secure development practices. What we would like to see from you Technical Expertise Strong experience developing production WebAssembly applications. Experience with Rust, C++, or another systems programming language used to produce WASM modules. Experience securing client-side applications against: Reverse engineering Runtime modification Instrumentation frameworks Code injection Experience with secure software architecture. Security Knowledge Experience in several of the following: WASM binary analysis Static and dynamic analysis Anti-debugging techniques Runtime integrity verification Secure code signing and integrity checking Software protection techniques Secure SDLC practices 5+ years of software engineering experience. Strong testing, debugging, and profiling skills. Experience working with CI/CD pipelines and automated security testing. Excellent communication skills with the ability to explain complex technical concepts clearly. Nice to Have Knowledge of WebGPU, WebRTC, or WebCodecs. Experience with binary instrumentation and compiler toolchains. Experience building SDKs or developer platforms. Experience with biometrics, identity verification, or fraud prevention technologies. Contributions to open-source security tools or security research publications. 25 days Annual Leave, plus 8 Bank Holidays (more holiday with service - up to an extra 5 days off per year based on your continuous service) Growth Shares allocated after passing probation (6 months of service) Salary sacrifice schemes including: Pension, Cycle To Work and Electric Car Scheme Nursery Sacrifice Scheme Work Overseas Perk - Work globally for up to 2 weeks Life Assurance SmartHealth - Access to private GP, Psychologist, Nutritionist along with tailored fitness plans for both you and your family Benefit from personalized 1:1 career coaching with our in-house Occupational Psychologist Award winning L&D platform with personal allocated training budgets Enhanced paid family leave Flexible hybrid working environment Free Barista Coffee/Tea, biscuits with fruit in the WeWork office Free access to WeWork discounts and free online well-being sessions Vitality Health - a range of options available on this below The Vitality Programme includes a number of reward benefits that all employees have access to as part of the plan, for example: Private Health cover including Dental, Optical, and Audiology 50% off monthly gym memberships Apple watches significantly discounted based member vitality status Half price trainers with Runners Need Weekly rewards - Free coffee with Café Nero Monthly rewards - Free Cinema ticket Discounts on travel with Expedia (hotels) and Mr & Mrs Smith with discounts getting greater throughout the year based on a members vitality status Amazon prime free months based on activity Up to 25% cashback at Waitrose when buying healthy foods 75% off stays at Champneys Health Spas Allen Carr's £299 no smoking programme for freeAccess to Vitality Healthy Mind with 30% off Headspace subscriptions and the ability to earn Vitality points for using Buddhify, Calm and Headspace Discounts on Weight Watchers Our Culture & Recruitment Process At iProov, we're incredibly proud of the culture we've carefully curated. Our culture enables diverse thought, curiosity and innovation. Our team strives to do everything to the highest standard possible to achieve the remarkable. To do that we need different perspectives, experiences and ideas alongside an environment where these are welcomed - we want everyone to feel confident in bringing their full capabilities to work. We firmly believe psychological safety is key to building and nurturing great teams. We're a small and dynamic company, that means having the right skills is important, and we know that our best work emerges when people feel secure, welcomed and respected. As an equal opportunities employer, we encourage applications from people of all backgrounds. We're committed to building a workforce that is representative of the people we serve. We will not put someone at a disadvantage or treat them less favourably because of race, color, national origin, ancestry, age, disability, creed, religion or belief, sex, sexual orientation, gender reassignment, marriage or civil partnership, or pregnancy and maternity. Our goal is to find people who are passionate about creating a safer, more secure world. Our recruitment process is designed to be fair and transparent, focusing solely on your qualifications, competence, and suitability for the role. We review all applications carefully and will be in touch with shortlisted candidates regarding the next steps in our interview process. If you need an adjustment for a disability or any other reason during the hiring process, please send a request to
26/07/2026
Full time
Senior Web Security Engineer (ProdSec) at iProov Senior Web Security Engineer About iProov iProov provides science-based biometric solutions that enable the world's most security-conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Our award-winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, GovTech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance. This global trust is built not only on our technology but on the strength of the people behind it. For us, diversity at iProov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together. We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose. The Role Reports to: Head of Red Team Location: UK (Flexible) Comp: Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK iProov Benefits We're looking for an experienced Senior Web Security Engineer to design, build, and secure high-performance web applications that run in some of the world's most demanding environments. How you can make an impact Develop techniques to protect client-side code from tampering, reverse engineering, debugging, automation, and exploitation. Design and implement anti-tamper, integrity verification, and runtime protection mechanisms. Build high-performance WebAssembly modules using C++, Rust, or AssemblyScript. Research emerging attack techniques targeting web applications and develop practical mitigations. Collaborate closely with developers, product, and red teams to integrate security into the development lifecycle. Investigate vulnerabilities, perform root-cause analysis, and develop long-term remediation strategies. Contribute to technical architecture and mentor other engineers on secure development practices. What we would like to see from you Technical Expertise Strong experience developing production WebAssembly applications. Experience with Rust, C++, or another systems programming language used to produce WASM modules. Experience securing client-side applications against: Reverse engineering Runtime modification Instrumentation frameworks Code injection Experience with secure software architecture. Security Knowledge Experience in several of the following: WASM binary analysis Static and dynamic analysis Anti-debugging techniques Runtime integrity verification Secure code signing and integrity checking Software protection techniques Secure SDLC practices 5+ years of software engineering experience. Strong testing, debugging, and profiling skills. Experience working with CI/CD pipelines and automated security testing. Excellent communication skills with the ability to explain complex technical concepts clearly. Nice to Have Knowledge of WebGPU, WebRTC, or WebCodecs. Experience with binary instrumentation and compiler toolchains. Experience building SDKs or developer platforms. Experience with biometrics, identity verification, or fraud prevention technologies. Contributions to open-source security tools or security research publications. 25 days Annual Leave, plus 8 Bank Holidays (more holiday with service - up to an extra 5 days off per year based on your continuous service) Growth Shares allocated after passing probation (6 months of service) Salary sacrifice schemes including: Pension, Cycle To Work and Electric Car Scheme Nursery Sacrifice Scheme Work Overseas Perk - Work globally for up to 2 weeks Life Assurance SmartHealth - Access to private GP, Psychologist, Nutritionist along with tailored fitness plans for both you and your family Benefit from personalized 1:1 career coaching with our in-house Occupational Psychologist Award winning L&D platform with personal allocated training budgets Enhanced paid family leave Flexible hybrid working environment Free Barista Coffee/Tea, biscuits with fruit in the WeWork office Free access to WeWork discounts and free online well-being sessions Vitality Health - a range of options available on this below The Vitality Programme includes a number of reward benefits that all employees have access to as part of the plan, for example: Private Health cover including Dental, Optical, and Audiology 50% off monthly gym memberships Apple watches significantly discounted based member vitality status Half price trainers with Runners Need Weekly rewards - Free coffee with Café Nero Monthly rewards - Free Cinema ticket Discounts on travel with Expedia (hotels) and Mr & Mrs Smith with discounts getting greater throughout the year based on a members vitality status Amazon prime free months based on activity Up to 25% cashback at Waitrose when buying healthy foods 75% off stays at Champneys Health Spas Allen Carr's £299 no smoking programme for freeAccess to Vitality Healthy Mind with 30% off Headspace subscriptions and the ability to earn Vitality points for using Buddhify, Calm and Headspace Discounts on Weight Watchers Our Culture & Recruitment Process At iProov, we're incredibly proud of the culture we've carefully curated. Our culture enables diverse thought, curiosity and innovation. Our team strives to do everything to the highest standard possible to achieve the remarkable. To do that we need different perspectives, experiences and ideas alongside an environment where these are welcomed - we want everyone to feel confident in bringing their full capabilities to work. We firmly believe psychological safety is key to building and nurturing great teams. We're a small and dynamic company, that means having the right skills is important, and we know that our best work emerges when people feel secure, welcomed and respected. As an equal opportunities employer, we encourage applications from people of all backgrounds. We're committed to building a workforce that is representative of the people we serve. We will not put someone at a disadvantage or treat them less favourably because of race, color, national origin, ancestry, age, disability, creed, religion or belief, sex, sexual orientation, gender reassignment, marriage or civil partnership, or pregnancy and maternity. Our goal is to find people who are passionate about creating a safer, more secure world. Our recruitment process is designed to be fair and transparent, focusing solely on your qualifications, competence, and suitability for the role. We review all applications carefully and will be in touch with shortlisted candidates regarding the next steps in our interview process. If you need an adjustment for a disability or any other reason during the hiring process, please send a request to
Who we are We're Super Group, the NYSE-listed digital gaming company behind some of the world's leading Sports and iGaming brands, including Betway and Jackpot City. We're a powerhouse built on decades of expertise and we're changing the game for good. Our mission is to give our customers a superclass entertainment experience. Who we're looking for We're on a thrilling journey of growth and innovation, and we need passionate, driven individuals to join us. At Super Group International, every day is action-packed, and we expect you to bring your A-game. In return, you'll find a supportive environment where your skills can flourish and your career can soar. Ready to become a game changer? Supercharge your career with us and be part of something extraordinary. Why we need you We're building experiences that wow our customers - and that starts with bold, curious people who want to do work that matters. If you're hungry to grow, excited by impact and ready for a challenge that will supercharge your career, this could be your moment. As our Senior DevSecOps Engineer, you'll play a key part in delivering secure applications and hands on security support to our developers to ensure they are fixing the right things, getting hands on as a technical authority across development, platform, operations, and information security, this is a multi disciplinary engineering role with a focus on application and platform security controls, working closely with development teams to improve security outcomes. Your drive and ideas will help us move faster, improve smarter, and stay ahead of the game. What you'll do Development and Application Security by Design Integrate and operate application security controls within CI/CD pipelines, including: Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Secrets detection and dependency risk scanning Support secure SDLC practices such as: Branch protection and quality gates, Secure build and release controls, Artifact integrity and validation checks Assist with threat modelling and secure design reviews in collaboration with architecture teams. Support developers in vulnerability triage and remediation. Tune security tools to reduce false positives and developer friction. Support audit, compliance, and evidence generation activities. Participate in security incident investigation related to application flaws. Ensure secure, compliant approaches are the default and easiest options for development teams to adopt. Configure and maintain security tooling integrations within CI/CD systems (e.g. GitHub Actions, GitLab CI, Jenkins, Azure DevOps) under agreed architectural standards Ensure security controls operate consistently across teams and repositories. Governance, Risk & Assurance Define and document DevSec security standards, patterns, and decisions. Provide evidence and control mappings to support audits, risk assessments, and regulatory reviews. Identify and track DevSec related risks and technical debt, driving remediation through process improvements rather than manual controls. Stakeholder Collaboration Influence security outcomes through collaboration and technical leadership rather than enforcement. Contribute to security enablement, awareness, and uplift initiatives focused on cloud native and container security practices. What you'll bring You're someone who brings: Clear, confident communication (written and verbal), and the ability to breakdown complex ideas A collaborative mindset, working smoothly with cross functional teams to hit shared goals Strong organisational skills and the ability to manage multiple projects without dropping the ball Exceptional attention to detail and a commitment to high quality work Adaptability - you stay sharp, productive and positive in fast moving environments Strong grounding in application security concepts. Secure coding knowledge (OWASP Top 10, API security, dependency risk). Strong knowledge of SAST, DAST, SCA, and software supply chain security concepts. Strong advocate for enablement first security. Ability to influence engineering teams through collaboration and technical credibility. Hands on expertise with containers and orchestration platforms (e.g. Docker, Kubernetes). Demonstrated experience implementing container security across build, registry, and runtime. Proven experience securing CI/CD pipelines and developer toolchains. Knowledge of: Infrastructure as Code (Terraform, Bicep, CloudFormation, etc.) Secrets and key management Cloud identity and access management Solid understanding of information security frameworks (e.g. ISO 27001). Experience operating in regulated or audited environments. Able to design controls that are auditable without slowing delivery. Desirable skills you've got up your sleeve It would be great if you also have some the following skills: In-depth knowledge of sports betting markets, including odds calculation, betting types and market trends Previous experience in the online gaming or casino industry, with a strong understanding of player behaviour and industry regulations Familiarity with gambling regulations and compliance requirements in various jurisdictions, ensuring adherence to legal standards Experience in developing and executing customer retention strategies Experience operating at scale in multi team or multinational environments. Prior involvement in audits, regulatory reviews, or formal assurance activities. Our values are non negotiables Our culture is underpinned by core values that are linked to key behavioural competencies. Along with the below behavioural competencies, these are essential for all employees in order for you to embed in and drive our culture forward. These competencies are: Adaptability Ownership and accountability Initiating action Resilience Team orientation Integrity Innovation What you'll get back We invest in your growth and wellbeing, so you can bring your best: Supergrowth is real here. Our learning and development programmes give you the tools, training and opportunities to level up fast. Your progress matters. Our Performance tool ensures you get meaningful feedback to support your development and superdrive your career. Support that has your back. Our Employee Assistance Programme offers resources for you and your family. Private Health Care Life Assurance & Income Protection Company Pension Ready to feel superclass? At Super Group, your experience matters. We're honest, fair, and focused on helping you succeed - and your work will have real impact from day one. Betway Group is a proud member of Super Group, who are listed on the New York Stock Exchange (ticker: SGHC). We are a leading provider of innovative and exciting entertainment across sports betting, casino and esports betting. Founded in 2006, our teams in Malta, Guernsey, Spain and London are constantly expanding and evolving. By developing and utilising the very latest technologies,we have remained at the forefront of the online gaming industry, providing innovative and interactive gaming experiences in a fair, safe and responsible environment. Driven by our shared vision to become the global leader in the online sports betting and casino industry, our people are forward thinking, team players who thrive on a collective diversity of skills and backgrounds. We provide our teams with the tools to create market leading, cutting edge interactive gaming experiences, from pre game and live sports betting, to esports and casino. We bring our people closer to the action - putting them at the heart, making them feel part of it. We live and breathe our values - these values define how we conduct ourselves in everything we do shaping how we interact with each other, our customers and our business partners. If you can imagine yourself in an environment which thrives off collaboration, and where everything is possible, then Betway could be the place for you.
26/07/2026
Full time
Who we are We're Super Group, the NYSE-listed digital gaming company behind some of the world's leading Sports and iGaming brands, including Betway and Jackpot City. We're a powerhouse built on decades of expertise and we're changing the game for good. Our mission is to give our customers a superclass entertainment experience. Who we're looking for We're on a thrilling journey of growth and innovation, and we need passionate, driven individuals to join us. At Super Group International, every day is action-packed, and we expect you to bring your A-game. In return, you'll find a supportive environment where your skills can flourish and your career can soar. Ready to become a game changer? Supercharge your career with us and be part of something extraordinary. Why we need you We're building experiences that wow our customers - and that starts with bold, curious people who want to do work that matters. If you're hungry to grow, excited by impact and ready for a challenge that will supercharge your career, this could be your moment. As our Senior DevSecOps Engineer, you'll play a key part in delivering secure applications and hands on security support to our developers to ensure they are fixing the right things, getting hands on as a technical authority across development, platform, operations, and information security, this is a multi disciplinary engineering role with a focus on application and platform security controls, working closely with development teams to improve security outcomes. Your drive and ideas will help us move faster, improve smarter, and stay ahead of the game. What you'll do Development and Application Security by Design Integrate and operate application security controls within CI/CD pipelines, including: Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Secrets detection and dependency risk scanning Support secure SDLC practices such as: Branch protection and quality gates, Secure build and release controls, Artifact integrity and validation checks Assist with threat modelling and secure design reviews in collaboration with architecture teams. Support developers in vulnerability triage and remediation. Tune security tools to reduce false positives and developer friction. Support audit, compliance, and evidence generation activities. Participate in security incident investigation related to application flaws. Ensure secure, compliant approaches are the default and easiest options for development teams to adopt. Configure and maintain security tooling integrations within CI/CD systems (e.g. GitHub Actions, GitLab CI, Jenkins, Azure DevOps) under agreed architectural standards Ensure security controls operate consistently across teams and repositories. Governance, Risk & Assurance Define and document DevSec security standards, patterns, and decisions. Provide evidence and control mappings to support audits, risk assessments, and regulatory reviews. Identify and track DevSec related risks and technical debt, driving remediation through process improvements rather than manual controls. Stakeholder Collaboration Influence security outcomes through collaboration and technical leadership rather than enforcement. Contribute to security enablement, awareness, and uplift initiatives focused on cloud native and container security practices. What you'll bring You're someone who brings: Clear, confident communication (written and verbal), and the ability to breakdown complex ideas A collaborative mindset, working smoothly with cross functional teams to hit shared goals Strong organisational skills and the ability to manage multiple projects without dropping the ball Exceptional attention to detail and a commitment to high quality work Adaptability - you stay sharp, productive and positive in fast moving environments Strong grounding in application security concepts. Secure coding knowledge (OWASP Top 10, API security, dependency risk). Strong knowledge of SAST, DAST, SCA, and software supply chain security concepts. Strong advocate for enablement first security. Ability to influence engineering teams through collaboration and technical credibility. Hands on expertise with containers and orchestration platforms (e.g. Docker, Kubernetes). Demonstrated experience implementing container security across build, registry, and runtime. Proven experience securing CI/CD pipelines and developer toolchains. Knowledge of: Infrastructure as Code (Terraform, Bicep, CloudFormation, etc.) Secrets and key management Cloud identity and access management Solid understanding of information security frameworks (e.g. ISO 27001). Experience operating in regulated or audited environments. Able to design controls that are auditable without slowing delivery. Desirable skills you've got up your sleeve It would be great if you also have some the following skills: In-depth knowledge of sports betting markets, including odds calculation, betting types and market trends Previous experience in the online gaming or casino industry, with a strong understanding of player behaviour and industry regulations Familiarity with gambling regulations and compliance requirements in various jurisdictions, ensuring adherence to legal standards Experience in developing and executing customer retention strategies Experience operating at scale in multi team or multinational environments. Prior involvement in audits, regulatory reviews, or formal assurance activities. Our values are non negotiables Our culture is underpinned by core values that are linked to key behavioural competencies. Along with the below behavioural competencies, these are essential for all employees in order for you to embed in and drive our culture forward. These competencies are: Adaptability Ownership and accountability Initiating action Resilience Team orientation Integrity Innovation What you'll get back We invest in your growth and wellbeing, so you can bring your best: Supergrowth is real here. Our learning and development programmes give you the tools, training and opportunities to level up fast. Your progress matters. Our Performance tool ensures you get meaningful feedback to support your development and superdrive your career. Support that has your back. Our Employee Assistance Programme offers resources for you and your family. Private Health Care Life Assurance & Income Protection Company Pension Ready to feel superclass? At Super Group, your experience matters. We're honest, fair, and focused on helping you succeed - and your work will have real impact from day one. Betway Group is a proud member of Super Group, who are listed on the New York Stock Exchange (ticker: SGHC). We are a leading provider of innovative and exciting entertainment across sports betting, casino and esports betting. Founded in 2006, our teams in Malta, Guernsey, Spain and London are constantly expanding and evolving. By developing and utilising the very latest technologies,we have remained at the forefront of the online gaming industry, providing innovative and interactive gaming experiences in a fair, safe and responsible environment. Driven by our shared vision to become the global leader in the online sports betting and casino industry, our people are forward thinking, team players who thrive on a collective diversity of skills and backgrounds. We provide our teams with the tools to create market leading, cutting edge interactive gaming experiences, from pre game and live sports betting, to esports and casino. We bring our people closer to the action - putting them at the heart, making them feel part of it. We live and breathe our values - these values define how we conduct ourselves in everything we do shaping how we interact with each other, our customers and our business partners. If you can imagine yourself in an environment which thrives off collaboration, and where everything is possible, then Betway could be the place for you.
Lead the design of the control suite and partner with the Domain Architect on architecture decisions. Act as a hands on technical lead, implementing solutions and helping developers execute the vision. Design and implement Proof of Concepts to validate the Architecture guidelines and governance Review code and mentor less experienced developers. Bridge the gap between business requirements and technical implementation. Provide architectural and technical guidance for remediation agents, continuous testing suites, and automated control frameworks Required Skills & Experience: Technical Proficiency: Strong hands on expertise in Java and Python. Cloud/Architecture: Expertise in AWS Services (specifically AWS Bedrock and AWS Step Functions). Agentic/Automation: Deep knowledge of agentic AI, remediation bots, and automated control frameworks. Data/Security: Strong understanding of data lineage, data sources/databases (NoSQL), and risk/governance/compliance frameworks (e.g. CMMI). Tools: Proficiency with GitHub, Jira, and X-ray for test management. Soft Skills: Proven ability to work in an ambiguous, rapidly evolving program, provide course correction, and act as a solution provider rather than just an order-taker. Excellent communication and team collaboration skills are critical. Benefits at IntelliBee Long-Term Stability: Join us on a multi-year opportunities with room to grow. Comprehensive Health Coverage: Access quality healthcare benefits to keep you and your family well. Future Planning: Enroll in our 401(k) program and invest in your financial security. GC Assistance: We support immediate Green Card processing, if required.
26/07/2026
Full time
Lead the design of the control suite and partner with the Domain Architect on architecture decisions. Act as a hands on technical lead, implementing solutions and helping developers execute the vision. Design and implement Proof of Concepts to validate the Architecture guidelines and governance Review code and mentor less experienced developers. Bridge the gap between business requirements and technical implementation. Provide architectural and technical guidance for remediation agents, continuous testing suites, and automated control frameworks Required Skills & Experience: Technical Proficiency: Strong hands on expertise in Java and Python. Cloud/Architecture: Expertise in AWS Services (specifically AWS Bedrock and AWS Step Functions). Agentic/Automation: Deep knowledge of agentic AI, remediation bots, and automated control frameworks. Data/Security: Strong understanding of data lineage, data sources/databases (NoSQL), and risk/governance/compliance frameworks (e.g. CMMI). Tools: Proficiency with GitHub, Jira, and X-ray for test management. Soft Skills: Proven ability to work in an ambiguous, rapidly evolving program, provide course correction, and act as a solution provider rather than just an order-taker. Excellent communication and team collaboration skills are critical. Benefits at IntelliBee Long-Term Stability: Join us on a multi-year opportunities with room to grow. Comprehensive Health Coverage: Access quality healthcare benefits to keep you and your family well. Future Planning: Enroll in our 401(k) program and invest in your financial security. GC Assistance: We support immediate Green Card processing, if required.
Join us to directly influence the future of technology at JPMorganChase. As a Senior Security Architect - SecOps and Vulnerability Management, you'll collaborate with top cybersecurity and engineering talent, solving complex challenges and enabling safe, secure innovation. Your passion for security and drive to make a real impact are valued here. Grow your skills in a dynamic environment designed for achievers. Help us build products that prioritize security from the start. Job Summary: As a Senior Security Architect - SecOps and Vulnerability Management in the Cybersecurity & Technology Controls team for International Consumer, you will proactively partner with technology and business colleagues to identify and address security issues. You will embed security culture, lead threat modeling, and drive architecture reviews to ensure our products are secure by design. Your role will be pivotal in managing emerging risks, influencing product strategy, and serving as the subject matter expert for the SecOps and Vulnerability Management strategy as well as embedding detection and response capabilities on a modern technology stack. You will collaborate globally, supporting audit, regulatory, and risk initiatives, with a focus on cloud computing and emerging technologies. Job Responsibilities: Design, scale, and manage the enterprise SIEM architecture to provide centralized visibility and high-fidelity threat detection across all corporate and cloud infrastructure. Develop and influence advanced SIEM correlation rules, custom data parsers, and detection logic to significantly minimize alert fatigue for the SOC team. Architect the end-to-end SBOM lifecycle to continuously track, analyze, and mitigate open-source and third-party software supply chain risks. Design a risk-based vulnerability management platform that automatically prioritizes infrastructure and application flaws utilizing real-world exploit intelligence and asset criticality. Build and optimize SOAR playbooks to automate incident response workflows, accelerate threat containment, and streamline vulnerability ticketing. Provide senior technical escalation support during critical security incidents and drive post-incident root-cause analysis to continuously improve defensive controls. Cultivate a security-first culture across product, technology, and business teams by providing developer-friendly tooling, training, and reusable secure patterns that accelerate rather than hinder delivery. Act with urgency to manage emerging security issues, monitor risk indicators, and recommend resolutions. Serve as the escalation point for IT Risk and Cyber domains related to Cybersecurity Operations and Vulnerability Management. Partner with engineering leads, product owners, and vendors to ensure effective technology risk management, translating regulatory and policy requirements into actionable, engineer-friendly controls. Support audit, regulatory, and risk activities by providing evidence of control effectiveness and translating compliance requirements into automated, repeatable processes. Identify and address unfamiliar technology components, share best practices, and influence peers to drive continuous improvement in SecOps and Vulnerability Management maturity across the organization. Uses enterprise-authorized AI capabilities within the work environment to accelerate cybersecurity risk analysis and control assessment, validating outputs and handling data according to sensitivity and security requirements. Drives reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing, remediation quality, and traceability/auditability in line with resiliency expectations. Required Qualifications, Capabilities, and Skills: Hands-on experience advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules). Deep execution knowledge of generating, managing, and analyzing Software Bills of Materials (SBOMs using frameworks like CycloneDX or SPDX) and integrating them with tools like Dependency-Track or Snyk to track open-source vulnerabilities. Advanced threat modeling experience (e.g., STRIDE-LM) for SIEM data flows, log ingestion pipelines, and vulnerability management platforms Experience architecting vulnerability programs using tools like Tenable, Qualys, or Wiz, specifically utilizing EPSS (Exploit Prediction Scoring System) alongside CVSS to determine patching prioritisation. Ability to design and influence automated response playbooks using SOAR platforms Practical experience creating reference architectures and patterns for engineering teams. Proven ability to design and deploy automated preventive and detective guardrails at scale. Ability to solve design and functionality problems independently. Strong written and verbal communication skills. Demonstrated success in influencing peers and stakeholders. Ability to evaluate and recommend emerging technologies for future state architecture. Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity. Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations. Preferred Qualifications, Capabilities, and Skills: Experience deploying AI-native capabilities within Google SecOps, leveraging Gemini-powered intelligence and ML-based anomaly detection to enhance UEBA and accelerate SOC triage at scale. Experience partnering with Red/Purple Teams to simulate attacks and actively validate that SIEM rules fire as intended. The ability to identify thematic vulnerability trends and common denominators to drive highest-impact, lowest-effort Vulnerability remediation. Experience operating in regulated organizations with a 3LoD model. Willingness to challenge existing processes respectfully. Experience translating policy and regulatory requirements into control design for engineers and architects. Proven ability to upskill and learn modern technologies. Experience in financial services consumer businesses or Fintech organizations.
26/07/2026
Full time
Join us to directly influence the future of technology at JPMorganChase. As a Senior Security Architect - SecOps and Vulnerability Management, you'll collaborate with top cybersecurity and engineering talent, solving complex challenges and enabling safe, secure innovation. Your passion for security and drive to make a real impact are valued here. Grow your skills in a dynamic environment designed for achievers. Help us build products that prioritize security from the start. Job Summary: As a Senior Security Architect - SecOps and Vulnerability Management in the Cybersecurity & Technology Controls team for International Consumer, you will proactively partner with technology and business colleagues to identify and address security issues. You will embed security culture, lead threat modeling, and drive architecture reviews to ensure our products are secure by design. Your role will be pivotal in managing emerging risks, influencing product strategy, and serving as the subject matter expert for the SecOps and Vulnerability Management strategy as well as embedding detection and response capabilities on a modern technology stack. You will collaborate globally, supporting audit, regulatory, and risk initiatives, with a focus on cloud computing and emerging technologies. Job Responsibilities: Design, scale, and manage the enterprise SIEM architecture to provide centralized visibility and high-fidelity threat detection across all corporate and cloud infrastructure. Develop and influence advanced SIEM correlation rules, custom data parsers, and detection logic to significantly minimize alert fatigue for the SOC team. Architect the end-to-end SBOM lifecycle to continuously track, analyze, and mitigate open-source and third-party software supply chain risks. Design a risk-based vulnerability management platform that automatically prioritizes infrastructure and application flaws utilizing real-world exploit intelligence and asset criticality. Build and optimize SOAR playbooks to automate incident response workflows, accelerate threat containment, and streamline vulnerability ticketing. Provide senior technical escalation support during critical security incidents and drive post-incident root-cause analysis to continuously improve defensive controls. Cultivate a security-first culture across product, technology, and business teams by providing developer-friendly tooling, training, and reusable secure patterns that accelerate rather than hinder delivery. Act with urgency to manage emerging security issues, monitor risk indicators, and recommend resolutions. Serve as the escalation point for IT Risk and Cyber domains related to Cybersecurity Operations and Vulnerability Management. Partner with engineering leads, product owners, and vendors to ensure effective technology risk management, translating regulatory and policy requirements into actionable, engineer-friendly controls. Support audit, regulatory, and risk activities by providing evidence of control effectiveness and translating compliance requirements into automated, repeatable processes. Identify and address unfamiliar technology components, share best practices, and influence peers to drive continuous improvement in SecOps and Vulnerability Management maturity across the organization. Uses enterprise-authorized AI capabilities within the work environment to accelerate cybersecurity risk analysis and control assessment, validating outputs and handling data according to sensitivity and security requirements. Drives reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing, remediation quality, and traceability/auditability in line with resiliency expectations. Required Qualifications, Capabilities, and Skills: Hands-on experience advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules). Deep execution knowledge of generating, managing, and analyzing Software Bills of Materials (SBOMs using frameworks like CycloneDX or SPDX) and integrating them with tools like Dependency-Track or Snyk to track open-source vulnerabilities. Advanced threat modeling experience (e.g., STRIDE-LM) for SIEM data flows, log ingestion pipelines, and vulnerability management platforms Experience architecting vulnerability programs using tools like Tenable, Qualys, or Wiz, specifically utilizing EPSS (Exploit Prediction Scoring System) alongside CVSS to determine patching prioritisation. Ability to design and influence automated response playbooks using SOAR platforms Practical experience creating reference architectures and patterns for engineering teams. Proven ability to design and deploy automated preventive and detective guardrails at scale. Ability to solve design and functionality problems independently. Strong written and verbal communication skills. Demonstrated success in influencing peers and stakeholders. Ability to evaluate and recommend emerging technologies for future state architecture. Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity. Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations. Preferred Qualifications, Capabilities, and Skills: Experience deploying AI-native capabilities within Google SecOps, leveraging Gemini-powered intelligence and ML-based anomaly detection to enhance UEBA and accelerate SOC triage at scale. Experience partnering with Red/Purple Teams to simulate attacks and actively validate that SIEM rules fire as intended. The ability to identify thematic vulnerability trends and common denominators to drive highest-impact, lowest-effort Vulnerability remediation. Experience operating in regulated organizations with a 3LoD model. Willingness to challenge existing processes respectfully. Experience translating policy and regulatory requirements into control design for engineers and architects. Proven ability to upskill and learn modern technologies. Experience in financial services consumer businesses or Fintech organizations.
What We Do At Goldman Sachs, our Engineers don't just make things - we make things possible. Change the world by connecting people and capital with ideas. Solve the most challenging and pressing engineering problems for our clients. Join our engineering teams that build massively scalable software and systems, architect low latency infrastructure solutions, proactively guard against cyber threats, and leverage machine learning alongside financial engineering to continuously turn data into action. Create new businesses, transform finance, and explore a world of opportunity at the speed of markets. Goldman Sachs Engineers are innovators and problem-solvers, building solutions in Artificial Intelligence, risk management, big data, mobile and more. As part of Core Engineering at Goldman Sachs, the CE&A team is responsible for enabling the use of public cloud services across the firm. You will be working as part of a multi-disciplinary team responsible for researching, architecting and building a cutting edge platform that enable Goldman Sachs Engineering teams to deploy and manage services in public cloud safely and securely. The organization is seeking highly collaborative, creative, and intellectually curious engineers who are passionate about developing and implementing cutting edge cloud computing and AI solutions. The ideal candidate will thrive in a DevOps culture and contribute to customer centric product development. They will work closely with cross functional teams, and will be creative collaborators who evolve, adapt to change and thrive in a fast paced global environment. Responsibilities And Qualifications: We are looking for a senior technical leader to join our Cloud Engineering & Architecture team and play a pivotal role in enabling the firm to maximize its use of cloud infrastructure. This is a hands on leadership position requiring deep technical expertise, strategic thinking, and the ability to drive large scale platform initiatives from conception to delivery. Key Responsibilities: Design, develop, and operationalize enterprise grade cloud platform capabilities. Architect scalable, resilient, and secure infrastructure solutions on AWS. Architect and operationalize autonomous AI based, self healing infrastructure Define technical standards, best practices, and reference architectures for cloud adoption across the firm. Partner with engineering teams to enable seamless migration and modernization of workloads to the cloud. Drive automation and infrastructure as code practices to improve operational efficiency. Drive AI powered FinOps and predictive resource optimization Mentor and guide engineers across teams, raising the overall technical bar. Collaborate with security, networking, and compliance teams to ensure platform meets regulatory and governance requirements. Evaluate emerging technologies and make recommendations for platform evolution. Participate in architecture design reviews and provide technical leadership on complex initiatives. Complementary AI Based Skills: LLM Orchestration & Agentic Workflows: Experience in designing, building, and deploying Large Language Model (LLM) orchestration frameworks (e.g., LangChain, Temporal, or custom agentic loops) to coordinate multi step diagnostic and remediation tasks. AIOps & Intelligent Observability: Ability to integrate traditional observability stacks (e.g., Datadog, Prometheus, OpenTelemetry) with AI/ML models to automate root cause analysis, anomaly detection, and semantic log clustering. Self Healing Infrastructure Engineering: Experience designing closed loop, self healing systems that autonomously execute recovery actions (e.g., traffic shifting, automated rollbacks, or service restarts) with built in verification and safety guardrails. AI Driven FinOps & Resource Optimization: Deep understanding of applying machine learning and predictive analytics to dynamically right size cloud resources, manage spot instances, and optimize data platform workloads. Predictive Capacity Planning: Ability to design algorithms that forecast workload demands and proactively scale infrastructure to prevent over provisioning while maintaining strict SLAs. Complementary Behaviours: Toil Reduction Mindset: A relentless focus on eliminating repetitive operational support and engineering friction by shifting platform operations from reactive troubleshooting to autonomous mitigation. Risk Aware Automation: Demonstrates a disciplined approach to safety by implementing strict confidence thresholds, validation loops, and human in the loop fallbacks for autonomous AI actions. Value Oriented Engineering: Treats cost optimization as a first class architectural metric, aligning infrastructure spend directly with business value and platform efficiency. Impact Preserving Innovation: Executes large scale optimization initiatives with a meticulous, risk mitigated approach, ensuring zero disruption to production environments or developer velocity. Basic Qualifications: 10+ years of experience in software engineering or infrastructure engineering. Deep hands on expertise with AWS services (EC2, EKS, Lambda, S3, IAM, VPC, CloudFormation, CDK, etc.). Strong background in platform engineering, building internal developer platforms, or infrastructure tooling. Experience designing and operating large scale distributed systems. Proficiency with infrastructure as code tools (Terraform, CloudFormation). Strong understanding of containerization and orchestration (Docker, Kubernetes). Experience with CI/CD pipelines and DevOps practices. Knowledge of networking, security, and identity management in cloud environments. Excellent communication skills with the ability to influence technical decisions across teams. Experience working in regulated industries is a plus. Preferred Qualifications: Experience building self service platforms for development teams. Familiarity with observability and monitoring tools (Prometheus, Grafana, Datadog, CloudWatch). Background in financial services or other highly regulated environments. About Goldman Sachs At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has several opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at We offer a wide range of health and welfare programs that vary depending on office location. These generally include medical, dental, short term disability, long term disability, life, accidental death, labor accident and business travel accident insurance. We offer competitive vacation policies based on employee level and office location. We promote time off from work to recharge by providing generous vacation entitlements and a minimum of three weeks expected vacation usage each year. Financial Wellness & Retirement We assist employees in saving and planning for retirement, offer financial support for higher education, and provide a number of benefits to help employees prepare for the unexpected. We offer live financial education and content on a variety of topics to address the spectrum of employees' priorities. Health Services We offer a medical advocacy service for employees and family members facing critical health situations, and counseling and referral services through the Employee Assistance Program (EAP). We provide Global Medical, Security and Travel Assistance and a Workplace Ergonomics Program. We also offer state of the art on site health centers in certain offices. Fitness To encourage employees to live a healthy and active lifestyle, some of our offices feature on site fitness centers. For eligible employees we typically reimburse fees paid for a fitness club membership or activity (up to a pre approved amount). Child Care & Family Care We offer on site child care centers that provide full time and emergency back up care, as well as mother and baby rooms and homework rooms. In every office, we provide advice and counseling services, expectant parent resources and transitional programs for parents returning from parental leave. Adoption, surrogacy, egg donation and egg retrieval stipends are also available. Benefits at Goldman Sachs Read more about the full suite of class leading benefits our firm has to offer.
26/07/2026
Full time
What We Do At Goldman Sachs, our Engineers don't just make things - we make things possible. Change the world by connecting people and capital with ideas. Solve the most challenging and pressing engineering problems for our clients. Join our engineering teams that build massively scalable software and systems, architect low latency infrastructure solutions, proactively guard against cyber threats, and leverage machine learning alongside financial engineering to continuously turn data into action. Create new businesses, transform finance, and explore a world of opportunity at the speed of markets. Goldman Sachs Engineers are innovators and problem-solvers, building solutions in Artificial Intelligence, risk management, big data, mobile and more. As part of Core Engineering at Goldman Sachs, the CE&A team is responsible for enabling the use of public cloud services across the firm. You will be working as part of a multi-disciplinary team responsible for researching, architecting and building a cutting edge platform that enable Goldman Sachs Engineering teams to deploy and manage services in public cloud safely and securely. The organization is seeking highly collaborative, creative, and intellectually curious engineers who are passionate about developing and implementing cutting edge cloud computing and AI solutions. The ideal candidate will thrive in a DevOps culture and contribute to customer centric product development. They will work closely with cross functional teams, and will be creative collaborators who evolve, adapt to change and thrive in a fast paced global environment. Responsibilities And Qualifications: We are looking for a senior technical leader to join our Cloud Engineering & Architecture team and play a pivotal role in enabling the firm to maximize its use of cloud infrastructure. This is a hands on leadership position requiring deep technical expertise, strategic thinking, and the ability to drive large scale platform initiatives from conception to delivery. Key Responsibilities: Design, develop, and operationalize enterprise grade cloud platform capabilities. Architect scalable, resilient, and secure infrastructure solutions on AWS. Architect and operationalize autonomous AI based, self healing infrastructure Define technical standards, best practices, and reference architectures for cloud adoption across the firm. Partner with engineering teams to enable seamless migration and modernization of workloads to the cloud. Drive automation and infrastructure as code practices to improve operational efficiency. Drive AI powered FinOps and predictive resource optimization Mentor and guide engineers across teams, raising the overall technical bar. Collaborate with security, networking, and compliance teams to ensure platform meets regulatory and governance requirements. Evaluate emerging technologies and make recommendations for platform evolution. Participate in architecture design reviews and provide technical leadership on complex initiatives. Complementary AI Based Skills: LLM Orchestration & Agentic Workflows: Experience in designing, building, and deploying Large Language Model (LLM) orchestration frameworks (e.g., LangChain, Temporal, or custom agentic loops) to coordinate multi step diagnostic and remediation tasks. AIOps & Intelligent Observability: Ability to integrate traditional observability stacks (e.g., Datadog, Prometheus, OpenTelemetry) with AI/ML models to automate root cause analysis, anomaly detection, and semantic log clustering. Self Healing Infrastructure Engineering: Experience designing closed loop, self healing systems that autonomously execute recovery actions (e.g., traffic shifting, automated rollbacks, or service restarts) with built in verification and safety guardrails. AI Driven FinOps & Resource Optimization: Deep understanding of applying machine learning and predictive analytics to dynamically right size cloud resources, manage spot instances, and optimize data platform workloads. Predictive Capacity Planning: Ability to design algorithms that forecast workload demands and proactively scale infrastructure to prevent over provisioning while maintaining strict SLAs. Complementary Behaviours: Toil Reduction Mindset: A relentless focus on eliminating repetitive operational support and engineering friction by shifting platform operations from reactive troubleshooting to autonomous mitigation. Risk Aware Automation: Demonstrates a disciplined approach to safety by implementing strict confidence thresholds, validation loops, and human in the loop fallbacks for autonomous AI actions. Value Oriented Engineering: Treats cost optimization as a first class architectural metric, aligning infrastructure spend directly with business value and platform efficiency. Impact Preserving Innovation: Executes large scale optimization initiatives with a meticulous, risk mitigated approach, ensuring zero disruption to production environments or developer velocity. Basic Qualifications: 10+ years of experience in software engineering or infrastructure engineering. Deep hands on expertise with AWS services (EC2, EKS, Lambda, S3, IAM, VPC, CloudFormation, CDK, etc.). Strong background in platform engineering, building internal developer platforms, or infrastructure tooling. Experience designing and operating large scale distributed systems. Proficiency with infrastructure as code tools (Terraform, CloudFormation). Strong understanding of containerization and orchestration (Docker, Kubernetes). Experience with CI/CD pipelines and DevOps practices. Knowledge of networking, security, and identity management in cloud environments. Excellent communication skills with the ability to influence technical decisions across teams. Experience working in regulated industries is a plus. Preferred Qualifications: Experience building self service platforms for development teams. Familiarity with observability and monitoring tools (Prometheus, Grafana, Datadog, CloudWatch). Background in financial services or other highly regulated environments. About Goldman Sachs At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has several opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at We offer a wide range of health and welfare programs that vary depending on office location. These generally include medical, dental, short term disability, long term disability, life, accidental death, labor accident and business travel accident insurance. We offer competitive vacation policies based on employee level and office location. We promote time off from work to recharge by providing generous vacation entitlements and a minimum of three weeks expected vacation usage each year. Financial Wellness & Retirement We assist employees in saving and planning for retirement, offer financial support for higher education, and provide a number of benefits to help employees prepare for the unexpected. We offer live financial education and content on a variety of topics to address the spectrum of employees' priorities. Health Services We offer a medical advocacy service for employees and family members facing critical health situations, and counseling and referral services through the Employee Assistance Program (EAP). We provide Global Medical, Security and Travel Assistance and a Workplace Ergonomics Program. We also offer state of the art on site health centers in certain offices. Fitness To encourage employees to live a healthy and active lifestyle, some of our offices feature on site fitness centers. For eligible employees we typically reimburse fees paid for a fitness club membership or activity (up to a pre approved amount). Child Care & Family Care We offer on site child care centers that provide full time and emergency back up care, as well as mother and baby rooms and homework rooms. In every office, we provide advice and counseling services, expectant parent resources and transitional programs for parents returning from parental leave. Adoption, surrogacy, egg donation and egg retrieval stipends are also available. Benefits at Goldman Sachs Read more about the full suite of class leading benefits our firm has to offer.
What We Do At Goldman Sachs, our Engineers don't just make things - we make things possible. Change the world by connecting people and capital with ideas. Solve the most challenging and pressing engineering problems for our clients. Join our engineering teams that build massively scalable software and systems, architect low latency infrastructure solutions, proactively guard against cyber threats, and leverage machine learning alongside financial engineering to continuously turn data into action. Create new businesses, transform finance, and explore a world of opportunity at the speed of markets. Goldman Sachs Engineers are innovators and problem-solvers, building solutions in Artificial Intelligence, risk management, big data, mobile and more. Cloud Engineering & Architecture (CE&A) As part of Core Engineering at Goldman Sachs, the CE&A team is responsible for enabling the use of public cloud services across the firm. You will be working as part of a multi-disciplinary team responsible for researching, architecting and building a cutting-edge platform that enable Goldman Sachs Engineering teams to deploy and manage services in public cloud safely and securely. The organization is seeking highly collaborative, creative, and intellectually curious engineers who are passionate about developing and implementing cutting-edge cloud computing and AI solutions. The ideal candidate will thrive in a DevOps culture and contribute to customer-centric product development. They will work closely with cross-functional teams, and will be creative collaborators who evolve, adapt to change and thrive in a fast-paced global environment. Responsibilities And Qualifications: We are looking for a senior technical leader to join our Cloud Engineering & Architecture team and play a pivotal role in enabling the firm to maximize its use of cloud infrastructure. This is a hands-on leadership position requiring deep technical expertise, strategic thinking, and the ability to drive large-scale platform initiatives from conception to delivery. Key Responsibilities: Design, develop, and operationalize enterprise-grade cloud platform capabilities. Architect scalable, resilient, and secure infrastructure solutions on AWS. Architect and operationalize autonomous AI based, self-healing infrastructure Define technical standards, best practices, and reference architectures for cloud adoption across the firm. Partner with engineering teams to enable seamless migration and modernization of workloads to the cloud. Drive automation and infrastructure-as-code practices to improve operational efficiency. Drive AI-powered FinOps and predictive resource optimization Mentor and guide engineers across teams, raising the overall technical bar. Collaborate with security, networking, and compliance teams to ensure platform meets regulatory and governance requirements. Evaluate emerging technologies and make recommendations for platform evolution. Participate in architecture design reviews and provide technical leadership on complex initiatives. Complementary AI Based Skills: LLM Orchestration & Agentic Workflows: Experience in designing, building, and deploying Large Language Model (LLM) orchestration frameworks (e.g., LangChain, Temporal, or custom agentic loops) to coordinate multi-step diagnostic and remediation tasks. AIOps & Intelligent Observability: Ability to integrate traditional observability stacks (e.g., Datadog, Prometheus, OpenTelemetry) with AI/ML models to automate root-cause analysis, anomaly detection, and semantic log clustering. Self-Healing Infrastructure Engineering: Experience designing closed-loop, self-healing systems that autonomously execute recovery actions (e.g., traffic shifting, automated rollbacks, or service restarts) with built-in verification and safety guardrails. AI-Driven FinOps & Resource Optimization: Deep understanding of applying machine learning and predictive analytics to dynamically right-size cloud resources, manage spot instances, and optimize data platform workloads. Predictive Capacity Planning: Ability to design algorithms that forecast workload demands and proactively scale infrastructure to prevent over-provisioning while maintaining strict SLAs. Complementary Behaviours: Toil-Reduction Mindset: A relentless focus on eliminating repetitive operational support and engineering friction by shifting platform operations from reactive troubleshooting to autonomous mitigation. Risk-Aware Automation: Demonstrates a disciplined approach to safety by implementing strict confidence thresholds, validation loops, and human-in-the-loop fallbacks for autonomous AI actions. Value-Oriented Engineering: Treats cost optimization as a first-class architectural metric, aligning infrastructure spend directly with business value and platform efficiency. Impact-Preserving Innovation: Executes large-scale optimization initiatives with a meticulous, risk-mitigated approach, ensuring zero disruption to production environments or developer velocity. Basic Qualifications: 10+ years of experience in software engineering or infrastructure engineering. Deep hands-on expertise with AWS services (EC2, EKS, Lambda, S3, IAM, VPC, CloudFormation, CDK, etc.). Strong background in platform engineering, building internal developer platforms, or infrastructure tooling. Experience designing and operating large-scale distributed systems. Proficiency with infrastructure-as-code tools (Terraform, CloudFormation). Strong understanding of containerization and orchestration (Docker, Kubernetes). Experience with CI/CD pipelines and DevOps practices. Knowledge of networking, security, and identity management in cloud environments. Excellent communication skills with the ability to influence technical decisions across teams. Experience working in regulated industries is a plus. Preferred Qualifications: AWS certifications (Solutions Architect Professional, DevOps Engineer, etc.). Experience building self-service platforms for development teams. Familiarity with observability and monitoring tools (Prometheus, Grafana, Datadog, CloudWatch). Background in financial services or other highly regulated environments. About Goldman Sachs At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has several opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at . We're committed to finding reasonable accommodation for candidates with special needs or disabilities during our recruiting process. Learn more:
26/07/2026
Full time
What We Do At Goldman Sachs, our Engineers don't just make things - we make things possible. Change the world by connecting people and capital with ideas. Solve the most challenging and pressing engineering problems for our clients. Join our engineering teams that build massively scalable software and systems, architect low latency infrastructure solutions, proactively guard against cyber threats, and leverage machine learning alongside financial engineering to continuously turn data into action. Create new businesses, transform finance, and explore a world of opportunity at the speed of markets. Goldman Sachs Engineers are innovators and problem-solvers, building solutions in Artificial Intelligence, risk management, big data, mobile and more. Cloud Engineering & Architecture (CE&A) As part of Core Engineering at Goldman Sachs, the CE&A team is responsible for enabling the use of public cloud services across the firm. You will be working as part of a multi-disciplinary team responsible for researching, architecting and building a cutting-edge platform that enable Goldman Sachs Engineering teams to deploy and manage services in public cloud safely and securely. The organization is seeking highly collaborative, creative, and intellectually curious engineers who are passionate about developing and implementing cutting-edge cloud computing and AI solutions. The ideal candidate will thrive in a DevOps culture and contribute to customer-centric product development. They will work closely with cross-functional teams, and will be creative collaborators who evolve, adapt to change and thrive in a fast-paced global environment. Responsibilities And Qualifications: We are looking for a senior technical leader to join our Cloud Engineering & Architecture team and play a pivotal role in enabling the firm to maximize its use of cloud infrastructure. This is a hands-on leadership position requiring deep technical expertise, strategic thinking, and the ability to drive large-scale platform initiatives from conception to delivery. Key Responsibilities: Design, develop, and operationalize enterprise-grade cloud platform capabilities. Architect scalable, resilient, and secure infrastructure solutions on AWS. Architect and operationalize autonomous AI based, self-healing infrastructure Define technical standards, best practices, and reference architectures for cloud adoption across the firm. Partner with engineering teams to enable seamless migration and modernization of workloads to the cloud. Drive automation and infrastructure-as-code practices to improve operational efficiency. Drive AI-powered FinOps and predictive resource optimization Mentor and guide engineers across teams, raising the overall technical bar. Collaborate with security, networking, and compliance teams to ensure platform meets regulatory and governance requirements. Evaluate emerging technologies and make recommendations for platform evolution. Participate in architecture design reviews and provide technical leadership on complex initiatives. Complementary AI Based Skills: LLM Orchestration & Agentic Workflows: Experience in designing, building, and deploying Large Language Model (LLM) orchestration frameworks (e.g., LangChain, Temporal, or custom agentic loops) to coordinate multi-step diagnostic and remediation tasks. AIOps & Intelligent Observability: Ability to integrate traditional observability stacks (e.g., Datadog, Prometheus, OpenTelemetry) with AI/ML models to automate root-cause analysis, anomaly detection, and semantic log clustering. Self-Healing Infrastructure Engineering: Experience designing closed-loop, self-healing systems that autonomously execute recovery actions (e.g., traffic shifting, automated rollbacks, or service restarts) with built-in verification and safety guardrails. AI-Driven FinOps & Resource Optimization: Deep understanding of applying machine learning and predictive analytics to dynamically right-size cloud resources, manage spot instances, and optimize data platform workloads. Predictive Capacity Planning: Ability to design algorithms that forecast workload demands and proactively scale infrastructure to prevent over-provisioning while maintaining strict SLAs. Complementary Behaviours: Toil-Reduction Mindset: A relentless focus on eliminating repetitive operational support and engineering friction by shifting platform operations from reactive troubleshooting to autonomous mitigation. Risk-Aware Automation: Demonstrates a disciplined approach to safety by implementing strict confidence thresholds, validation loops, and human-in-the-loop fallbacks for autonomous AI actions. Value-Oriented Engineering: Treats cost optimization as a first-class architectural metric, aligning infrastructure spend directly with business value and platform efficiency. Impact-Preserving Innovation: Executes large-scale optimization initiatives with a meticulous, risk-mitigated approach, ensuring zero disruption to production environments or developer velocity. Basic Qualifications: 10+ years of experience in software engineering or infrastructure engineering. Deep hands-on expertise with AWS services (EC2, EKS, Lambda, S3, IAM, VPC, CloudFormation, CDK, etc.). Strong background in platform engineering, building internal developer platforms, or infrastructure tooling. Experience designing and operating large-scale distributed systems. Proficiency with infrastructure-as-code tools (Terraform, CloudFormation). Strong understanding of containerization and orchestration (Docker, Kubernetes). Experience with CI/CD pipelines and DevOps practices. Knowledge of networking, security, and identity management in cloud environments. Excellent communication skills with the ability to influence technical decisions across teams. Experience working in regulated industries is a plus. Preferred Qualifications: AWS certifications (Solutions Architect Professional, DevOps Engineer, etc.). Experience building self-service platforms for development teams. Familiarity with observability and monitoring tools (Prometheus, Grafana, Datadog, CloudWatch). Background in financial services or other highly regulated environments. About Goldman Sachs At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has several opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at . We're committed to finding reasonable accommodation for candidates with special needs or disabilities during our recruiting process. Learn more:
What We Do At the company, our Engineers don't just make things - we make things possible. Change the world by connecting people and capital with ideas. Solve the most challenging and pressing engineering problems for our clients. Join our engineering teams that build massively scalable software and systems, architect low latency infrastructure solutions, proactively guard against cyber threats, and leverage machine learning alongside financial engineering to continuously turn data into action. Create new businesses, transform finance, and explore a world of opportunity at the speed of markets. the company Engineers are innovators and problem-solvers, building solutions in Artificial Intelligence, risk management, big data, mobile and more. Cloud Engineering & Architecture (CE&A) As part of Core Engineering at the company, the CE&A team is responsible for enabling the use of public cloud services across the firm. You will be working as part of a multi-disciplinary team responsible for researching, architecting and building a cutting edge platform that enable the company Engineering teams to deploy and manage services in public cloud safely and securely. The organization is seeking highly collaborative, creative, and intellectually curious engineers who are passionate about developing and implementing cutting edge cloud computing and AI solutions. The ideal candidate will thrive in a DevOps culture and contribute to customer centric product development. They will work closely with cross functional teams, and will be creative collaborators who evolve, adapt to change and thrive in a fast paced global environment. Responsibilities And Qualifications: We are looking for a senior technical leader to join our Cloud Engineering & Architecture team and play a pivotal role in enabling the firm to maximize its use of cloud infrastructure. This is a hands on leadership position requiring deep technical expertise, strategic thinking, and the ability to drive large scale platform initiatives from conception to delivery. Key Responsibilities: Design, develop, and operationalize enterprise grade cloud platform capabilities. Architect scalable, resilient, and secure infrastructure solutions on AWS. Architect and operationalize autonomous AI based, self healing infrastructure Define technical standards, best practices, and reference architectures for cloud adoption across the firm. Partner with engineering teams to enable seamless migration and modernization of workloads to the cloud. Drive automation and infrastructure as code practices to improve operational efficiency. Drive AI powered FinOps and predictive resource optimization Mentor and guide engineers across teams, raising the overall technical bar. Collaborate with security, networking, and compliance teams to ensure platform meets regulatory and governance requirements. Evaluate emerging technologies and make recommendations for platform evolution. Participate in architecture design reviews and provide technical leadership on complex initiatives. Complementary AI Based Skills: LLM Orchestration & Agentic Workflows: Experience in designing, building, and deploying Large Language Model (LLM) orchestration frameworks (e.g., LangChain, Temporal, or custom agentic loops) to coordinate multi step diagnostic and remediation tasks. AIOps & Intelligent Observability: Ability to integrate traditional observability stacks (e.g., Datadog, Prometheus, OpenTelemetry) with AI/ML models to automate root cause analysis, anomaly detection, and semantic log clustering. Self Healing Infrastructure Engineering: Experience designing closed loop, self healing systems that autonomously execute recovery actions (e.g., traffic shifting, automated rollbacks, or service restarts) with built in verification and safety guardrails. AI Driven FinOps & Resource Optimization: Deep understanding of applying machine learning and predictive analytics to dynamically right size cloud resources, manage spot instances, and optimize data platform workloads. Predictive Capacity Planning: Ability to design algorithms that forecast workload demands and proactively scale infrastructure to prevent over provisioning while maintaining strict SLAs. Complementary Behaviours: Toil Reduction Mindset: A relentless focus on eliminating repetitive operational support and engineering friction by shifting platform operations from reactive troubleshooting to autonomous mitigation. Risk Aware Automation: Demonstrates a disciplined approach to safety by implementing strict confidence thresholds, validation loops, and human in the loop fallbacks for autonomous AI actions. Value Oriented Engineering: Treats cost optimization as a first class architectural metric, aligning infrastructure spend directly with business value and platform efficiency. Impact Preserving Innovation: Executes large scale optimization initiatives with a meticulous, risk mitigated approach, ensuring zero disruption to production environments or developer velocity. Basic Qualifications: 10+ years of experience in software engineering or infrastructure engineering. Deep hands on expertise with AWS services (EC2, EKS, Lambda, S3, IAM, VPC, CloudFormation, CDK, etc.). Strong background in platform engineering, building internal developer platforms, or infrastructure tooling. Experience designing and operating large scale distributed systems. Proficiency with infrastructure as code tools (Terraform, CloudFormation). Strong understanding of containerization and orchestration (Docker, Kubernetes). Experience with CI/CD pipelines and DevOps practices. Knowledge of networking, security, and identity management in cloud environments. Excellent communication skills with the ability to influence technical decisions across teams. Experience working in regulated industries is a plus. Preferred Qualifications: AWS certifications (Solutions Architect Professional, DevOps Engineer, etc.). Experience building self service platforms for development teams. Familiarity with observability and monitoring tools (Prometheus, Grafana, Datadog, CloudWatch). Background in financial services or other highly regulated environments. About the company At the company, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has several opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. about our culture, benefits, and people at We're committed to finding reasonable accommodation for candidates with special needs or disabilities during our recruiting process. : We Offer Best-In-Class Benefits Healthcare & Medical Insurance We offer a wide range of health and welfare programs that vary depending on office location. These generally include medical, dental, short term disability, long term disability, life, accidental death, labor accident and business travel accident insurance. Holiday & Vacation Policies We offer competitive vacation policies based on employee level and office location. We promote time off from work to recharge by providing generous vacation entitlements and a minimum of three weeks expected vacation usage each year. Financial Wellness & Retirement We assist employees in saving and planning for retirement, offer financial support for higher education, and provide a number of benefits to help employees prepare for the unexpected. We offer live financial education and content on a variety of topics to address the spectrum of employees' priorities. Health Services We offer a medical advocacy service for employees and family members facing critical health situations, and counseling and referral services through the Employee Assistance Program (EAP). We provide Global Medical, Security and Travel Assistance and a Workplace Ergonomics Program. We also offer state of the art on site health centers in certain offices. Fitness To encourage employees to live a healthy and active lifestyle, some of our offices feature on site fitness centers. For eligible employees we typically reimburse fees paid for a fitness club membership or activity (up to a pre approved amount). Child Care & Family Care We offer on site child care centers that provide full time and emergency back up care, as well as mother and baby rooms and homework rooms. In every office, we provide advice and counseling services, expectant parent resources and transitional programs for parents returning from parental leave. Adoption, surrogacy, egg donation and egg retrieval stipends are also available. Benefits at the company Read more about the full suite of class leading benefits our firm has to offer.
26/07/2026
Full time
What We Do At the company, our Engineers don't just make things - we make things possible. Change the world by connecting people and capital with ideas. Solve the most challenging and pressing engineering problems for our clients. Join our engineering teams that build massively scalable software and systems, architect low latency infrastructure solutions, proactively guard against cyber threats, and leverage machine learning alongside financial engineering to continuously turn data into action. Create new businesses, transform finance, and explore a world of opportunity at the speed of markets. the company Engineers are innovators and problem-solvers, building solutions in Artificial Intelligence, risk management, big data, mobile and more. Cloud Engineering & Architecture (CE&A) As part of Core Engineering at the company, the CE&A team is responsible for enabling the use of public cloud services across the firm. You will be working as part of a multi-disciplinary team responsible for researching, architecting and building a cutting edge platform that enable the company Engineering teams to deploy and manage services in public cloud safely and securely. The organization is seeking highly collaborative, creative, and intellectually curious engineers who are passionate about developing and implementing cutting edge cloud computing and AI solutions. The ideal candidate will thrive in a DevOps culture and contribute to customer centric product development. They will work closely with cross functional teams, and will be creative collaborators who evolve, adapt to change and thrive in a fast paced global environment. Responsibilities And Qualifications: We are looking for a senior technical leader to join our Cloud Engineering & Architecture team and play a pivotal role in enabling the firm to maximize its use of cloud infrastructure. This is a hands on leadership position requiring deep technical expertise, strategic thinking, and the ability to drive large scale platform initiatives from conception to delivery. Key Responsibilities: Design, develop, and operationalize enterprise grade cloud platform capabilities. Architect scalable, resilient, and secure infrastructure solutions on AWS. Architect and operationalize autonomous AI based, self healing infrastructure Define technical standards, best practices, and reference architectures for cloud adoption across the firm. Partner with engineering teams to enable seamless migration and modernization of workloads to the cloud. Drive automation and infrastructure as code practices to improve operational efficiency. Drive AI powered FinOps and predictive resource optimization Mentor and guide engineers across teams, raising the overall technical bar. Collaborate with security, networking, and compliance teams to ensure platform meets regulatory and governance requirements. Evaluate emerging technologies and make recommendations for platform evolution. Participate in architecture design reviews and provide technical leadership on complex initiatives. Complementary AI Based Skills: LLM Orchestration & Agentic Workflows: Experience in designing, building, and deploying Large Language Model (LLM) orchestration frameworks (e.g., LangChain, Temporal, or custom agentic loops) to coordinate multi step diagnostic and remediation tasks. AIOps & Intelligent Observability: Ability to integrate traditional observability stacks (e.g., Datadog, Prometheus, OpenTelemetry) with AI/ML models to automate root cause analysis, anomaly detection, and semantic log clustering. Self Healing Infrastructure Engineering: Experience designing closed loop, self healing systems that autonomously execute recovery actions (e.g., traffic shifting, automated rollbacks, or service restarts) with built in verification and safety guardrails. AI Driven FinOps & Resource Optimization: Deep understanding of applying machine learning and predictive analytics to dynamically right size cloud resources, manage spot instances, and optimize data platform workloads. Predictive Capacity Planning: Ability to design algorithms that forecast workload demands and proactively scale infrastructure to prevent over provisioning while maintaining strict SLAs. Complementary Behaviours: Toil Reduction Mindset: A relentless focus on eliminating repetitive operational support and engineering friction by shifting platform operations from reactive troubleshooting to autonomous mitigation. Risk Aware Automation: Demonstrates a disciplined approach to safety by implementing strict confidence thresholds, validation loops, and human in the loop fallbacks for autonomous AI actions. Value Oriented Engineering: Treats cost optimization as a first class architectural metric, aligning infrastructure spend directly with business value and platform efficiency. Impact Preserving Innovation: Executes large scale optimization initiatives with a meticulous, risk mitigated approach, ensuring zero disruption to production environments or developer velocity. Basic Qualifications: 10+ years of experience in software engineering or infrastructure engineering. Deep hands on expertise with AWS services (EC2, EKS, Lambda, S3, IAM, VPC, CloudFormation, CDK, etc.). Strong background in platform engineering, building internal developer platforms, or infrastructure tooling. Experience designing and operating large scale distributed systems. Proficiency with infrastructure as code tools (Terraform, CloudFormation). Strong understanding of containerization and orchestration (Docker, Kubernetes). Experience with CI/CD pipelines and DevOps practices. Knowledge of networking, security, and identity management in cloud environments. Excellent communication skills with the ability to influence technical decisions across teams. Experience working in regulated industries is a plus. Preferred Qualifications: AWS certifications (Solutions Architect Professional, DevOps Engineer, etc.). Experience building self service platforms for development teams. Familiarity with observability and monitoring tools (Prometheus, Grafana, Datadog, CloudWatch). Background in financial services or other highly regulated environments. About the company At the company, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has several opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. about our culture, benefits, and people at We're committed to finding reasonable accommodation for candidates with special needs or disabilities during our recruiting process. : We Offer Best-In-Class Benefits Healthcare & Medical Insurance We offer a wide range of health and welfare programs that vary depending on office location. These generally include medical, dental, short term disability, long term disability, life, accidental death, labor accident and business travel accident insurance. Holiday & Vacation Policies We offer competitive vacation policies based on employee level and office location. We promote time off from work to recharge by providing generous vacation entitlements and a minimum of three weeks expected vacation usage each year. Financial Wellness & Retirement We assist employees in saving and planning for retirement, offer financial support for higher education, and provide a number of benefits to help employees prepare for the unexpected. We offer live financial education and content on a variety of topics to address the spectrum of employees' priorities. Health Services We offer a medical advocacy service for employees and family members facing critical health situations, and counseling and referral services through the Employee Assistance Program (EAP). We provide Global Medical, Security and Travel Assistance and a Workplace Ergonomics Program. We also offer state of the art on site health centers in certain offices. Fitness To encourage employees to live a healthy and active lifestyle, some of our offices feature on site fitness centers. For eligible employees we typically reimburse fees paid for a fitness club membership or activity (up to a pre approved amount). Child Care & Family Care We offer on site child care centers that provide full time and emergency back up care, as well as mother and baby rooms and homework rooms. In every office, we provide advice and counseling services, expectant parent resources and transitional programs for parents returning from parental leave. Adoption, surrogacy, egg donation and egg retrieval stipends are also available. Benefits at the company Read more about the full suite of class leading benefits our firm has to offer.
LONDON, LONDON, United Kingdom Job Information Job Identification Job Category Software Engineering Business Unit Corporate Sector Posting Date 01/21/2025, 02:09 PM Locations LONDON, LONDON, United Kingdom Job Schedule Full time Job Description Out of the successful launch of Chase in 2021, we're a new team, with a new mission. We'm creating products that solve real world problems and put customers at the center - all in an environment that nurtures skills and helps you realize your potential. Our team is key to our success. We're people-first. We value collaboration, curiosity and commitment. As a Platform Engineer at JPMorgan Chase within the platform team, you are the heart of this venture, focused on getting smart ideas into the hands of our customers. You have a curious mindset, thrive in collaborative squads, and are passionate about new technology. By your nature, you are also solution-oriented, commercially savvy and have a head for fintech. You thrive in working in tribes and squads that focus on specific products and projects - and depending on your strengths and interests, you'll have the opportunity to move between them. While we're looking for professional skills, culture is just as important to us. We understand that everyone's unique - and that diversity of thought, experience and background is what makes a good team, great. By bringing people with different points of view together, we can represent everyone and truly reflect the communities we serve. This way, there's scope for you to make a huge difference - on us as a company, and on our clients and business partners around the world Job responsibilities Develops secure high-quality production code, and reviews and debugs code written by others Develops composable infrastructure systems and capabilities Identifies opportunities to eliminate or automate remediation of recurring issues to improve overall operational stability of software applications and systems Provides operational support of production systems within a you-build-it-you-run-it culture Leads evaluation sessions with external vendors, startups, and internal teams to drive outcomes-oriented probing of architectural designs, technical credentials, and applicability for use within existing systems and information architecture Leads communities of practice across Software Engineering to drive awareness and use of new and leading-edge technologies Adds to team culture of diversity, equity, inclusion, and respect Required qualifications, capabilities, and skills Formal training or certification on software engineering concepts, such as Certified Kubernetes Application Developer (CKAD), Google Associate Cloud Engineer Certification, or AWS Certified Solutions Architect Hands-on practical experience delivering system design, application development, testing, and operational stability Advanced in one or more programming language(s), such as Go, Java or Kotlin Advanced understanding of agile methodologies, CI/CD, application resiliency, and security Demonstrated proficiency in software applications and processes within a technical domain, such as cloud, artificial intelligence, machine learning, mobile, etc. Practical cloud native experience, deploying Kubernetes applications on a cloud service provider, such as Google Cloud, Amazon Web Services, or Microsoft Cloud Preferred qualifications, capabilities, and skills Expertise in the Kubernetes operator pattern Expertise deploying infrastructure as code, using Crossplane, Terraform, or equivalent About Us J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives. We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit ourFAQs for more information about requesting an accommodation. About the Team Our Corporate Technology team relies on smart, driven people like you to develop applications and provide tech support for all our corporate functions across our network. Your efforts will touch lives all over the financial spectrum and across all our divisions: Global Finance, Corporate Treasury, Risk Management, Human Resources, Compliance, Legal, and within the Corporate Administrative Office. You'll be part of a team specifically built to meet and exceed our evolving technology needs, as well as our technology controls agenda.
26/07/2026
Full time
LONDON, LONDON, United Kingdom Job Information Job Identification Job Category Software Engineering Business Unit Corporate Sector Posting Date 01/21/2025, 02:09 PM Locations LONDON, LONDON, United Kingdom Job Schedule Full time Job Description Out of the successful launch of Chase in 2021, we're a new team, with a new mission. We'm creating products that solve real world problems and put customers at the center - all in an environment that nurtures skills and helps you realize your potential. Our team is key to our success. We're people-first. We value collaboration, curiosity and commitment. As a Platform Engineer at JPMorgan Chase within the platform team, you are the heart of this venture, focused on getting smart ideas into the hands of our customers. You have a curious mindset, thrive in collaborative squads, and are passionate about new technology. By your nature, you are also solution-oriented, commercially savvy and have a head for fintech. You thrive in working in tribes and squads that focus on specific products and projects - and depending on your strengths and interests, you'll have the opportunity to move between them. While we're looking for professional skills, culture is just as important to us. We understand that everyone's unique - and that diversity of thought, experience and background is what makes a good team, great. By bringing people with different points of view together, we can represent everyone and truly reflect the communities we serve. This way, there's scope for you to make a huge difference - on us as a company, and on our clients and business partners around the world Job responsibilities Develops secure high-quality production code, and reviews and debugs code written by others Develops composable infrastructure systems and capabilities Identifies opportunities to eliminate or automate remediation of recurring issues to improve overall operational stability of software applications and systems Provides operational support of production systems within a you-build-it-you-run-it culture Leads evaluation sessions with external vendors, startups, and internal teams to drive outcomes-oriented probing of architectural designs, technical credentials, and applicability for use within existing systems and information architecture Leads communities of practice across Software Engineering to drive awareness and use of new and leading-edge technologies Adds to team culture of diversity, equity, inclusion, and respect Required qualifications, capabilities, and skills Formal training or certification on software engineering concepts, such as Certified Kubernetes Application Developer (CKAD), Google Associate Cloud Engineer Certification, or AWS Certified Solutions Architect Hands-on practical experience delivering system design, application development, testing, and operational stability Advanced in one or more programming language(s), such as Go, Java or Kotlin Advanced understanding of agile methodologies, CI/CD, application resiliency, and security Demonstrated proficiency in software applications and processes within a technical domain, such as cloud, artificial intelligence, machine learning, mobile, etc. Practical cloud native experience, deploying Kubernetes applications on a cloud service provider, such as Google Cloud, Amazon Web Services, or Microsoft Cloud Preferred qualifications, capabilities, and skills Expertise in the Kubernetes operator pattern Expertise deploying infrastructure as code, using Crossplane, Terraform, or equivalent About Us J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives. We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit ourFAQs for more information about requesting an accommodation. About the Team Our Corporate Technology team relies on smart, driven people like you to develop applications and provide tech support for all our corporate functions across our network. Your efforts will touch lives all over the financial spectrum and across all our divisions: Global Finance, Corporate Treasury, Risk Management, Human Resources, Compliance, Legal, and within the Corporate Administrative Office. You'll be part of a team specifically built to meet and exceed our evolving technology needs, as well as our technology controls agenda.