Summary
✨ AI‑Generated
Join a security engineering team as a senior specialist responsible for strengthening application and cloud security across the software development lifecycle. You will conduct threat modeling and architecture reviews, secure Kubernetes environments, integrate automated security controls into CI/CD, review code, and guide engineers toward secure-by-design practices.
Highlights
Hands-on senior security role focused on secure-by-design engineering, cloud and Kubernetes security, modern application security tooling, and close collaboration with software engineering teams throughout the development lifecycle.
Description
Senior Software Cybersecurity Engineer - Edinburgh (Hybrid)
Are you a Senior Cybersecurity Engineer with strong AppSec, DevSecOps, Cloud and Kubernetes experience?
I'm currently working on an exciting opportunity, supporting the Avigilon security team in protecting the software, cloud platforms and intellectual property behind their physical and video security solutions.
This is a hands-on role where you'll work closely with software engineering teams to identify vulnerabilities, improve security throughout the SDLC and build secure-by-design solutions.
What you'll be doing
Conduct threat modelling, risk assessments and security architecture reviewsAssess security across cloud and Kubernetes/container environmentsEmbed SAST, DAST, SCA, SBOM and secret scanning into CI/CD pipelinesPerform security code reviews and provide secure coding guidanceDefine security requirements and support engineering teams with secure-by-design practicesDrive vulnerability management, particularly across Kubernetes and container imagesTriage and validate vulnerabilities, including developing PoCs where appropriateManage IAM and key management controlsSupport product security incident response, root-cause analysis and remediationDevelop detection engineering capabilities, IDS/IPS rules and technical runbooksMonitor emerging threats and continuously improve security controlsWork across engineering, security and compliance teams to drive security improvements
You'll ideally have:
7+ years' experience in Cybersecurity, Application Security or Security EngineeringStrong AppSec / DevSecOps experienceHands-on experience with AWS, Azure or GCPStrong Kubernetes and Docker/container security knowledgeExperience integrating SAST, DAST, SCA and security tooling into CI/CDStrong understanding of threat modelling, IAM, cryptography and application securityExperience with Go and/or C# developmentKnowledge of HTTP, REST, TLS and TCP/IPStrong understanding of OWASP, NIST, ISO 27001 and CISExcellent communication skills with the ability to work closely with developers and technical stakeholders
Desirable
Experience with:
Vulnerability research / exploit developmentManual penetration testingCloud, web, embedded or mobile securitySplunk / OSQueryAI/ML securityDistributed systemsAWS Security Specialty, OSCP, CISSP, CCSP, CCAK or SANS/GIAC certifications
Why consider it?
You'll join a global technology organisation developing mission-critical security and video technologies used to help protect people, property and communities worldwide.
You'll have the opportunity to work at the intersection of:
Application Security | Cloud Security | Kubernetes | DevSecOps | Vulnerability Research | Product Security with strong career development, flexible working and an excellent benefits package.