Product Security Engineer in Cirencester

Product Security Engineer in Cirencester

Cirencester Full-Time 60000 - 72000 £ / year (est.) No working from home possible
A

At a Glance

  • Tasks: Identify and mitigate security risks across innovative hardware and software products.
  • Company: Pioneering tech firm focused on Arctic autonomy and real-world impact.
  • Benefits: Competitive pay, equity options, private healthcare, and unique travel opportunities.
  • Other info: Be part of a small team where your contributions truly matter.
  • Why this job: Join a mission-driven team tackling high-stakes security challenges in extreme environments.
  • Qualifications: Experience in security domains and a knack for risk assessment.

The predicted salary is between 60000 - 72000 £ per year.

LOCATION - ONSITE: CALMSDEN, CIRENCESTER, UK & IN THE FIELD WHEN NEEDED

THE LAST FRONTIER

The Arctic is a place of extremes: unforgiving, untamed, and undergoing rapid change. A literal defrosting reveals a multi-trillion-dollar opportunity spanning energy, defence, logistics, research, and infrastructure. ARD was founded on a paradox. The Arctic is both the next great economic frontier and one of the most hostile environments on Earth. Rich in resources and strategically vital, yet bone-chillingly cold, dark for months, and fundamentally inhospitable to humans. This paradox—an explosion of activity in a place that resists human presence—is why we exist. Our solution is autonomy. We build systems that operate reliably and intelligently in the Arctic, so that humans don't always have to. Founded by record-holding pioneers with decades of polar experience, we take calculated risks on hard problems that matter. If you want to build and deploy ground-up technology with real-world impact, at an inflection point in history that won’t reappear, we’d like to talk.

THE ROLE

We’re hiring our first Product Security Engineer. Security Engineering at ARD blends sharp technical skill, an attacker's mindset, and tangible real-world stakes. You'll operate across our entire hardware and software product suite — cloud infrastructure, applications, identity systems, and the autonomous products we field — spotting and cutting down the risks that actually matter. The systems we run and the data we hold call for a security approach that's thorough, flexible, and woven into everything we do. Your work will directly underpin the trust partners, customers, and the public place in us, while keeping our teams free to build and ship with confidence. Given how high the stakes are at ARD, this is core to delivering our mission the right way.

Core Responsibilities

  • Spot, evaluate, and rank security risks across our physical products, systems and infrastructure — separating hypothetical worries from genuine threats to the business.
  • Build and roll out practical security controls across cloud platforms, applications, products, and data, and help engineering teams do likewise.
  • Build and use threat models to catch architectural weak points, trust boundary gaps, and failure modes before they turn into incidents.
  • Own secure-by-design evidence, EN 18031/CRA Annex I assessments, fuzzing/pen-test programmes, the vulnerability register and advisories.
  • Work alongside engineering, product, and operations teams as a trusted security partner — offering patterns, guidance, and guardrails rather than acting as a gatekeeper.
  • Play a part in detecting, investigating, and containing security incidents, and push for lasting fixes based on what we learn.
  • Cut down on manual, reactive security work through automation, better tooling, and secure-by-default habits built into how we develop and run systems.
  • Apply technical rigour to assurance work like audits, certifications, and customer security reviews — making sure our controls hold up in practice, not just on paper.

What We Value

  • Deep, hands-on skill in one or two security domains — application security, cloud security, identity and access management, cryptography, detection and response, or platform security — backed by real evidence of impact.
  • An instinct for trust boundaries, failure modes, blast radius, and attacker behaviour, rather than viewing vulnerabilities in isolation.
  • A knack for turning complex security risk into terms that land with engineers, product managers, and senior leadership alike, and for shaping outcomes through persuasion rather than title.
  • A risk-based approach — weighing decisions proportionately under uncertainty, and always asking whether the work cuts real risk rather than just checking a compliance box.
  • Comfort juggling multiple teams and technical domains at once without losing quality or judgement.
  • A history of finding gaps and pushing security fixes through to completion, even in messy or loosely defined problem spaces.

BONUS POINTS

  • Time spent in or around regulated, high-assurance, or defence-adjacent settings where security demands are intricate and failure carries real weight.
  • Practical offensive security background — red teaming, penetration testing, or adversarial simulation — that shapes how you think about defensive design and threat modelling.
  • Awareness of security issues unique to AI or machine learning systems, such as model integrity, data pipeline security, or adversarial ML.
  • A hand in building security programmes at scale — security champions networks, secure development lifecycle tooling, or company-wide risk frameworks.
  • A background in cloud-native security engineering, especially across AWS, GCP, or Azure, spanning infrastructure-as-code, container security, and cloud identity patterns.
  • Some exposure to supply chain security issues, such as dependency management, build pipeline integrity, or third-party component assurance.
  • Experience working with classified data, government security frameworks, or cross-domain security requirements.

What we offer

  • Competitive compensation.
  • Equity — meaningful options as an early employee at an early-stage company.
  • Private healthcare, dental & optician.
  • Real field exposure — travel to Arctic sites and Outposts when needed (genuinely, not as a gimmick).
  • Mission-driven culture — focus on impact, not hours logged.
  • Small team, real ownership — what you build matters and ships.

Product Security Engineer in Cirencester employer: Arctic Research and Development

At ARD, we pride ourselves on being an exceptional employer, offering a mission-driven culture that prioritises real-world impact over hours logged. As a Product Security Engineer, you'll enjoy competitive compensation, equity options, and the unique opportunity to work in one of the most challenging environments on Earth, with travel to Arctic sites that enrich your experience. Our small team structure ensures that your contributions are valued and have a direct influence on our innovative solutions, fostering both personal and professional growth in a supportive atmosphere.

A

Contact Details:

Arctic Research and Development Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Product Security Engineer in Cirencester

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Arctic Research and Development, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Arctic Research and Development

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Arctic Research and Development. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Product Security Engineer in Cirencester

Security Engineering
Application Security
Cloud Security
Identity and Access Management
Cryptography
Detection and Response
Platform Security

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Arctic Research and Development insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Arctic Research and Development that you’re committed to staying ahead in the game.

How to prepare for a job interview at Arctic Research and Development

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Arctic Research and Development to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Arctic Research and Development.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.