Description & Requirements
- Partner with engineering stakeholders to understand Bloomberg’s development landscape and security needs. Develop automated security solutions that integrate into development pipelines.
- Maintain and enhance existing security automation processes and security capabilities.
- Understand and research technical details of core technology stacks and develop or enhance custom code analysis queries.
- Communicate vulnerability landscape and work on mitigations with stakeholders across the business.
- Actively monitor the latest news and trends in automated security capabilities, secure development, and AI-assisted security workflows.
- Develop and enhance operational run books
- Perform ad-hoc vulnerability discovery, including code review and static analysis for key engineering teams, applications and services.
- Build or adopt new security capabilities to address issues at scale, such as Software Composition Analysis, Secret searching, and other automated security testing techniques.
- Use LLMs and AI-assisted workflows as part of security assessments, vulnerability research, secure code review, developer enablement, and security automation.
- Explore, evaluate, and build automation using modern LLM tooling and integration patterns, including custom skills, MCP servers, agentic workflows, retrieval-augmented workflows, and integrations with development and security tooling.
You'll need to have:
- A strong core engineering background with a proven track record.
- 3+ years of experience in software development.
- Strong programming experience, with working knowledge of at least one of: C/C++, Python, JavaScript/TypeScript.
- Knowledge and experience with DevOps and software used in development pipelines (e.g. Github, Jenkins).
- Working knowledge of build systems, package managers, and development tooling (such as cmake, npm, maven, gradle etc).
- A core understanding of common security vulnerabilities, such as OWASP Top 10 issues and language-specific vulnerabilities.
- Experience using, evaluating, or building with LLMs or AI-assisted tooling in technical workflows.
- Ability to combine technical knowledge with an understanding of core aspects of an information security program.
- Motivation to keep up with latest trends and techniques in the information security community.
- Excellent written and verbal communication skills.
- Experience or familiarity with running, maintaining, and customizing static analysis security testing tools such as CodeQL and Semgrep.
- Broad familiarity with programming language ecosystems and frameworks, particularly C++, JavaScript/TypeScript, Python, Java as well as well as modern systems and infrastructure languages such as Go and Rust
- Experience using LLMs or AI-assisted tools for security assessments, vulnerability research, secure code review, developer enablement, or security automation.
- Familiarity with LLM automation concepts and tooling, such as custom skills, MCP servers, agentic workflows, retrieval-augmented workflows, or integrations with development and security tooling.
- Knowledge of open source software component management, Software Composition Analysis, and related security tools.
- Knowledge of core concepts in public cloud providers such as AWS, GCP, and Azure. Familiarity with container orchestration technologies such as Kubernetes and Docker, and cloud deployment orchestration.
- Technical information security certifications, such as CISSP, CSSLP, or SANS certifications.
- Prior experience integrating security testing into DevOps pipelines.
If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role.
Security Engineer - Software Security Enablement in London employer: Bloomberg
Bloomberg is an exceptional employer, offering a dynamic work environment in London where innovation and collaboration thrive. As a Senior Physical Security Technology Specialist, you will benefit from a culture that prioritises professional growth, with opportunities to lead impactful projects across the EMEA region while working alongside a team of dedicated security professionals. With a commitment to employee development and a focus on cutting-edge technology, Bloomberg provides a rewarding career path for those looking to make a meaningful impact in the security industry.