Staff Product Security Engineer in Cambridge

Staff Product Security Engineer in Cambridge

Cambridge Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
C

At a Glance

  • Tasks: Lead security strategy and architecture for cutting-edge cryptographic products.
  • Company: Entrust, a leader in identity-centric security solutions with a global presence.
  • Benefits: Flexible work options, career growth opportunities, and a collaborative culture.
  • Other info: Join a diverse team committed to innovation and inclusion.
  • Why this job: Make a real impact on security solutions that keep the world safe.
  • Qualifications: Strong background in security engineering and leadership skills required.

The predicted salary is between 63000 - 77000 £ per year.

Join us at Entrust

At Entrust, we're shaping the future of identity centric security solutions.

From our comprehensive portfolio of solutions to our flexible, global workplace, we empower careers, foster collaboration, and build solutions that help keep the world moving safely.

Get to Know Us

Headquartered in Minnesota, Entrust is an industry leader in identity-centric security solutions, serving over 150 countries with cutting-edge, scalable technologies.

But our secret weapon?

Our people.

It's the curiosity, dedication, and innovation that drive our success and help us anticipate the future.

Position Overview

The Staff Product Security Engineer is a senior technical leader responsible for defining and driving the security strategy, architecture, and engineering practices across Entrust's cryptographic product portfolio.

This role provides technical leadership beyond individual products, influencing security decisions across multiple engineering teams and ensuring security is embedded throughout the entire product lifecycle.

The Staff Product Security Engineer serves as a recognized security subject matter expert, partnering with product management, engineering leadership, certification teams, and executive stakeholders to establish security roadmaps, enhance security capabilities, and address emerging threats.

This role combines deep technical expertise in software, hardware, and cryptographic security with strong leadership and mentoring capabilities.

You will lead complex security initiatives, establish engineering standards, drive security architecture reviews, and guide teams in adopting secure-by-design principles.

You will also represent security engineering in customer engagements, security audits, certification activities, and interactions with external security researchers and industry experts.

A strong background in mathematics, engineering, computer science, or information security is essential.

The successful candidate will demonstrate a proven ability to influence technical direction, solve highly complex security challenges, and drive security excellence across the organization.

Responsibilities

  • Technical Leadership & Strategy
  • Define and drive product security strategy, architecture principles, and security engineering roadmaps across multiple products and platforms.
  • Lead the security architecture review process for new products, major feature developments, and platform changes.
  • Establish and evolve secure development standards, security design patterns, and engineering best practices.
  • Serve as the primary technical authority for complex security architecture decisions and risk-based security trade‑off discussions.
  • Drive strategic security initiatives that improve security posture, development efficiency, and regulatory readiness across the organization.
  • Anticipate emerging threats, industry trends, and regulatory requirements and translate these into actionable engineering improvements.
  • Product Security Engineering
  • Collaborate with cross‑functional teams to integrate security requirements into product design, development, deployment, and maintenance processes.
  • Lead threat modeling activities for critical systems, products, and architectures.
  • Conduct and oversee advanced security assessments, vulnerability investigations, attack surface analyses, and risk evaluations.
  • Design, implement, and review security controls, cryptographic protections, and system hardening mechanisms.
  • Lead investigations of critical security issues and provide technical direction for remediation efforts.
  • Guide secure design reviews and code review activities for business‑critical products.
  • Security Tooling & Automation
  • Define and drive the security tooling strategy across software and hardware development environments.
  • Lead the development and adoption of advanced security testing capabilities, including fuzzing, software composition analysis (SCA), static analysis, dynamic analysis, memory safety validation, and vulnerability discovery tooling.
  • Partner with Dev Ops and engineering teams to embed security automation and policy enforcement into CI/CD processes.
  • Improve vulnerability detection, triage, and remediation workflows through automation and data‑driven approaches.
  • Security Governance & Risk Management
  • Establish scalable approaches for vulnerability management, risk assessment, and security assurance across multiple product lines.
  • Provide technical leadership during security incidents, vulnerability disclosures, and coordinated remediation efforts.
  • Support product compliance and certification initiatives including FIPS 140-3, Common Criteria, PCI HSM, Cyber Resilience Act (CRA), and other applicable security standards.
  • Review and approve security exceptions, risk acceptance decisions, and compensating controls where appropriate.
  • Collaboration & External Engagement
  • Act as a trusted advisor to engineering leaders, architects, product managers, and executive stakeholders.
  • Represent Entrust in customer security discussions, security reviews, certification engagements, and external assessments.
  • Collaborate with external researchers, independent laboratories, certification bodies, and security consultants.
  • Contribute to industry working groups, standards development efforts, and security communities where appropriate.
  • Mentoring & Organizational Impact
  • Mentor senior engineers and security practitioners, fostering technical excellence across the organization.
  • Lead technical communities of practice focused on secure development and product security.
  • Influence engineering culture by promoting security‑first thinking and secure‑by‑design principles.
  • Provide technical leadership during strategic planning, architecture reviews, and product roadmap discussions.
  • Help identify security skill gaps and contribute to workforce development initiatives.

Technical Knowledge / Skills and Experience Required

  • Extensive experience in product security, security architecture, or security engineering roles.
  • Demonstrated experience providing technical leadership across multiple teams, products, or business units.
  • Deep expertise in applied cryptography, cryptographic protocols, and security architectures.
  • Strong understanding of secure software development and software assurance practices.
  • Strong understanding of hardware security, embedded systems security, trusted execution environments, and FPGA security concepts.
  • Advanced knowledge of threat modeling methodologies and risk assessment frameworks.
  • Experience leading large‑scale vulnerability management and remediation programs.
  • Expertise with security assessment methodologies, penetration testing techniques, and offensive security concepts.
  • Experience building or deploying security tooling integrated into modern software development pipelines.
  • Strong programming capability in Python, C/C++, Go, Rust, Java, or similar languages.
  • Experience supporting or leading security certification activities including FIPS 140-3, Common Criteria, PCI HSM, or equivalent frameworks.
  • Strong understanding of modern regulatory and compliance requirements impacting product security, including CRA, NIS2, and secure development frameworks.
  • Excellent communication skills with demonstrated ability to influence executive stakeholders and technical teams.
  • Proven ability to drive organizational change through technical leadership and influence.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Electrical Engineering, Mathematics, or related discipline.
  • Master's degree preferred.
  • Relevant security certifications (CISSP, CSSLP, OSCP, GIAC, CCSP, SABSA, or similar) are desirable.
  • Demonstrated track record of leading complex security initiatives with organization‑wide impact.

At Entrust, we don't just offer jobs - we offer career journeys. Here is what you can expect when you join our team:

  • Career

Growth: Whether you're a budding developer or a seasoned expert, we're invested in your professional journey.

With learning‑forward initiatives and exciting challenges, your growth is our priority.

  • Flexibility: Life is all about balance. Whether you're remote, hybrid, or on‑site, we offer flexible options that fit your lifestyle.
  • Collaboration: Here, your voice matters. Our teams thrive on sharing ideas, brainstorming solutions, and working together to build a better tomorrow.

We believe in securing identities-but it doesn't stop there.

At Entrust, we're passionate about valuing all identities.

Our culture is built on diversity, inclusion, and respect.

From unconscious bias training for our leaders to global affinity groups that connect colleagues across the globe, we're creating a community where everyone is encouraged to be themselves.

Ready to Make an Impact?

If you're excited by the prospect of innovating, growing your career, and collaborating in a dynamic environment, Entrust is the place for you.

Join us in making a difference.

Let's build a more secure world-together.

Entrust is an EEO/AA/Disabled/Veterans Employer

Entrust values diversity and inclusion and we are committed to building a diverse workforce with wide perspectives and innovative ideas.

We welcome applications from qualified individuals of all backgrounds, and we strive to provide an accessible experience for candidates of all abilities.

If you require an accommodation, contact accessibility@entrust. com.

#J-18808-Ljbffr

Staff Product Security Engineer in Cambridge employer: Creative Information Technology, Inc.

Entrust is an exceptional employer that prioritises your career growth and work-life balance, offering flexible working arrangements whether remote, hybrid, or on-site. Our collaborative culture fosters innovation and inclusivity, ensuring every voice is heard while you tackle meaningful challenges in the field of identity-centric security solutions. With a commitment to diversity and continuous learning, Entrust empowers you to thrive in a dynamic environment where your contributions truly make a difference.

C

Contact Details:

Creative Information Technology, Inc. Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Staff Product Security Engineer in Cambridge

Join Local Tech Meetups

Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at Creative Information Technology, Inc. or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!

Contribute to Open Source Projects

Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to Creative Information Technology, Inc..

Tap into Online Developer Communities

Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like Creative Information Technology, Inc..

Explore Job Boards Specifically for Tech Roles

Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like Creative Information Technology, Inc. that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!

We think you need these skills to ace Staff Product Security Engineer in Cambridge

Product Security
Security Architecture
Cryptographic Protocols
Secure Software Development
Threat Modeling
Vulnerability Management
Penetration Testing

Some tips for your application 🫡

Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.

Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at Creative Information Technology, Inc..

Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at Creative Information Technology, Inc. and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!

Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!

How to prepare for a job interview at Creative Information Technology, Inc.

Brush Up on Your Coding Skills

For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.

Know Your Tools and Frameworks

Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If Creative Information Technology, Inc. uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.

Showcase Your Projects

Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.

Prepare for Behavioural Questions

While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.