Staff Product Security Engineer in Cambridge

Staff Product Security Engineer in Cambridge

Cambridge Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Entrust

At a Glance

  • Tasks: Lead security strategy and architecture for cutting-edge cryptographic products.
  • Company: Join Entrust, a leader in identity-centric security solutions.
  • Benefits: Flexible work options, career growth opportunities, and a collaborative culture.
  • Other info: Diverse and inclusive workplace focused on innovation and teamwork.
  • Why this job: Make a real impact on global security while advancing your career.
  • Qualifications: Strong background in security engineering and leadership skills required.

The predicted salary is between 63000 - 77000 £ per year.

Join us at Entrust. At Entrust, we’re shaping the future of identity centric security solutions. From our comprehensive portfolio of solutions to our flexible, global workplace, we empower careers, foster collaboration, and build solutions that help keep the world moving safely.

Get to Know Us. Headquartered in Minnesota, Entrust is an industry leader in identity-centric security solutions, serving over 150 countries with cutting-edge, scalable technologies. But our secret weapon? Our people. It’s the curiosity, dedication, and innovation that drive our success and help us anticipate the future.

Position Overview: The Staff Product Security Engineer is a senior technical leader responsible for defining and driving the security strategy, architecture, and engineering practices across Entrust's cryptographic product portfolio. This role provides technical leadership beyond individual products, influencing security decisions across multiple engineering teams and ensuring security is embedded throughout the entire product lifecycle. The Staff Product Security Engineer serves as a recognized security subject matter expert, partnering with product management, engineering leadership, certification teams, and executive stakeholders to establish security roadmaps, enhance security capabilities, and address emerging threats. This role combines deep technical expertise in software, hardware, and cryptographic security with strong leadership and mentoring capabilities.

You will lead complex security initiatives, establish engineering standards, drive security architecture reviews, and guide teams in adopting secure-by-design principles. You will also represent security engineering in customer engagements, security audits, certification activities, and interactions with external security researchers and industry experts. A strong background in mathematics, engineering, computer science, or information security is essential. The successful candidate will demonstrate a proven ability to influence technical direction, solve highly complex security challenges, and drive security excellence across the organization.

Responsibilities:

  • Technical Leadership & Strategy
    • Define and drive product security strategy, architecture principles, and security engineering roadmaps across multiple products and platforms.
    • Lead the security architecture review process for new products, major feature developments, and platform changes.
    • Establish and evolve secure development standards, security design patterns, and engineering best practices.
    • Serve as the primary technical authority for complex security architecture decisions and risk-based security trade-off discussions.
    • Drive strategic security initiatives that improve security posture, development efficiency, and regulatory readiness across the organization.
    • Anticipate emerging threats, industry trends, and regulatory requirements and translate these into actionable engineering improvements.
  • Product Security Engineering
    • Collaborate with cross-functional teams to integrate security requirements into product design, development, deployment, and maintenance processes.
    • Lead threat modeling activities for critical systems, products, and architectures.
    • Conduct and oversee advanced security assessments, vulnerability investigations, attack surface analyses, and risk evaluations.
    • Design, implement, and review security controls, cryptographic protections, and system hardening mechanisms.
    • Lead investigations of critical security issues and provide technical direction for remediation efforts.
    • Guide secure design reviews and code review activities for business-critical products.
  • Security Tooling & Automation
    • Define and drive the security tooling strategy across software and hardware development environments.
    • Lead the development and adoption of advanced security testing capabilities, including fuzzing, software composition analysis (SCA), static analysis, dynamic analysis, memory safety validation, and vulnerability discovery tooling.
    • Partner with DevOps and engineering teams to embed security automation and policy enforcement into CI/CD processes.
    • Improve vulnerability detection, triage, and remediation workflows through automation and data-driven approaches.
  • Security Governance & Risk Management
    • Establish scalable approaches for vulnerability management, risk assessment, and security assurance across multiple product lines.
    • Provide technical leadership during security incidents, vulnerability disclosures, and coordinated remediation efforts.
    • Support product compliance and certification initiatives including FIPS 140-3, Common Criteria, PCI HSM, Cyber Resilience Act (CRA), and other applicable security standards.
    • Review and approve security exceptions, risk acceptance decisions, and compensating controls where appropriate.
  • Collaboration & External Engagement
    • Act as a trusted advisor to engineering leaders, architects, product managers, and executive stakeholders.
    • Represent Entrust in customer security discussions, security reviews, certification engagements, and external assessments.
    • Collaborate with external researchers, independent laboratories, certification bodies, and security consultants.
    • Contribute to industry working groups, standards development efforts, and security communities where appropriate.
  • Mentoring & Organizational Impact
    • Mentor senior engineers and security practitioners, fostering technical excellence across the organization.
    • Lead technical communities of practice focused on secure development and product security.
    • Influence engineering culture by promoting security-first thinking and secure-by-design principles.
    • Provide technical leadership during strategic planning, architecture reviews, and product roadmap discussions.
    • Help identify security skill gaps and contribute to workforce development initiatives.

Technical Knowledge / Skills and Experience Required:

  • Extensive experience in product security, security architecture, or security engineering roles.
  • Demonstrated experience providing technical leadership across multiple teams, products, or business units.
  • Deep expertise in applied cryptography, cryptographic protocols, and security architectures.
  • Strong understanding of secure software development and software assurance practices.
  • Strong understanding of hardware security, embedded systems security, trusted execution environments, and FPGA security concepts.
  • Advanced knowledge of threat modeling methodologies and risk assessment frameworks.
  • Experience leading large-scale vulnerability management and remediation programs.
  • Expertise with security assessment methodologies, penetration testing techniques, and offensive security concepts.
  • Experience building or deploying security tooling integrated into modern software development pipelines.
  • Strong programming capability in Python, C/C++, Go, Rust, Java, or similar languages.
  • Experience supporting or leading security certification activities including FIPS 140-3, Common Criteria, PCI HSM, or equivalent frameworks.
  • Strong understanding of modern regulatory and compliance requirements impacting product security, including CRA, NIS2, and secure development frameworks.
  • Excellent communication skills with demonstrated ability to influence executive stakeholders and technical teams.
  • Proven ability to drive organizational change through technical leadership and influence.

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, Electrical Engineering, Mathematics, or related discipline.
  • Master's degree preferred.
  • Relevant security certifications (CISSP, CSSLP, OSCP, GIAC, CCSP, SABSA, or similar) are desirable.
  • Demonstrated track record of leading complex security initiatives with organization-wide impact.

At Entrust, we don’t just offer jobs – we offer career journeys. Here is what you can expect when you join our team:

  • Career Growth: Whether you’re a budding developer or a seasoned expert, we’re invested in your professional journey. With learning-forward initiatives and exciting challenges, your growth is our priority.
  • Flexibility: Life is all about balance. Whether you’re remote, hybrid, or on-site, we offer flexible options that fit your lifestyle.
  • Collaboration: Here, your voice matters. Our teams thrive on sharing ideas, brainstorming solutions, and working together to build a better tomorrow.

We believe in securing identities—but it doesn’t stop there. At Entrust, we’re passionate about valuing all identities. Our culture is built on diversity, inclusion, and respect. From unconscious bias training for our leaders to global affinity groups that connect colleagues across the globe, we’re creating a community where everyone is encouraged to be themselves.

Ready to Make an Impact? If you’re excited by the prospect of innovating, growing your career, and collaborating in a dynamic environment, Entrust is the place for you. Join us in making a difference. Let’s build a more secure world—together.

Apply today!

For more information, visit www.entrust.com.

Staff Product Security Engineer in Cambridge employer: Entrust

Entrust is an exceptional employer that prioritises employee growth and development, offering professional learning opportunities tailored to enhance your skills as a Systems Integrator. With a flexible work environment that supports remote, hybrid, or on-site options, you will thrive in an inclusive and collaborative culture that values diversity and encourages innovation. Join us to make a meaningful impact while working with cutting-edge identity and security solutions in a dynamic team setting.

Entrust

Contact Details:

Entrust Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Staff Product Security Engineer in Cambridge

Join Local Tech Meetups

Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at Entrust or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!

Contribute to Open Source Projects

Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to Entrust.

Tap into Online Developer Communities

Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like Entrust.

Explore Job Boards Specifically for Tech Roles

Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like Entrust that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!

We think you need these skills to ace Staff Product Security Engineer in Cambridge

Product Security
Security Architecture
Cryptographic Security
Technical Leadership
Threat Modelling
Vulnerability Management
Security Assessments

Some tips for your application 🫡

Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.

Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at Entrust.

Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at Entrust and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!

Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!

How to prepare for a job interview at Entrust

Brush Up on Your Coding Skills

For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.

Know Your Tools and Frameworks

Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If Entrust uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.

Showcase Your Projects

Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.

Prepare for Behavioural Questions

While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.