Staff Product Security Engineer in Cambridge

Staff Product Security Engineer in Cambridge

Cambridge Full-Time 60000 - 80000 £ / year (est.) No working from home possible
G

At a Glance

  • Tasks: Join us in building a secure cloud platform for electronics design.
  • Company: Renesas Electronics, a leader in innovative technology and diversity.
  • Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
  • Other info: Collaborative environment with a focus on continuous learning and development.
  • Why this job: Make a real impact by enhancing product security in cutting-edge projects.
  • Qualifications: 5+ years in application security and strong hands-on testing experience required.

The predicted salary is between 60000 - 80000 £ per year.

Build the cloud platform that's transforming electronics design. Altium 365 for cloud lets design engineers communicate, collaborate and bring their ideas to market more efficiently than any platform in the industry.

We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention. The goal is simple: ensure that both existing functionality and new changes remain secure over time, and that real vulnerabilities are discovered before customers do.

Key Responsibilities

  • Security Regression Testing
    • Build and maintain security regression test suites covering critical application flows
    • Ensure that once fixed, vulnerabilities are permanently prevented from recurring
    • Integrate security regression into CI/CD pipelines
    • Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
  • Threat Modeling
    • Lead structured threat modeling sessions for:
      • Existing system components
      • New features and architectural changes
    • Identify attack surfaces, abuse cases, and trust boundaries
    • Translate threats into:
      • Test cases
      • Security requirements
      • Mitigation plans
    • Ensure threat modeling becomes a continuous lifecycle activity
  • Offensive Security / Red Team Activities
    • Perform manual and automated security testing simulating real attacker behavior
    • Focus on high-impact vulnerabilities, not theoretical findings
    • Validate exploitability and business impact
    • Partner with engineering teams to:
      • Reproduce issues
      • Prioritize fixes
      • Validate remediation
  • OWASP Top 10-Driven Vulnerability Discovery
    • Continuously assess the platform against OWASP Top 10 categories
    • Use deep product knowledge to find non-obvious, context-specific vulnerabilities
    • Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
  • Security Assurance for Product Changes
    • Review new features and changes for security risks
    • Ensure all changes are:
      • Threat-modeled
      • Covered by regression tests
    • Act as a security gatekeeper without becoming a bottleneck:
      • Enable teams with guidance and tooling
      • Avoid heavy process overhead
  • Collaboration & Enablement
    • Work closely with engineering teams, architecture, and SRE/Platform teams
    • Contribute to secure-by-design practices
    • Support developers in understanding and fixing vulnerabilities
    • Help scale security through:
      • Reusable patterns
      • Automation
      • Security guidance

Qualifications

Required Qualifications

  • 5+ years in Application / Product Security
  • Bachelor's Degree or equivalent of 12 years of work experience
  • Strong hands-on experience in:
    • Web application security testing
    • API security
    • Threat modeling methodologies
  • Deep understanding of OWASP Top 10
  • Experience with:
    • Manual penetration testing
    • Security regression testing
    • CI/CD security integration
  • Ability to identify business logic vulnerabilities
  • Strong understanding of:
    • Authentication, authorization, and session management
    • Multi-tenant architectures
    • Cloud-native systems

Preferred Qualifications

  • Experience in SaaS / multi-tenant platforms
  • Familiarity with:
    • Bug bounty programs
    • Red teaming
    • Security automation frameworks
  • Knowledge of:
    • AWS
    • Identity systems and federation (SSO, MFA)
    • Background in software engineering (ability to read/write code)

Renesas Electronics is an equal opportunity and affirmative action employer, committed to supporting diversity and fostering a work environment free of discrimination on the basis of sex, race, religion, national origin, gender, gender identity, gender expression, age, sexual orientation, military status, veteran status, or any other basis protected by law.

Staff Product Security Engineer in Cambridge employer: GCA Altium

Altium Limited is an exceptional employer, offering a dynamic work culture that prioritises innovation and collaboration in the fast-paced field of cloud and app security. Employees benefit from continuous professional development opportunities, a supportive team environment, and the chance to make a significant impact on the security of the Altium 365 platform. Located in a vibrant tech hub, Altium fosters a culture of creativity and growth, making it an ideal place for those seeking meaningful and rewarding employment.

G

Contact Details:

GCA Altium Recruitment Team

We think you need these skills to ace Staff Product Security Engineer in Cambridge

Security Regression Testing
Vulnerability Discovery
Threat Modeling
Manual Penetration Testing
API Security
OWASP Top 10
CI/CD Security Integration