Product Security Engineer (we have office locations in Cambridge, Leeds & London)

Product Security Engineer (we have office locations in Cambridge, Leeds & London)

Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Genomics England Limited

At a Glance

  • Tasks: Join our Cyber Security team to integrate security into innovative software development.
  • Company: Genomics England, a leader in genomic medicine and research.
  • Benefits: 30 days holiday, flexible working, learning budgets, and health perks.
  • Other info: Diverse and inclusive workplace with excellent career growth opportunities.
  • Why this job: Make a real impact on healthcare by securing groundbreaking genomic technologies.
  • Qualifications: Experience in cyber security engineering and embedding security in software development.

The predicted salary is between 60000 - 80000 £ per year.

Genomics England is a global leader in enabling genomic medicine and research, focused on creating a world where everyone benefits from genomic healthcare. Building on the 100,000 Genomes Project, we support the NHS’s world‑first national whole genome sequencing service and run the growing National Genomic Research Library, alongside delivering numerous major genomics initiatives. By connecting research and clinical care at national scale, we enable immediate healthcare benefits and advances for the future. Our mission is to provide the evidence and digital systems so that by 2035 genomics could play a role in up to half of all healthcare interactions, whilst securing the UK’s position as the best place to discover, prove and benefit from genomic innovations.

As a Product Security Engineer, you will work as part of the Cyber Security team at Genomics England, partnering closely with engineering squads and product teams to integrate security into day‑to‑day delivery. The purpose of this role is to bring security closer to where engineering decisions are made, enabling teams to adopt Genomics England’s security standards in a practical and scalable way. You will work directly with squads as a trusted partner, helping them build and deliver secure systems rather than acting as a central gatekeeper. You will support teams to shift security left by contributing to secure design and development from the outset. This includes helping teams implement security testing in CI/CD pipelines, improving vulnerability management within squads, and ensuring security issues are addressed as part of normal delivery.

Acting as a bridge between central security and delivery teams, you will translate security policies and risk expectations into clear, actionable engineering practices. You will contribute to threat modelling, design discussions, and security reviews, helping teams break down complex security challenges into pragmatic technical solutions. This is a hands‑on, product‑embedded security role. While it is not a platform or site reliability engineering position, it requires strong practical familiarity with cloud‑native systems, CI/CD pipelines and infrastructure‑as‑code to credibly influence design and implementation decisions within squads. A key part of the role is enabling and scaling security capability through the Security Champions programme. You will support and grow this community, helping champions build security knowledge and embed good practices within their teams. Through this role, you will help evolve Genomics England towards a model where security is owned by engineering teams, with Cyber Security providing guidance, expertise, and enablement.

Skills and Experience for Success:

  • A strong foundation in cyber security engineering, including secure design principles and risk‑based decision making.
  • Practical experience embedding security into software development, including supporting shift‑left practices across design, development, and delivery.
  • Experience working hands‑on with engineering teams, with the ability to understand application architectures, review code or designs, and help troubleshoot security issues.
  • Experience integrating security controls into CI/CD pipelines, including code, dependency, and infrastructure‑as‑code scanning, with an emphasis on automation and developer experience.
  • Practical familiarity with public cloud environments, particularly AWS, including common security patterns and risks.
  • Experience working alongside Infrastructure‑as‑Code and delivery pipelines (e.g. Terraform, GitLab CI/CD or equivalent), with the ability to review and influence implementations.
  • Confidence engaging at an engineering level on designs, pipelines and configurations, even where you are not the primary implementer.
  • Solid understanding of vulnerability management, including helping teams interpret findings, prioritise remediation, and manage vulnerabilities as part of business‑as‑usual delivery.
  • Experience facilitating threat modelling and contributing to design reviews, helping teams identify and address security risks early in the development lifecycle.
  • Ability to translate security standards and policies into clear, actionable engineering guidance, patterns, and reusable approaches.
  • Experience working in modern engineering environments (e.g. cloud platforms, APIs, microservices, or containerised systems).
  • Strong communication and stakeholder‑management skills, with the ability to influence teams through collaboration rather than authority.
  • An interest in security education, enablement, and culture, including mentoring engineers and supporting security champions within teams.

This role does not require ownership of production platforms or central security tooling but does require the credibility to work closely with engineers and influence how security is implemented. Qualifications are not essential for this role; practical experience working with engineering teams and embedding security into delivery is far more important. However, the following certifications or areas of formal training may be beneficial:

  • Certifications or training in secure software development or application security (e.g. secure coding, secure SDLC, or application security practices).
  • Knowledge of cloud security principles, whether through formal certification or hands‑on experience.
  • Training in threat modelling, secure design, or security architecture.
  • Exposure to DevSecOps practices, including integrating security into CI/CD pipelines.
  • Evidence of ongoing professional development in cyber security or software security, such as learning new tools, techniques, or contributing to security practices within teams.

Equivalent real‑world experience enabling teams to adopt secure development practices, integrate security into CI/CD pipelines, and manage vulnerabilities effectively is considered equally valuable.

Salary From: £78,850

Closing Date: Sunday 12th July at 23:00 (UK time)

Being an integral part of such a meaningful mission is extremely rewarding in itself, but in order to support our people, we’re continually improving our benefits package. We pride ourselves on investing in our people and supporting them to achieve their career goals, as well as offering a benefits package including:

  • Generous Leave: 30 days’ holiday plus bank holidays, plus additional leave for long service, and also the option to apply for up to 30 days of remote working abroad annually (approval required).
  • Family-Friendly: Blended working arrangements, flexible working, enhanced maternity, paternity and shared parental leave benefits.
  • Pension & Financial: Defined contribution pension (Genomics England double‑matches up to 10%, however you can contribute more if you wish), Life Assurance (3x salary), an Electric Vehicle salary sacrifice scheme and a Give As You Earn scheme.
  • Learning & Development: Individual learning budgets, support for training and certifications, and reimbursement for one annual professional subscription (approval required).
  • Recognition & Rewards: Employee recognition programme and referral scheme.
  • Health & Wellbeing: Subsidised gym membership, a free Headspace account, and access to an Employee Assistance Programme, eye tests, flu jabs.

Equal opportunities and our commitment to a diverse and inclusive workplace: Genomics England is actively committed to providing and supporting an inclusive environment that promotes equity, diversity and inclusion best practice both within our community and in any other area where we have influence. We are proud of our diverse community where everyone can come to work and feel welcomed and treated with respect regardless of any disability, ethnicity, gender, gender identity, religion, sexual orientation, or social background. Genomics England’s policies of non‑discrimination and equity will be applied fairly to all people, regardless of age, disability, gender identity or reassignment, marital or civil partnership status, being pregnant or recently becoming a parent, race, religion or beliefs, sex or sexual orientation, length of service, whether full or part‑time or employed under a permanent or a fixed‑term contract or any other relevant factor. Genomics England does not tolerate any form of discrimination, harassment, victimisation or bullying at work. Such behaviour undermines our mission and core values and diminishes the dignity, respect and integrity of all parties. Our People policies outline our commitment to inclusivity.

Product Security Engineer (we have office locations in Cambridge, Leeds & London) employer: Genomics England Limited

Genomics England is an exceptional employer, offering a dynamic work culture that prioritises innovation and collaboration in the field of genomic medicine. With generous leave policies, flexible working arrangements, and a strong commitment to employee development, we empower our staff to grow their careers while contributing to meaningful healthcare advancements. Our inclusive environment fosters diversity and respect, making it a rewarding place to work for those passionate about making a difference in healthcare.

Genomics England Limited

Contact Details:

Genomics England Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Product Security Engineer (we have office locations in Cambridge, Leeds & London)

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Genomics England Limited, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Genomics England Limited

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Genomics England Limited. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Product Security Engineer (we have office locations in Cambridge, Leeds & London)

SQL
Communication Skills
Python
Problem-Solving Skills
Automation
Data Engineering
Data Pipeline Development

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Genomics England Limited insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Genomics England Limited that you’re committed to staying ahead in the game.

How to prepare for a job interview at Genomics England Limited

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Genomics England Limited to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Genomics England Limited.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.