At a Glance
- Tasks: Join our Security Engineering team to enhance product security and tackle real-world vulnerabilities.
- Company: Glasswall, a leading cybersecurity firm with a mission-driven culture.
- Benefits: Flexible working, competitive salary, private medical insurance, and 25 days holiday.
- Other info: Diverse and inclusive workplace focused on work-life balance and personal growth.
- Why this job: Make a tangible impact in cybersecurity while working with cutting-edge AI tools.
- Qualifications: 3-5 years in application security, strong communication skills, and coding experience.
The predicted salary is between 63000 - 77000 Β£ per year.
Glasswall is looking for a hands-on
Security Engineer with 3-5 years of experience to join our small, high-impact Security Engineering team.
Reporting to the Lead Security Engineer, you will help embed security throughout the product design and development lifecycle.
You will investigate security findings, assess their practical risk, work with engineering teams on remediation, and verify that issues have been resolved.
You will also help identify systemic improvements that prevent similar vulnerabilities from recurring.
We use AI-assisted tools for activities such as code review, threat modelling, triage and security testing.
These tools increase our coverage, while engineers remain accountable for all analysis and decisions.
You will help improve these workflows and contribute to securing the AI-enabled features in Glasswall's products.
Responsibilities
- Conduct threat modelling and secure design reviews for new features, services and architecture changes, identifying risks early and recommending practical security controls
- Perform secure code reviews and hands-on testing of our applications and APIs, combining manual analysis with SAST, DAST, SCA, secret scanning, container scanning and Ia C scanning
- Triage security findings to determine their practical exploitability and business impact, prioritising remediation based on reachability, exposure and relevant threat intelligence
- Partner with engineering teams to develop remediation plans, provide code-level guidance, contribute fixes where appropriate and verify that issues have been resolved
- Investigate the root causes of vulnerabilities and reduce recurrence by introducing secure patterns, targeted linting rules and appropriate pipeline controls
- Integrate, operate and tune security tools across CI/CD workflows, automating scanning, triage and reporting to improve coverage and reduce noise
- Develop and improve the AI agents, prompts and automation that support code review, threat modelling, triage and security testing, evaluating their output and maintaining human accountability
- Contribute to container, Kubernetes and software supply chain security by assessing configurations and dependencies, supporting SBOM adoption and improving build and deployment controls
- Support external penetration tests, vulnerability disclosure and bug bounty programmes by helping define scope, reproducing and validating findings, and coordinating remediation
- Contribute to product security incident response and secure development standards by investigating issues, documenting lessons learned and turning them into practical guidance.
- Required Knowledge, experience and values
- 3-5 Years of Hands-on experience in application security, product security or Dev Sec Ops within a software product environment
- Experience reviewing unfamiliar code, identifying security defects and explaining them clearly to engineering teams
- Practical knowledge of common vulnerability categories, including the OWASP Top 10 and CWE classifications
- Vulnerability analysis and exploitability assessment skills, including familiarity with CVSS, EPSS and CISA's Known Exploited Vulnerabilities catalogue
- Experience working with engineering teams to prioritise and remediate security findings
- Practical knowledge of threat modelling and risk assessment
- Hands-on experience with at least one of SAST, DAST or SCA tooling in a CI/CD environment
- Practical experience using LLMs or agentic AI tools, with an understanding of their strengths and limitations in security workflows
- Some hands-on security testing experience, such as penetration testing, red teaming, bug bounty work or CTFs
- Programming ability in at least one language, plus scripting skills sufficient to contribute fixes and automation (we use C#, Python, Bash and Power Shell)
- Clear communication and sound, risk-based decision-making that balances security, delivery pace and cost.
We encourage you to apply even if your experience is not a 100% match with the position.
- Beneficial Knowledge, experience, and values
- A drive to identify and automate repetitive manual work
- Experience building or security testing LLM and agentic AI systems, including prompt injection testing, AI red teaming, guardrails, or MCP and tool-use security
- Secure development experience in . NET
- Knowledge of cloud and container security across Azure or AWS and Kubernetes
- Experience with CI/CD platforms such as Azure Dev Ops or Argo Workflows, and an understanding of how security controls fit within them
- Knowledge of standards and frameworks such as OWASP ASVS, NIST SSDF, MITRE ATT&CK and SLSA
- Experience with Application Security Posture Management (ASPM) tools
- Experience with fuzzing or security testing of file parsers and binary formats
- Experience running or managing penetration tests, vulnerability disclosure processes or bug bounty programmes
- Engagement with the security community through activities such as security research, bug bounty results, published CVEs or advisories, CTF participation, conference speaking or technical writing.
About Us
We didn't start out as a traditional security product.
In the beginning, Glasswall was one of only two file sanitization filters in the US Intelligence Community's highly classified networks.
We are rated #1 by the National Security Agency.
We designed Glasswall CDR to protect businesses against the most advanced file-based threats.
Today, we're trusted by commercial and government organisations around the world.
In June 2025 Glasswall officially entered a new era of growth and innovation having been acquired by the leading private equity firm, PSG Equity.
This marks a significant milestone for our company and one that underscores the strength of our business, the dedication of our team, and the exciting potential that lies ahead.
With PSG's strong track record of scaling high-growth cybersecurity and technology businesses, we are better positioned than ever to accelerate innovation, expand into new markets, and deliver even greater value to our clients, employees, and stakeholders.
Cybersecurity is a mission-critical field, and we've always believed that staying ahead means moving faster, continually adapting to meet new challenges and investing more boldly in the future.
This partnership empowers us to do exactly that while maintaining the same leadership, values, and commitment to excellence that have brought us this far
We're excited for what's to come so now is a great time for you to join us on our journey.
Inclusion
At Glasswall we believe that diversity of people and thought are central to our purpose.
We are committed to making Glasswall a company that is attractive to people of many different backgrounds.
This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions.
We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce.
One of our corporate objectives is to ensure that the organisational health of the firm is highly rated by our employees.
We believe that this is only possible if we promote a culture of inclusion and respect across our business.
Every six months we survey employees on a range of questions relating to our organisational health.
This holds a mirror-up to a business and ensures that we can focus on where we need to do better.
We have an Organisational Health Committee, which is chaired by a non-executive position.
The panel has been formed to guide the leadership in taking positive action that supports a good work-life balance, family friendly relations and to be inviting to a diverse range of potential employees.
We also have a Women in Technology Group which has been formed to promote balance in the way that we communicate with, promote, encourage, and support people across our business.
Work/Life Balance
Our team puts a high value on work-life balance.
It isn't about how many hours you spend at home or at work; it's about the flow you establish that brings energy to both parts of your life.
We believe striking the right balance between your personal and professional life is critical to lifelong happiness and fulfillment.
We offer flexibility in working hours and encourage you to find your own balance between your work and personal lives.
Salary and Benefits
- Glasswall offers a competitive salary and incentives package.
- We offer flexible and remote working options, with hybrid working from our office in the Central London area.
- Office travel and incidental WFH expense coverage.
- 25 days holiday (plus public holidays).
- Private Medical Insurance including mental health support and cancer care.
- Enhanced sick pay.
- Company sponsored life, critical illness, and income protection insurance.
- Contributory pension scheme.
- Access to 'salary sacrifice' benefits such as Cycle to Work and Tech Schemes.
A successful candidate will live in the United Kingdom and be comfortable working from home with some meetings being held in the London office.
We are looking for someone with relevant skills and experience, not a checklist that exactly matches the job description.
We want to help you grow, and in return, you help us grow into a stronger, more inclusive organisation.
Glasswall is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, disability, age, or other legally protected status.
#J-18808-Ljbffr
Security Engineer at Glasswall employer: Glasswall Solutions Limited
At Glasswall, we pride ourselves on being an exceptional employer, offering a dynamic work environment in Central London that fosters innovation and collaboration. Our commitment to employee growth is evident through our flexible working options, competitive salary packages, and a strong focus on work-life balance, ensuring that every team member can thrive both personally and professionally. Join us as we continue to lead in cybersecurity, where your contributions will directly impact the safety of businesses worldwide.
Contact Details:
Glasswall Solutions Limited Recruitment Team