At a Glance
- Tasks: Engineer security into products and defend against real threats in a fast-paced environment.
- Company: Fast-scaling FinTech company with a strong focus on product security.
- Benefits: Competitive salary, share options, health insurance, and flexible hybrid working.
- Other info: Dynamic culture with excellent growth opportunities and a commitment to diversity.
- Why this job: Join a team that values security as a core engineering discipline and make a real impact.
- Qualifications: Experience in production software on AWS and a genuine security specialism.
The predicted salary is between 85000 - 100000 € per year.
Product Security Engineer
Industry: FinTech / RegTech SaaS
Location: Manchester, Hybrid (1 - 2 days a week in the office)
Salary: £85,000 - £100,000 (potentially some wiggle room for the right person)
We're working with a client we know extremely well, a fast-scaling communications compliance platform processing hundreds of millions of events a month for financial services firms across the UK, US, and beyond. They protect regulated data for thousands of firms worldwide. The threat is real, the surface is interesting, and the engineering bar is high.
We've placed a number of people here and can genuinely vouch for the culture, the team, and the ambition of the business. They're growing fast, and this is a pivotal hire as they scale.
The Role
This is a Product Security Engineer position, and the emphasis is firmly on engineering. If you're coming from a GRC, DevSecOps, or infrastructure security background, this probably isn't the right fit.
Our client is looking for a software engineer whose specialism is security, someone who writes production code, builds real detections, hardens the systems everyone else depends on, and thinks in terms of specific adversaries and specific failure modes rather than abstract control libraries.
You'll be the security subject matter expert across a rapidly scaling business, working closely with the VP of Engineering, Head of Platform, and CTO. You'll embed inside the engineering team, not alongside it, and you'll raise the bar through the tooling and patterns you ship.
What you'll be working on
- Engineering defence into the product: multi-tenant isolation, encryption and key management, IAM as code, application-layer hardening
- Securing the supply chain: provenance, build-pipeline isolation, dependency trust as a real control, third-party risk as runtime telemetry
- Detection and response: runtime detection that catches real attacks, incident response codified as automation, adversary emulation against your actual attack surface
- Securing the agentic development surface: the team ships with AI agents in the loop on every change, which brings its own attack surface. You'll own the security layer of that platform
What they're looking for
Essential:
- Several years writing production software on AWS
- A genuine security specialism with shipped defence systems you can talk to in depth
- Adversarial instincts: you follow supply-chain incidents, read postmortems, think like a threat actor
- Hands-on experience using AI coding agents in production workflows, and a clear model of where the trust boundaries are
- Threat-modelling fluency: you can walk a system design and come out with what's worth defending
Desirable:
- detection engineering at scale, supply-chain security (SLSA, sigstore, SBOM), cloud-native AWS attack patterns and their defences, incident response end-to-end, cryptography in practice
The package
- £85,000 - £100,000 (some wiggle room for the right person)
- Share options
- 25 days holiday + bank holidays + your birthday off
- Vitality health insurance + cash plan
- Juno wellbeing benefit (£100/month)
- Enhanced pension + life insurance (4x salary)
- Latest MacBook Pro + equipment budget
- Flexible hybrid working from Manchester
What you won't find here
- A CVE triage queue.
- A SOC rota.
- A compliance function dressed up as engineering.
This is a role for someone who wants to defend a real product against real adversaries, in a business that treats security as a first-class engineering discipline.
If that sounds like your kind of challenge, get in touch.
At Inara Talent, we believe everyone deserves a fair chance to shine. We connect great people from all backgrounds with opportunities where they can thrive making sure hiring is fair, inclusive, and genuinely diverse. No matter your background, we focus on what matters: your talent.
Senior Software Engineer (Security SME) in Manchester employer: Inara
Join a fast-scaling FinTech company in Manchester that prioritises security as a core engineering discipline. With a culture that values innovation and collaboration, you'll have the opportunity to work closely with senior leadership while contributing to cutting-edge security solutions. Enjoy a competitive salary, generous benefits including share options and health insurance, and a flexible hybrid working model that supports your work-life balance.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Software Engineer (Security SME) in Manchester
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, especially those already working at companies you're interested in. A friendly chat can open doors and give you insider info that could help you stand out.
✨Tip Number 2
Show off your skills! If you've got a GitHub or portfolio showcasing your security projects, make sure to highlight it during interviews. Real-world examples of your work can speak volumes about your expertise.
✨Tip Number 3
Prepare for technical interviews by brushing up on relevant security concepts and coding challenges. We recommend practicing with mock interviews or coding platforms to get comfortable with the format and types of questions you might face.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets the attention it deserves. Plus, we’re here to support you every step of the way in landing that dream job!
We think you need these skills to ace Senior Software Engineer (Security SME) in Manchester
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in security engineering. We want to see how your skills align with the specific requirements of the role, so don’t hold back on showcasing your relevant projects!
Show Off Your Technical Skills:When you’re writing your application, be sure to include specific examples of your work with AWS and any defence systems you've implemented. We love seeing real-world applications of your skills, so let us know what you've built and how it’s made a difference.
Demonstrate Your Adversarial Thinking:We’re looking for someone who thinks like a threat actor. In your application, share instances where you’ve identified potential vulnerabilities or threats in a system. This will show us that you have the right mindset for the role!
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to keep track of your application and ensure it gets the attention it deserves. Plus, we love seeing candidates who follow instructions!
How to prepare for a job interview at Inara
✨Know Your Stuff
Make sure you brush up on your production software experience, especially with AWS. Be ready to discuss specific security systems you've implemented and how they’ve defended against real threats. This role is all about practical application, so have examples at the ready!
✨Think Like a Threat Actor
Showcase your adversarial instincts by discussing recent supply-chain incidents or postmortems you've followed. The interviewers will want to see that you can think critically about potential vulnerabilities and how to mitigate them, so prepare some scenarios to demonstrate your thought process.
✨Get Hands-On with AI Agents
Since this role involves working with AI coding agents, be prepared to talk about your hands-on experience in this area. Discuss how you've integrated these tools into your workflows and where you see trust boundaries. This will show that you’re not just familiar with the technology but can also leverage it effectively.
✨Master Threat Modelling
Be ready to walk through a system design and identify what’s worth defending. This is crucial for the role, so practice articulating your threat-modelling fluency. Think of a project where you had to assess risks and explain how you prioritised security measures.