Product Security Engineer: Build Secure SDLC & Apps
Product Security Engineer: Build Secure SDLC & Apps

Product Security Engineer: Build Secure SDLC & Apps

Full-Time 70000 - 90000 ÂŁ / year (est.) No home office possible
ION

At a Glance

  • Tasks: Join our team to enhance product security and drive innovation in secure software development.
  • Company: ION, a leading fintech company with a diverse and inclusive culture.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Why this job: Make a real impact on security in a dynamic environment with cutting-edge technology.
  • Qualifications: 6+ years in Product Security, strong coding skills, and a passion for secure engineering.
  • Other info: Join a global team of innovators and enjoy excellent career advancement opportunities.

The predicted salary is between 70000 - 90000 ÂŁ per year.

This is an amazing opportunity to work with the Markets Information Security Team at ION. As a Product Security Engineer, you would be the key enabler of secure and compliant products. This role reports to the Product Security Lead and partners closely with engineering and product teams to increase the overall product security posture. You will own and scale product/application security by embedding security into the Secure SDLC, automating controls in CI/CD, and driving measurable risk reduction. The role is hands-on: you will perform security-focused code review and targeted testing, strengthen API security, implement supply chain security (SCA/SBOM) practices, and run an efficient vulnerability lifecycle with clear SLAs and metrics.

Key Responsibilities:

  • Secure SDLC Ownership: Help to define lightweight, measurable SSDLC (requirements, design checks, guidance, release criteria); establish “paved roads” (reference architectures, secure templates, approved libs/patterns).
  • CI/CD Security Automation (Shift‑left): Own AppSec toolchain/pipelines (SAST, DAST, SCA, secrets, IaC/container); integrate risk‑based gating with clear developer feedback; tune rules, cut false positives, and standardize triage (tickets, auto‑routing, SLAs).
  • Code Review & Secure Engineering Support: Perform security code reviews for critical areas (authn/authz, sessions, crypto, data protection, input validation, business logic); provide remediation guidance, secure patterns, and concise code/design examples.
  • Secure Design Reviews & Threat Modeling: Run pragmatic threat modelling/design reviews for new features and changes; produce actionable outputs (mitigations, backlog, acceptance criteria, test cases); maintain requirements for identity, sensitive data, and privacy‑by‑design.
  • Supply Chain Security (SCA/SBOM): Manage dependency risk (triage, upgrade strategies, deprecations, guardrails); establish SBOM generation/use and provide evidence for assurance; assess third‑party components/SDKs and provenance/attestation risks.
  • Vulnerability Lifecycle, SLAs & Metrics: Run intake/triage across tools, pen tests, VDP/bug bounty, and internal findings; define remediation SLAs by severity/exploitability and asset criticality, manage exceptions and verify fixes; report meaningful metrics (MTTD, MTTF, reopen rate, recurring classes, coverage, control effectiveness).
  • Hands‑on Testing (Targeted & Risk‑Based): Execute focused testing on high‑risk areas (web, APIs, mobile/auth flows) to validate exploitability; coordinate third‑party testing and ensure findings translate into prioritized engineering outcomes.

Required Skills, Qualifications And Experience:

  • 6+ years in Product Security / Application Security, with demonstrable engineering-facing delivery.
  • Strong understanding of OWASP (Web + API risks) and modern attack paths (authz flaws, SSRF, injection, deserialization, business logic abuse, supply chain).
  • Hands-on experience integrating security into CI/CD (SAST/DAST/SCA/secrets), triaging findings, and enabling developer remediation.
  • Comfortable reading/reviewing code in at least one backend language (e.g., Java, C++, Go, Python, Node.js) and common web stacks.
  • Solid grasp of cloud-native delivery practices: microservices, containers, CI/CD, IaC fundamentals, observability, and logging.
  • Strong communication skills: able to translate risk into clear engineering actions and influence outcomes.

Nice to have:

  • Threat modeling experience (STRIDE or similar) with real production outcomes.
  • Fintech or regulated-environment experience in translating obligations into product controls (e.g., PCI, GDPR/DORA concepts).
  • Bug bounty/VDP experience (triage, validation, reporter comms process).

Certifications: OSWE/OSCP/GPEN/GXPN, cloud certifications, or secure software development certifications.

Ability to:

  • Effectively communicate technical issues to diverse audiences, both in writing and verbally.
  • Handle sensitive and confidential matters, situations, and data.
  • Understand and follow broad and complex instructions.
  • Comprehend technical language and to confer, analyse and write in an objective, lucid manner.
  • Work independently and prioritize multiple tasks and adapt to needed changes.
  • Remain calm under high pressure/difficult situations.

Preferred Certifications: OSWE/OSCP/GPEN/GXPN, cloud certifications, or secure software development certifications.

About Us: We’re a diverse group of visionary innovators who provide trading and workflow automation software, high-value analytics, and strategic consulting to corporations, central banks, financial institutions, and governments. Founded in 1999, we’ve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world. Over 2,000 of the world’s leading corporations, including 50% of the Fortune 500 and 30% of the world’s central banks, trust ION solutions to manage their cash, in-house banking, commodity supply chain, trading and risk. Over 800 of the world’s leading banks and broker-dealers use our electronic trading platforms to operate the world’s financial market infrastructure. ION is a rapidly expanding and dynamic group with 13,000 employees and offices in more than 40 cities around the globe. Our ever-expanding global footprint, cutting edge products, and over 40,000 customers worldwide provide an unparalleled career experience for those who share our vision. ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities, abilities, cultures, and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business. ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.

Product Security Engineer: Build Secure SDLC & Apps employer: ION

ION is an exceptional employer that fosters a dynamic and inclusive work culture, providing employees with the opportunity to engage in meaningful projects that enhance product security within a rapidly growing fintech environment. With a commitment to professional development, employees can expect robust growth opportunities, hands-on experience in cutting-edge technologies, and a supportive atmosphere that values diverse perspectives. Located in a global hub for financial technology, ION offers unique advantages such as collaboration with industry leaders and access to a vast network of resources.
ION

Contact Detail:

ION Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Product Security Engineer: Build Secure SDLC & Apps

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to secure SDLC and application security. This gives potential employers a taste of what you can do and sets you apart from the crowd.

✨Tip Number 3

Prepare for interviews by brushing up on common security scenarios and coding challenges. Practice explaining your thought process clearly, as communication is key in this role. We want to see how you tackle problems and convey your ideas!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at ION.

We think you need these skills to ace Product Security Engineer: Build Secure SDLC & Apps

Product Security
Application Security
Secure SDLC
CI/CD Security Automation
Security Code Review
Threat Modelling
Supply Chain Security (SCA/SBOM)
Vulnerability Lifecycle Management
OWASP Knowledge
Backend Programming Languages (Java, C++, Go, Python, Node.js)
Cloud-Native Delivery Practices
Strong Communication Skills
Bug Bounty/VDP Experience
Certifications (OSWE/OSCP/GPEN/GXPN)

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in product security and application security. We want to see how your skills align with the key responsibilities mentioned in the job description.

Showcase Your Hands-On Experience: Since this role is hands-on, don’t forget to include specific examples of your work with secure SDLC, CI/CD automation, and code reviews. We love seeing real-world applications of your skills!

Communicate Clearly: Your ability to translate complex security issues into clear actions is crucial. Use straightforward language in your application to demonstrate your communication skills, as this is something we highly value.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity with the Markets Information Security Team!

How to prepare for a job interview at ION

✨Know Your Stuff

Make sure you brush up on your knowledge of OWASP and modern attack paths. Be ready to discuss specific vulnerabilities and how they relate to the role. This will show that you’re not just familiar with the theory but can apply it practically.

✨Showcase Your Hands-On Experience

Prepare to talk about your hands-on experience with CI/CD security automation and secure coding practices. Bring examples of past projects where you integrated security into the development lifecycle, as this will demonstrate your capability to own and scale product security.

✨Communicate Clearly

Practice explaining complex security concepts in simple terms. You’ll need to communicate effectively with engineering teams, so being able to translate technical jargon into clear actions is key. Think of scenarios where you’ve successfully influenced outcomes through effective communication.

✨Be Ready for Technical Questions

Expect technical questions related to code reviews and threat modelling. Brush up on your coding skills in at least one backend language and be prepared to discuss how you would approach a security review or threat model for a new feature. This will highlight your practical skills and problem-solving abilities.

Product Security Engineer: Build Secure SDLC & Apps
ION

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>