Product Security Engineer: Build Secure SDLC & Apps

Product Security Engineer: Build Secure SDLC & Apps

Full-Time 70000 - 90000 £ / year (est.) On-site
I

At a Glance

  • Tasks: Join our team to enhance product security and drive innovation in secure software development.
  • Company: ION, a leading fintech company with a diverse and inclusive culture.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Join a global team of innovators and enjoy excellent career advancement opportunities.
  • Why this job: Make a real impact on security in a dynamic environment with cutting-edge technology.
  • Qualifications: 6+ years in Product Security, strong coding skills, and a passion for secure engineering.

The predicted salary is between 70000 - 90000 £ per year.

This is an amazing opportunity to work with the Markets Information Security Team at ION. As a Product Security Engineer, you would be the key enabler of secure and compliant products. This role reports to the Product Security Lead and partners closely with engineering and product teams to increase the overall product security posture. You will own and scale product/application security by embedding security into the Secure SDLC, automating controls in CI/CD, and driving measurable risk reduction. The role is hands-on: you will perform security-focused code review and targeted testing, strengthen API security, implement supply chain security (SCA/SBOM) practices, and run an efficient vulnerability lifecycle with clear SLAs and metrics.

Key Responsibilities:

  • Secure SDLC Ownership: Help to define lightweight, measurable SSDLC (requirements, design checks, guidance, release criteria); establish “paved roads” (reference architectures, secure templates, approved libs/patterns).
  • CI/CD Security Automation (Shift‑left): Own AppSec toolchain/pipelines (SAST, DAST, SCA, secrets, IaC/container); integrate risk‑based gating with clear developer feedback; tune rules, cut false positives, and standardize triage (tickets, auto‑routing, SLAs).
  • Code Review & Secure Engineering Support: Perform security code reviews for critical areas (authn/authz, sessions, crypto, data protection, input validation, business logic); provide remediation guidance, secure patterns, and concise code/design examples.
  • Secure Design Reviews & Threat Modeling: Run pragmatic threat modelling/design reviews for new features and changes; produce actionable outputs (mitigations, backlog, acceptance criteria, test cases); maintain requirements for identity, sensitive data, and privacy‑by‑design.
  • Supply Chain Security (SCA/SBOM): Manage dependency risk (triage, upgrade strategies, deprecations, guardrails); establish SBOM generation/use and provide evidence for assurance; assess third‑party components/SDKs and provenance/attestation risks.
  • Vulnerability Lifecycle, SLAs & Metrics: Run intake/triage across tools, pen tests, VDP/bug bounty, and internal findings; define remediation SLAs by severity/exploitability and asset criticality, manage exceptions and verify fixes; report meaningful metrics (MTTD, MTTF, reopen rate, recurring classes, coverage, control effectiveness).
  • Hands‑on Testing (Targeted & Risk‑Based): Execute focused testing on high‑risk areas (web, APIs, mobile/auth flows) to validate exploitability; coordinate third‑party testing and ensure findings translate into prioritized engineering outcomes.

Required Skills, Qualifications And Experience:

  • 6+ years in Product Security / Application Security, with demonstrable engineering-facing delivery.
  • Strong understanding of OWASP (Web + API risks) and modern attack paths (authz flaws, SSRF, injection, deserialization, business logic abuse, supply chain).
  • Hands-on experience integrating security into CI/CD (SAST/DAST/SCA/secrets), triaging findings, and enabling developer remediation.
  • Comfortable reading/reviewing code in at least one backend language (e.g., Java, C++, Go, Python, Node.js) and common web stacks.
  • Solid grasp of cloud-native delivery practices: microservices, containers, CI/CD, IaC fundamentals, observability, and logging.
  • Strong communication skills: able to translate risk into clear engineering actions and influence outcomes.

Nice to have:

  • Threat modeling experience (STRIDE or similar) with real production outcomes.
  • Fintech or regulated-environment experience in translating obligations into product controls (e.g., PCI, GDPR/DORA concepts).
  • Bug bounty/VDP experience (triage, validation, reporter comms process).

Certifications: OSWE/OSCP/GPEN/GXPN, cloud certifications, or secure software development certifications.

Ability to:

  • Effectively communicate technical issues to diverse audiences, both in writing and verbally.
  • Handle sensitive and confidential matters, situations, and data.
  • Understand and follow broad and complex instructions.
  • Comprehend technical language and to confer, analyse and write in an objective, lucid manner.
  • Work independently and prioritize multiple tasks and adapt to needed changes.
  • Remain calm under high pressure/difficult situations.

Preferred Certifications: OSWE/OSCP/GPEN/GXPN, cloud certifications, or secure software development certifications.

About Us: We’re a diverse group of visionary innovators who provide trading and workflow automation software, high-value analytics, and strategic consulting to corporations, central banks, financial institutions, and governments. Founded in 1999, we’ve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world. Over 2,000 of the world’s leading corporations, including 50% of the Fortune 500 and 30% of the world’s central banks, trust ION solutions to manage their cash, in-house banking, commodity supply chain, trading and risk. Over 800 of the world’s leading banks and broker-dealers use our electronic trading platforms to operate the world’s financial market infrastructure. ION is a rapidly expanding and dynamic group with 13,000 employees and offices in more than 40 cities around the globe. Our ever-expanding global footprint, cutting edge products, and over 40,000 customers worldwide provide an unparalleled career experience for those who share our vision. ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities, abilities, cultures, and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business. ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.

Product Security Engineer: Build Secure SDLC & Apps employer: ION

LAB49 is an exceptional employer that fosters a culture of innovation and collaboration, particularly in the dynamic field of banking transformation. With a strong emphasis on employee growth, we offer comprehensive training and development opportunities, ensuring our team members are equipped to excel in their roles. Located in a vibrant financial hub, our workplace promotes a healthy work-life balance and provides unique advantages such as access to industry-leading projects and a supportive community dedicated to quality excellence.

I

Contact Details:

ION Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Product Security Engineer: Build Secure SDLC & Apps

✨Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

✨Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including ION, love seeing candidates who actively engage in these challenges.

✨Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

✨Apply Directly Through ION

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at ION. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Product Security Engineer: Build Secure SDLC & Apps

Product Security
Application Security
Secure SDLC
CI/CD Security Automation
Security Code Review
Threat Modelling
Supply Chain Security (SCA/SBOM)

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at ION insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to ION that you’re committed to staying ahead in the game.

How to prepare for a job interview at ION

✨Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

✨Prepare for Scenario-Based Questions

Expect the interviewers at ION to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

✨Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at ION.

✨Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.