At a Glance
- Tasks: Design and secure high-performance web applications against sophisticated attacks.
- Company: Join iProov, a leader in biometric security solutions.
- Benefits: Enjoy 25 days leave, flexible working, and health perks.
- Other info: Be part of a diverse team fostering innovation and growth.
- Why this job: Make a real impact in web security while pushing tech boundaries.
- Qualifications: Expertise in JavaScript, WebAssembly, and client-side security required.
The predicted salary is between 60000 - 80000 £ per year.
Senior Web Security Engineer
About i Proov i Proov provides science-based biometric solutions that enable the world’s most security-conscious organizations to streamline secure remote onboarding and authentication for digital and physical access.
Our award-winning liveness technology and i SOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences.
Trusted by leading governments and enterprises, including the U.
Department of Homeland Security, U.
Home Office, Gov Tech Singapore, ING, and UBS, i Proov sets the standard in biometric identity assurance.
This global trust is built not only on our technology but on the strength of the people behind it.
For us, diversity at i Proov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together.
We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose.
The Role
Reports to
Head of Red Team
Location
UK (Flexible)
Comp
Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK i Proov Benefits
We're looking for an experienced Senior Web Security Engineer to design, build, and secure high-performance web applications that run in some of the world's most demanding environments.
In this role, you'll work at the intersection of browser security, Java Script runtimes, Web Assembly, anti-reverse engineering, and application hardening.
You'll help protect client-side applications against tampering, reverse engineering, and sophisticated attacks while developing highly optimized code that performs consistently across modern browsers and devices.
This is a hands-on engineering position for someone who enjoys solving difficult technical problems, understands the realities of client-side security, and is passionate about pushing the boundaries of what's possible in the browser.
How you can make an impact
You'll work on technically challenging problems that few engineering teams tackle—protecting sophisticated client-side applications in hostile environments.
You'll collaborate with experts in browser technology, security, cryptography, and systems engineering while building solutions used at global scale.
If you're passionate about Java Script internals, Web Assembly, browser security, and solving complex engineering problems, we'd love to hear from you.
- Design and implement secure Java Script and Web Assembly components for production web applications.
- Develop techniques to protect client-side code from tampering, reverse engineering, debugging, automation, and exploitation.
- Design and implement anti-tamper, integrity verification, and runtime protection mechanisms.
- Build high-performance Web Assembly modules using C++, Rust, or Assembly Script.
- Analyse browser behaviour, Java Script engines, and Web Assembly runtimes to identify security risks and performance opportunities.
- Research emerging attack techniques targeting web applications and develop practical mitigations.
- Collaborate closely with developers, product, and red teams to integrate security into the development lifecycle.
- Investigate vulnerabilities, perform root-cause analysis, and develop long-term remediation strategies.
- Contribute to technical architecture and mentor other engineers on secure development practices.
- What we would like to see from you
Within your first year, you'll have shipped secure, production-grade Java Script and Web Assembly components that real users depend on every day.
Along the way, you'll have introduced new techniques that materially strengthen our resistance to reverse engineering and client-side attacks, pushing the boundaries of what's possible in browser-based security.
You'll have found ways to make the application faster without ever compromising its security guarantees, proving that performance and protection aren't a trade-off.
Beyond the code itself, you'll have helped define the engineering standards that shape how we approach browser security and secure client-side architecture, leaving a lasting mark on how we build.
And by the end of that first year, you'll have become the person engineers across the organisation turn to when they need answers on web security, a trusted technical leader whose influence extends well beyond your own team.
- Technical Expertise
- Expert-level Java Script (ES6+) and Type Script.
- Strong experience developing production Web Assembly applications.
- Experience with Rust, C++, or another systems programming language used to produce WASM modules.
- Deep understanding of browser internals and modern web platform APIs.
• Experience securing client-side applications against
- Reverse engineering
- Runtime modification
- Instrumentation frameworks
- Code injection
- Experience with secure software architecture.
- Security Knowledge
Experience in several of the following
- Java Script de-obfuscation and obfuscation techniques
- WASM binary analysis
- Static and dynamic analysis
- Anti-debugging techniques
- Anti-tamper technologies
- Runtime integrity verification
- Secure code signing and integrity checking
- Software protection techniques
- Secure SDLC practices
- Engineering Experience
- 5+ years of software engineering experience.
- Experience designing highly performant browser-based applications.
- Strong testing, debugging, and profiling skills.
- Experience working with CI/CD pipelines and automated security testing.
- Comfortable working across Windows, mac OS, Linux, and mobile browsers.
- Excellent communication skills with the ability to explain complex technical concepts clearly.
- Nice to Have
- Experience with V8, Spider Monkey, Java Script Core, or Chromium internals.
- Knowledge of Web GPU, Web RTC, or Web Codecs.
- Experience with binary instrumentation and compiler toolchains.
- Experience building SDKs or developer platforms.
- Knowledge of mobile browser security.
- Experience with biometrics, identity verification, or fraud prevention technologies.
- Contributions to open-source security tools or security research publications.
Benefits
- 25 days Annual Leave, plus 8 Bank Holidays (more holiday with service - up to an extra 5 days off per year based on your continuous service)
- Growth Shares allocated after passing probation (6 months of service)
- Salary sacrifice schemes including: Pension, Cycle To Work and Electric Car Scheme
- Nursery Sacrifice Scheme
- Work Overseas Perk - Work globally for up to 2 weeks
- Life Assurance
- Smart Health - Access to private GP, Psychologist, Nutritionist along with tailored fitness plans for both you and your family
- Benefit from personalized 1:1 career coaching with our in-house Occupational Psychologist
- Award winning L&D platform with personal allocated training budgets
- Enhanced paid family leave
- Pension - 5% employee, 3% employer
- Flexible hybrid working environment
- Free Barista Coffee/Tea, biscuits with fruit in the We Work office
- Free access to We Work discounts and free online well-being sessions
- Vitality Health - a range of options available on this below
The Vitality Programme includes a number of reward benefits that all employees have access to as part of the plan, for example:
- Private Health cover including Dental, Optical, and Audiology
- 50% off monthly gym memberships
- Apple watches significantly discounted based member vitality status
- Half price trainers with Runners Need
- Weekly rewards – Free coffee with Café Nero
- Monthly rewards – Free Cinema ticket
- Discounts on travel with Expedia (hotels) and Mr & Mrs Smith with discounts getting greater throughout the year based on a members vitality status
- Amazon prime free months based on activity
- Up to 25% cashback at Waitrose when buying healthy foods
- 75% off stays at Champneys Health Spas
- Allen Carr’s £299 no smoking programme for free
- Access to Vitality Healthy Mind with 30% off Headspace subscriptions and the ability to earn Vitality points for using Buddhify, Calm and Headspace
- Discounts on Weight Watchers
- 50%-80% off Comprehensive Private Health screenings
- Our Culture & Recruitment Process
At i Proov, we're incredibly proud of the culture we've carefully curated.
Our culture enables diverse thought, curiosity and innovation.
Our team strives to do everything to the highest standard possible to achieve the remarkable.
To do that we need different perspectives, experiences and ideas alongside an environment where these are welcomed - we want everyone to feel confident in bringing their full capabilities to work.
We firmly believe psychological safety is key to building and nurturing great teams.
We’re a small and dynamic company, that means having the right skills is important, and we know that our best work emerges when people feel secure, welcomed and respected.
As an equal opportunities employer, we encourage applications from people of all backgrounds.
We’re committed to building a workforce that is representative of the people we serve.
We will not put someone at a disadvantage or treat them less favourably because of race, color, national origin, ancestry, age, disability, creed, religion or belief, sex, sexual orientation, gender reassignment, marriage or civil partnership, or pregnancy and maternity.
Our goal is to find people who are passionate about creating a safer, more secure world.
Our recruitment process is designed to be fair and transparent, focusing solely on your qualifications, competence, and suitability for the role.
We review all applications carefully and will be in touch with shortlisted candidates regarding the next steps in our interview process.
If you need an adjustment for a disability or any other reason during the hiring process, please send a request to careers@iproov. com
Senior Web Security Engineer (ProdSec) in London employer: iProov
iProov is an exceptional employer that champions diversity and inclusion, creating a supportive environment where every employee can thrive. With a hybrid work model based in the vibrant WeWork Waterloo in London, employees enjoy flexible working arrangements alongside competitive benefits, including a performance bonus and share options. The company prioritises personal growth and innovation, empowering its team to make meaningful contributions to cutting-edge biometric solutions that enhance security for clients worldwide.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Web Security Engineer (ProdSec) in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including iProov, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through iProov
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at iProov. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Web Security Engineer (ProdSec) in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at iProov insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to iProov that you’re committed to staying ahead in the game.
How to prepare for a job interview at iProov
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at iProov to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at iProov.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.