At a Glance
- Tasks: Engineer robust security solutions for financial communications and tackle real-world engineering challenges.
- Company: Join MirrorWeb, a leading compliance platform for financial services.
- Benefits: Competitive salary, remote work options, and opportunities for professional growth.
- Other info: Dynamic team environment with a focus on innovation and real-world problem-solving.
- Why this job: Make a significant impact by securing vital data for thousands of firms worldwide.
- Qualifications: Experience in software development, particularly with AWS and security-focused projects.
The predicted salary is between 72000 - 88000 Β£ per year.
The hardest security problems we face aren't policy problems. They're engineering problems. Supply-chain operators and financially-motivated attackers who turn a compromised dependency into production access require engineering solutions.
A Product Security Engineer is a software engineer whose specialism is making those attack paths hard, expensive, or impossible. They write production code to defend the regulated communications record of thousands of financial firms. The data is a real target, and the work is engineering work.
MirrorWeb is a communications compliance supervision platform that processes hundreds of millions of events a month for thousands of financial-services firms worldwide. You'll work across the platform: web capture, large-scale data pipelines, archiving, the customer-facing product, and the developer infrastructure.
- Engineer defence into the product:
Encryption and key management you'd trust on your own data. IAM modelled as code, reviewed like code, with privilege-escalation paths analysed before they ship. Security as a property of how the product is built, not a layer on top.
You'll engineer the systems that make our supply chain defensible: provenance and integrity for what we build (SLSA, sigstore patterns, signed artifacts), dependency trust as a real control rather than a manifest scan, build-pipeline isolation, and third-party risk as runtime telemetry. Our engineers ship with AI agents in the loop on every change, creating new attack surfaces such as prompt injection against agent harnesses and untrusted MCP server outputs.
You'll own the security layer of our agent platform: sandbox boundaries, scoped credentials, provenance trails on agent-shipped changes, and secure-by-default code-generation patterns.
- Lead the security craft inside engineering:
You will pair with platform and product engineers on the work where threat models matter. You raise the bar through the tooling and patterns you ship, not through review gates. Compliance (SOC 2 today, more as we scale) falls out as evidence of real security work, not as a separate workstream.
Requirements include:
- Several years writing production software on AWS.
- Security as your specialism, with a track record of defence systems you've shipped: detections that fired on real attacks, supply-chain or build-pipeline hardening, hardened product surfaces, and IR automation that contained an incident.
- Hands-on experience using AI coding agents (Claude Code, Cursor, Codex, or similar) in production development workflows.
- Supply-chain security: Cloud-native attack patterns on AWS, IAM privilege analysis, IMDS exploitation, cross-account paths, KMS misuse, and the defences for each.
- Authoring MCP servers or custom agent tools with a security lens.
- Scoping red-team and pentest engagements (you commission and consume offensive testing, you don't run it day-to-day).
We are a communications compliance surveillance and supervision platform, processing hundreds of millions of events a month for firms worldwide, scaling fast. Security Engineering, like Product Engineering, is a first-class software engineering discipline here, not an audit function bolted onto one. We protect the regulated record for thousands of financial firms.
Our Tech Stack includes:
- Go, TypeScript, Python
- Frontend: React, TypeScript
- Cloud: AWS (Lambda, EC2, ECS Fargate, Aurora PostgreSQL/MySQL, S3, SQS/SNS), Vercel AI
- Infrastructure: AWS Bedrock, Langfuse, Vercel AI Gateway
- Infrastructure: Terraform, GitHub Actions
- Data: Large-scale PostgreSQL, ClickHouse, Turbopuffer
Cyber Security/ Product Security Engineer employer: MirrorWeb
At MirrorWeb, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. As a Cyber Security/Product Security Engineer, you'll have the opportunity to work on cutting-edge technology in a fast-paced environment, with ample opportunities for professional growth and development. Our commitment to security engineering as a core discipline ensures that your contributions will have a meaningful impact on the safety of communications for thousands of financial firms worldwide.