AI Security Engineer in London

AI Security Engineer in London

London Full-Time 60000 - 80000 £ / year (est.) No working from home possible
Orbital Witness Limited

At a Glance

  • Tasks: Lead security for our innovative Greenfield Product, ensuring enterprise readiness and robust protection.
  • Company: Join Orbital Copilot, a trailblazer in AI for commercial real estate law.
  • Benefits: Competitive pay, flexible work environment, and the chance to make a real impact.
  • Other info: Diverse and inclusive team culture, welcoming all backgrounds.
  • Why this job: Be at the forefront of transforming real estate transactions with cutting-edge technology.
  • Qualifications: Hands-on security engineering experience and strong AWS knowledge required.

The predicted salary is between 60000 - 80000 £ per year.

We’re on a mission to make real estate transactions smarter, faster, and friction-free. Real estate is the world’s largest asset class, yet the legal processes and tools behind it remain slow, manual, and underinvested. Lawyers must review dense documents line by line and piece together information across silos, all while clients demand faster, more transparent due diligence. That’s where we come in. Orbital Copilot is the AI assistant built exclusively for commercial real estate law. Developed with former practicing real estate lawyers, it accelerates complex due diligence by up to 70% while delivering legal-grade precision.

We’ve just raised a $60m Series B to accelerate our UK/US expansion. We’re trusted by leading firms like Goodwin and BCLP to remove the busywork so legal teams can focus on what they do best: applying sharp legal judgment, delivering standout client service, and getting deals over the line faster. Working at Orbital means joining a team that’s reimagining how real estate transactions get done – moving fast, working collaboratively, and giving people the ownership to make a real impact from day one.

The role

We are looking for a Security Engineer (Contract) to be the internal security lead on our Greenfield Product. You will have full access to source code, cloud infrastructure, and configurations, everything an external pen tester cannot see. Your job is to ensure the product is enterprise-ready before a customer goes anywhere near it. You will work alongside the Greenfield Product hardening squad: head of engineering, platform engineers, a developer, and a QA engineer. You will also act as day‑to‑day counterpart to our external security and pen test partners. This is a hands‑on engineering role, not an advisory one. You will be building and implementing controls, not writing recommendations for someone else to action.

What this role is not

We are not looking for a consultant who produces reports and hands them to an engineering team. We are not looking for someone whose SOC 2 experience is limited to policy writing or questionnaire completion. And we are not looking for someone who needs close direction or a large security team around them to operate. The right person has done this before, moves quickly, and can own the security posture of a greenfield AWS product independently.

What you will own

  • AWS security posture from the ground up: account structure, IAM, RBAC, logging, and monitoring within the AWS Well-Architected Framework.
  • SOC 2 Type II controls and evidence for the Greenfield Product on AWS, ensuring the new platform meets the same compliance bar as our existing certified platform.
  • Application-level hardening: authentication (JumpCloud SSO/OIDC), API rate limiting, web security headers, CSRF, CORS, and file-upload validation.
  • AI and agentic security: hardening a sandboxed agent environment including shell execution controls, SSRF/DNS rebinding prevention, prompt injection defences, and tool‑use guardrails.
  • Penetration test management: working alongside our external pen test firm, triaging findings, and closing them rapidly.
  • Continuous security validation: putting automated processes in place so that security posture does not erode after this engagement ends.
  • Data residency: ensuring US and UK data residency requirements are met from the start given our law firm customer base.
  • Vendor security due diligence: assessing third‑party integrations including LLM API providers (OpenAI, Anthropic via AWS Bedrock).
  • Security status reporting: concise updates to Graham and wider leadership.

You should apply if

  • You have deep, hands‑on security engineering experience: you build and implement controls, you do not just advise.
  • You have strong AWS security knowledge: IAM, account structure, Well-Architected Framework, CloudTrail, GuardDuty, Config, and Security Hub.
  • You have driven a real SOC 2 Type II engagement: controls, evidence collection, and audit preparation, not just policy documentation.
  • You have application security experience: auth, RBAC, common web vulnerabilities, and the ability to implement fixes directly in code and config.
  • You have managed external pen test engagements: scoping, triaging findings, and closing them.
  • You are comfortable working at pace with minimal hand‑holding in a small, senior team.
  • You are available immediately or within days, not weeks.

It would also be great if you have

  • AI and LLM security experience: agentic systems, prompt injection, SSRF in agent fetch tools, sandbox escaping, and tool‑use threat modelling.
  • Experience with high‑bar compliance frameworks (FedRAMP, NIST): SOC 2 will feel straightforward if you have done these.
  • Multi‑tenant SaaS security experience.
  • Data residency and multi‑region architecture experience across UK and US.
  • Experience securing LLM API integrations (OpenAI, Anthropic, AWS Bedrock).
  • ISO 27001 familiarity: we are already certified.

Security is everyone’s responsibility at Orbital. We ask all team members to follow our security policies, complete regular awareness training, and handle sensitive data with care in line with ISO 27001 standards. Spot something unusual? Reporting risks or incidents quickly helps us maintain the strong culture of security and compliance we all depend on.

At Orbital, we’re committed to building a diverse and inclusive team. We especially welcome applications from people who are traditionally underrepresented in tech. Even if you don’t meet every single requirement, or if the right role isn’t listed yet, we’d still love to hear from you.

AI Security Engineer in London employer: Orbital Witness Limited

At Orbital, we pride ourselves on being an innovative employer that empowers our team members to make a significant impact from day one. Our collaborative work culture fosters creativity and ownership, while our commitment to employee growth is evident through hands-on roles like the AI Security Engineer position, where you will directly shape the security posture of our cutting-edge Greenfield Product. With competitive benefits and a focus on diversity and inclusion, Orbital is an excellent place for those looking to advance their careers in a fast-paced, supportive environment.

Orbital Witness Limited

Contact Details:

Orbital Witness Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land AI Security Engineer in London

Tip Number 1

Network like a pro! Reach out to people in the industry, attend meetups, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects and contributions. This is especially important for a hands-on role like Security Engineer, where demonstrating your technical prowess can set you apart from the crowd.

Tip Number 3

Prepare for interviews by brushing up on common security scenarios and AWS best practices. Be ready to discuss how you've tackled challenges in the past and how you can bring that experience to our Greenfield Product.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our mission to revolutionise real estate transactions.

We think you need these skills to ace AI Security Engineer in London

AWS Security Knowledge
IAM
Account Structure
Well-Architected Framework
SOC 2 Type II Engagement
Application Security
RBAC

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the AI Security Engineer role. Highlight your hands-on security engineering experience and AWS knowledge, as these are key for us. Use specific examples that showcase your skills in building and implementing controls.

Craft a Compelling Cover Letter:Your cover letter should tell us why you're excited about joining Orbital and how you can contribute to our mission. Mention your experience with SOC 2 Type II engagements and application security, and don’t forget to show a bit of personality!

Showcase Relevant Projects:If you've worked on any relevant projects, especially those involving AWS security or penetration testing, make sure to include them. We love seeing real-world applications of your skills, so don’t hold back on the details!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows us you’re keen to join our team!

How to prepare for a job interview at Orbital Witness Limited

Know Your AWS Security Inside Out

Make sure you brush up on your AWS security knowledge, especially around IAM, account structure, and the Well-Architected Framework. Be ready to discuss how you've implemented these controls in past roles, as this will show you can hit the ground running.

Demonstrate Hands-On Experience

This role is all about doing, not advising. Prepare examples of how you've built and implemented security controls directly. Share specific instances where you've managed external pen tests and triaged findings, as this will highlight your practical experience.

Showcase Your Application Security Skills

Be ready to talk about your experience with application-level hardening. Discuss authentication methods, common web vulnerabilities, and how you've implemented fixes directly in code. This will demonstrate that you can tackle security challenges head-on.

Emphasise Your Ability to Work Independently

The team is looking for someone who can operate with minimal direction. Prepare to share examples of how you've successfully worked in fast-paced environments and taken ownership of security postures in previous roles. This will reassure them that you're the right fit for their dynamic team.