At a Glance
- Tasks: Lead security for our innovative Greenfield Product, ensuring enterprise readiness and compliance.
- Company: Join Orbital Copilot, a pioneering AI firm transforming real estate transactions.
- Benefits: Competitive pay, flexible work environment, and opportunities for professional growth.
- Other info: Diverse and inclusive workplace welcoming all applicants, especially those underrepresented in tech.
- Why this job: Make a real impact in a fast-paced, collaborative team focused on cutting-edge technology.
- Qualifications: Hands-on security engineering experience, strong AWS knowledge, and application security skills required.
The predicted salary is between 60000 - 80000 £ per year.
We’re on a mission to make real estate transactions smarter, faster, and friction-free. Real estate is the world’s largest asset class, yet the legal processes and tools behind it remain slow, manual, and underinvested. Lawyers must review dense documents line by line and piece together information across silos, all while clients demand faster, more transparent due diligence. That's where we come in. Orbital Copilot is the AI assistant built exclusively for commercial real estate law. Developed with former practicing real estate lawyers, it accelerates complex due diligence by up to 70% while delivering legal-grade precision. We’ve just raised a $60m Series B to accelerate our UK/US expansion. We're trusted by leading firms like Goodwin and BCLP to remove the busywork so legal teams can focus on what they do best: applying sharp legal judgment, delivering standout client service, and getting deals over the line faster.
Working at Orbital means joining a team that's reimagining how real estate transactions get done - moving fast, working collaboratively, and giving people the ownership to make a real impact from day one.
The role
We are looking for a Security Engineer (Contract) to be the internal security lead on our Greenfield Product. You will have full access to source code, cloud infrastructure, and configurations, everything an external pen tester cannot see. Your job is to ensure the product is enterprise-ready before a customer goes anywhere near it. You will work alongside the Greenfield Product hardening squad: head of engineering, platform engineers, a developer, and a QA engineer. You will also act as day-to-day counterpart to our external security and pen test partners. This is a hands-on engineering role, not an advisory one. You will be building and implementing controls, not writing recommendations for someone else to action.
What this role is not
- We are not looking for a consultant who produces reports and hands them to an engineering team.
- We are not looking for someone whose SOC 2 experience is limited to policy writing or questionnaire completion.
- And we are not looking for someone who needs close direction or a large security team around them to operate.
The right person has done this before, moves quickly, and can own the security posture of a greenfield AWS product independently.
What you will own
- AWS security posture from the ground up: account structure, IAM, RBAC, logging, and monitoring within the AWS Well-Architected Framework.
- SOC 2 Type II controls and evidence for the Greenfield Product on AWS, ensuring the new platform meets the same compliance bar as our existing certified platform.
- Application-level hardening: authentication (JumpCloud SSO/OIDC), API rate limiting, web security headers, CSRF, CORS, and file-upload validation.
- AI and agentic security: hardening a sandboxed agent environment including shell execution controls, SSRF/DNS rebinding prevention, prompt injection defences, and tool-use guardrails.
- Penetration test management: working alongside our external pen test firm, triaging findings, and closing them rapidly.
- Continuous security validation: putting automated processes in place so that security posture does not erode after this engagement ends.
- Data residency: ensuring US and UK data residency requirements are met from the start given our law firm customer base.
- Vendor security due diligence: assessing third-party integrations including LLM API providers (OpenAI, Anthropic via AWS Bedrock).
- Security status reporting: concise updates to Graham and wider leadership.
You should apply if
- You have deep, hands-on security engineering experience: you build and implement controls, you do not just advise.
- You have strong AWS security knowledge: IAM, account structure, Well-Architected Framework, CloudTrail, GuardDuty, Config, and Security Hub.
- You have driven a real SOC 2 Type II engagement: controls, evidence collection, and audit preparation, not just policy documentation.
- You have application security experience: auth, RBAC, common web vulnerabilities, and the ability to implement fixes directly in code and config.
- You have managed external pen test engagements: scoping, triaging findings, and closing them.
- You are comfortable working at pace with minimal hand-holding in a small, senior team.
- You are available immediately or within days, not weeks.
It would also be great if you have
- AI and LLM security experience: agentic systems, prompt injection, SSRF in agent fetch tools, sandbox escaping, and tool-use threat modelling.
- Experience with high-bar compliance frameworks (FedRAMP, NIST): SOC 2 will feel straightforward if you have done these.
- Multi-tenant SaaS security experience.
- Data residency and multi-region architecture experience across UK and US.
- Experience securing LLM API integrations (OpenAI, Anthropic, AWS Bedrock).
- ISO 27001 familiarity: we are already certified.
Security is everyone’s responsibility at Orbital. We ask all team members to follow our security policies, complete regular awareness training, and handle sensitive data with care in line with ISO 27001 standards. Spot something unusual? Reporting risks or incidents quickly helps us maintain the strong culture of security and compliance we all depend on.
At Orbital, we’re committed to building a diverse and inclusive team. We especially welcome applications from people who are traditionally underrepresented in tech. Even if you don’t meet every single requirement, or if the right role isn’t listed yet, we’d still love to hear from you.
This hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on several factors, which may include job-related knowledge, skills, experience, and business requirements.
AI Security Engineer in London employer: Orbital
At Orbital, we pride ourselves on fostering a dynamic and inclusive work culture that empowers our employees to make a tangible impact from day one. As an AI Security Engineer, you will be at the forefront of innovation in commercial real estate law, working collaboratively with a talented team while enjoying opportunities for professional growth and development. With competitive compensation and a commitment to diversity, Orbital is an exceptional employer for those looking to advance their careers in a fast-paced, meaningful environment.
StudySmarter Expert Advice🤫
We think this is how you could land AI Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects and contributions. This is especially important for a hands-on role like Security Engineer, where practical experience speaks volumes.
✨Tip Number 3
Prepare for interviews by practising common technical questions and scenarios related to AWS security and SOC 2 compliance. We want to see how you think on your feet, so be ready to demonstrate your problem-solving skills!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our mission at Orbital.
We think you need these skills to ace AI Security Engineer in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the AI Security Engineer role. Highlight your hands-on experience with AWS security and SOC 2 engagements, as we want to see how you can directly contribute to our mission.
Show Off Your Skills:Don’t just list your skills; demonstrate them! Use specific examples from your past work that showcase your ability to build and implement security controls. We love seeing real-world applications of your expertise.
Be Concise and Clear:Keep your application straightforward and to the point. We appreciate clarity, so avoid jargon and focus on what makes you a great fit for our team. Remember, we’re looking for someone who can communicate effectively!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at Orbital
✨Know Your AWS Security Inside Out
Make sure you brush up on your AWS security knowledge, especially around IAM, account structure, and the Well-Architected Framework. Be ready to discuss how you've implemented these in past roles, as this will show you're not just familiar with the concepts but have hands-on experience.
✨Demonstrate Your Hands-On Experience
This role is all about building and implementing controls, so be prepared to share specific examples of how you've done this before. Talk about the challenges you faced and how you overcame them, as this will highlight your problem-solving skills and ability to work independently.
✨Familiarise Yourself with SOC 2 Type II
Since the role involves driving a SOC 2 Type II engagement, make sure you understand the controls and evidence collection process. Be ready to explain how you've managed similar engagements in the past, focusing on your direct involvement rather than just advisory roles.
✨Prepare for Technical Questions
Expect technical questions related to application security, such as authentication methods and common web vulnerabilities. Brush up on your knowledge of CSRF, CORS, and file-upload validation, and be ready to discuss how you've implemented fixes directly in code and configuration.