Security Engineer in London

Security Engineer in London

London Freelance 60000 - 80000 £ / year (est.) Home office (partial)
Orbital

At a Glance

  • Tasks: Lead security for our innovative Greenfield Product, ensuring enterprise readiness and compliance.
  • Company: Join Orbital Copilot, revolutionising real estate transactions with AI technology.
  • Benefits: Competitive pay, flexible work environment, and a chance to make a real impact.
  • Other info: Diverse and inclusive workplace welcoming all backgrounds.
  • Why this job: Be part of a fast-paced team transforming the legal landscape in real estate.
  • Qualifications: Hands-on security engineering experience and strong AWS knowledge required.

The predicted salary is between 60000 - 80000 £ per year.

We’re on a mission to make real estate transactions smarter, faster, and friction-free. Real estate is the world’s largest asset class, yet the legal processes and tools behind it remain slow, manual, and underinvested. Lawyers must review dense documents line by line and piece together information across silos, all while clients demand faster, more transparent due diligence. That's where we come in. Orbital Copilot is the AI assistant built exclusively for commercial real estate law. Developed with former practicing real estate lawyers, it accelerates complex due diligence by up to 70% while delivering legal-grade precision. We’ve just raised a $60m Series B to accelerate our UK/US expansion. We're trusted by leading firms like Goodwin and BCLP to remove the busywork so legal teams can focus on what they do best: applying sharp legal judgment, delivering standout client service, and getting deals over the line faster.

Working at Orbital means joining a team that's reimagining how real estate transactions get done - moving fast, working collaboratively, and giving people the ownership to make a real impact from day one.

The role

We are looking for a Security Engineer (Contract) to be the internal security lead on our Greenfield Product. You will have full access to source code, cloud infrastructure, and configurations, everything an external pen tester cannot see. Your job is to ensure the product is enterprise-ready before a customer goes anywhere near it. You will work alongside the Greenfield Product hardening squad: head of engineering, platform engineers, a developer, and a QA engineer. You will also act as day-to-day counterpart to our external security and pen test partners. This is a hands-on engineering role, not an advisory one. You will be building and implementing controls, not writing recommendations for someone else to action.

What this role is not

  • We are not looking for a consultant who produces reports and hands them to an engineering team.
  • We are not looking for someone whose SOC 2 experience is limited to policy writing or questionnaire completion.
  • And we are not looking for someone who needs close direction or a large security team around them to operate.

The right person has done this before, moves quickly, and can own the security posture of a greenfield AWS product independently.

What you will own

  • AWS security posture from the ground up: account structure, IAM, RBAC, logging, and monitoring within the AWS Well-Architected Framework.
  • SOC 2 Type II controls and evidence for the Greenfield Product on AWS, ensuring the new platform meets the same compliance bar as our existing certified platform.
  • Application-level hardening: authentication (JumpCloud SSO/OIDC), API rate limiting, web security headers, CSRF, CORS, and file-upload validation.
  • AI and agentic security: hardening a sandboxed agent environment including shell execution controls, SSRF/DNS rebinding prevention, prompt injection defences, and tool-use guardrails.
  • Penetration test management: working alongside our external pen test firm, triaging findings, and closing them rapidly.
  • Continuous security validation: putting automated processes in place so that security posture does not erode after this engagement ends.
  • Data residency: ensuring US and UK data residency requirements are met from the start given our law firm customer base.
  • Vendor security due diligence: assessing third-party integrations including LLM API providers (OpenAI, Anthropic via AWS Bedrock).
  • Security status reporting: concise updates to Graham and wider leadership.

You should apply if

  • You have deep, hands-on security engineering experience: you build and implement controls, you do not just advise.
  • You have strong AWS security knowledge: IAM, account structure, Well-Architected Framework, CloudTrail, GuardDuty, Config, and Security Hub.
  • You have driven a real SOC 2 Type II engagement: controls, evidence collection, and audit preparation, not just policy documentation.
  • You have application security experience: auth, RBAC, common web vulnerabilities, and the ability to implement fixes directly in code and config.
  • You have managed external pen test engagements: scoping, triaging findings, and closing them.
  • You are comfortable working at pace with minimal hand-holding in a small, senior team.
  • You are available immediately or within days, not weeks.

It would also be great if you have

  • AI and LLM security experience: agentic systems, prompt injection, SSRF in agent fetch tools, sandbox escaping, and tool-use threat modelling.
  • Experience with high-bar compliance frameworks (FedRAMP, NIST): SOC 2 will feel straightforward if you have done these.
  • Multi-tenant SaaS security experience.
  • Data residency and multi-region architecture experience across UK and US.
  • Experience securing LLM API integrations (OpenAI, Anthropic, AWS Bedrock).
  • ISO 27001 familiarity: we are already certified.

Security is everyone’s responsibility at Orbital. We ask all team members to follow our security policies, complete regular awareness training, and handle sensitive data with care in line with ISO 27001 standards. Spot something unusual? Reporting risks or incidents quickly helps us maintain the strong culture of security and compliance we all depend on.

At Orbital, we’re committed to building a diverse and inclusive team. We especially welcome applications from people who are traditionally underrepresented in tech. Even if you don’t meet every single requirement, or if the right role isn’t listed yet, we’d still love to hear from you.

This hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on several factors, which may include job-related knowledge, skills, experience, and business requirements.

Security Engineer in London employer: Orbital

At Orbital, we pride ourselves on being an innovative employer that empowers our team members to make a significant impact from day one. Our collaborative work culture fosters creativity and ownership, while our commitment to employee growth is evident through hands-on roles like the Security Engineer position, where you will directly shape the security posture of our cutting-edge Greenfield Product. With competitive compensation and a focus on diversity and inclusion, Orbital is an excellent place for those looking to thrive in a fast-paced, meaningful environment.

Orbital

Contact Details:

Orbital Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer in London

Get Active on Cybersecurity Forums

Join platforms like Stack Exchange and Reddit’s r/cybersecurity to hang out with industry pros, learn the latest, and share your insights. This will not only boost your visibility but also help you connect with potential clients who might need your freelance services.

Show Off Your Skills with Public Projects

Create a few open-source projects or contribute to existing ones that showcase your cybersecurity skills. Use GitHub to display your work, as this is an excellent way to attract clients looking for freelancers with a proven track record.

Attend Local Conferences and Meetups

Make sure to hit up cybersecurity meetups, workshops, and conferences in your area. These events are goldmines for networking, and you’ll often find people looking for freelancers after a chat over a coffee – so come prepared with your business cards and a killer elevator pitch!

Market Yourself Smartly

Set up a professional website that showcases your portfolio, expertise, and client testimonials. Optimise it for SEO with relevant keywords so potential clients searching for cybersecurity freelancers can easily find you. Don’t forget to link to your site on all your social media and profiles!

We think you need these skills to ace Security Engineer in London

AWS Security Knowledge
IAM
Account Structure
Well-Architected Framework
SOC 2 Type II Engagement
Application Security
RBAC

Some tips for your application 🫡

Show Your Skills Through a Strong Portfolio:Since you're applying for a freelance role in cybersecurity, it's crucial to showcase your technical skills through a detailed portfolio. Include case studies of projects you've worked on, any security tools you've developed or assessed, and specifics on the methodologies you’ve used. This will help Orbital understand what you're capable of.

Certifications Matter!:Make sure to list any relevant certifications you hold, such as CISSP, CEH, or CompTIA Security+. Freelance clients often value these credentials as they reflect your expertise and commitment to the field. If you’re actively pursuing more certifications, don’t hesitate to mention that too!

Rates, Availability, and Your Work Style:In your application, it’s essential to be clear about your freelance rates and availability. Clients appreciate transparency. Mention how many hours a week you can dedicate and your preferred working hours, as this sets expectations from the start and shows you're organised and professional.

Tailor Your CV to Highlight Cybersecurity Experience:When crafting your CV, make sure to tailor it specifically to cybersecurity. Highlight projects, tasks, and achievements related to security assessments, vulnerabilities you've mitigated, or compliance work you've undertaken. Keywords relevant to the job can grab attention and increase your chances of landing a spot at Orbital.

How to prepare for a job interview at Orbital

Showcase Your Cybersecurity Skills

As a freelancer in cybersecurity, it’s crucial we demonstrate not just our knowledge but our practical skills too. Be ready to discuss specific tools you’ve used, like Wireshark or Metasploit, and share relevant experiences where you identified vulnerabilities or mitigated risks in past projects.

Prepare Your Portfolio

Unlike traditional roles, freelancing relies heavily on your portfolio. Let’s curate a selection of past work that showcases our best projects. If we’ve handled penetration tests, audits, or incident responses, be sure to highlight these in your portfolio, and share any client testimonials if we have them.

Stay Updated on Trends and Tools

Cybersecurity is an ever-evolving field, so we should be prepared to chat about recent developments and how they impact our work. Familiarise ourselves with the latest threats, tools, and frameworks, like MITRE ATT&CK, that are pertinent to the projects we’re pitching.

Pitching Your Value as a Freelancer

When freelancing, we often need to negotiate our rates and value propositions. Be ready to explain how our skills can help Orbital protect their assets and manage risks. It can help to outline some potential strategies or improvements we could implement for them based on their current setup.