At a Glance
- Tasks: Design and implement secure development practices in a cutting-edge tech environment.
- Company: PhysicsX, a deep-tech company revolutionising hardware innovation with AI-driven solutions.
- Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
- Why this job: Shape the future of security in a high-impact role while collaborating with innovative teams.
- Qualifications: 10+ years in security, expertise in DevSecOps, and hands-on coding experience.
- Other info: Diverse workplace committed to equal opportunity and supporting underrepresented groups in tech.
The predicted salary is between 72000 - 108000 £ per year.
PhysicsX is a deep-tech company with roots in numerical physics and Formula One, dedicated to accelerating hardware innovation at the speed of software. We are building an AI-driven simulation software stack for engineering and manufacturing across advanced industries. By enabling high-fidelity, multi-physics simulation through AI inference across the entire engineering lifecycle, PhysicsX unlocks new levels of optimization and automation in design, manufacturing, and operations — empowering engineers to push the boundaries of possibility. Our customers include leading innovators in Aerospace & Defense, Materials, Energy, Semiconductors, and Automotive.
As a Principal Security Engineer, you will partner closely with engineering teams to design and implement secure development practices, integrate security into our CI/CD pipeline, and lead security and design reviews. You’ll bring deep expertise in DevSecOps, application security, hands-on experience securing web applications and APIs, and a strong understanding of modern development workflows. This is a unique opportunity to shape the future of our security program while working in a high-ownership, high-impact environment.
What you will do:
- Architect and integrate security tooling directly into CI/CD pipelines to automate the detection and prevention of vulnerabilities, ensuring "shift-left" security at scale.
- Lead threat modeling and secure design reviews for web applications, APIs, and cloud services.
- Oversee the end-to-end product vulnerability lifecycle, from issue triage, prioritization, remediation support, with clear risk communication.
- Drive secure coding standards, develop playbooks, and provide hands-on training and mentorship to instill a security-first mindset across the organization.
- Design and scale secure development practices by collaborating cross-functionally with engineering teams throughout the entire software lifecycle.
- Engage with customers during security reviews.
What you bring to the table:
- 10+ years in security, with a focus on DevSecOps and security design reviews.
- Hands-on experience with secure coding, OWASP Top 10, threat modeling, and SDLC integration.
- Experience with GitHub/GitLab, CI/CD, IaC, and containerized environments.
- Experience deploying and working with SAST tooling (e.g. Semgrep, Snyk).
- Experience developing in Python and Go.
- Track record of balancing pragmatism and security rigor in a fast-paced setting.
Nice to Have Skills:
- Understanding of AI security fundamentals and how application security and AI security intersect.
- Experience securing cloud infrastructure.
- Participation in bug bounty programs and managing security disclosure.
- Familiarity with the BSIMM framework.
- Experience in cloud security including identity and access management and cloud-native services.
We value diversity and are committed to equal employment opportunity regardless of sex, race, religion, ethnicity, nationality, disability, age, sexual orientation or gender identity. We strongly encourage individuals from groups traditionally underrepresented in tech to apply. To help make a change, we sponsor bright women from disadvantaged backgrounds through their university degrees in science and mathematics.
We collect diversity and inclusion data solely for the purpose of monitoring the effectiveness of our equal opportunities policies and ensuring compliance with UK employment and equality legislation. This information is confidential, used only in aggregate form, and will not influence the outcome of your application.
Principal Security Engineer – DevSecOps and Security Architect London employer: PhysicsX Ltd
Contact Detail:
PhysicsX Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Principal Security Engineer – DevSecOps and Security Architect London
✨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at events. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repo showcasing your projects, especially those related to DevSecOps and security. This gives potential employers a taste of what you can do.
✨Tip Number 3
Prepare for interviews by practising common security scenarios and questions. We recommend doing mock interviews with friends or using online platforms to get comfortable.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love hearing from passionate candidates like you!
We think you need these skills to ace Principal Security Engineer – DevSecOps and Security Architect London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the Principal Security Engineer role. Highlight your DevSecOps expertise and any hands-on experience you've had with secure coding and CI/CD pipelines.
Craft a Compelling Cover Letter: Use your cover letter to tell us why you're passionate about security and how your background makes you a great fit for our team. Be sure to mention specific projects or achievements that showcase your skills in application security.
Showcase Your Technical Skills: Don’t shy away from listing your technical proficiencies, especially with tools like GitHub/GitLab, SAST tooling, and programming languages like Python and Go. We want to see how you can contribute to our security practices!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows us you’re keen on joining our team!
How to prepare for a job interview at PhysicsX Ltd
✨Know Your Stuff
Make sure you brush up on your knowledge of DevSecOps, secure coding practices, and the OWASP Top 10. PhysicsX is looking for someone with deep expertise, so be ready to discuss your hands-on experience and how you've integrated security into CI/CD pipelines.
✨Showcase Your Problem-Solving Skills
Prepare to talk about specific challenges you've faced in securing web applications and APIs. Think of examples where you led threat modelling or security design reviews, and be ready to explain your thought process and the outcomes.
✨Demonstrate Collaboration
Since this role involves working closely with engineering teams, be prepared to discuss how you've collaborated cross-functionally in the past. Share examples of how you’ve instilled a security-first mindset and driven secure development practices across teams.
✨Engage with Their Mission
Familiarise yourself with PhysicsX's mission and their focus on AI-driven simulation software. Be ready to discuss how your skills can contribute to their goals and how you can help push the boundaries of possibility in security.