Product Security Engineer in Cambridge

Product Security Engineer in Cambridge

Cambridge Full-Time 60000 - 75000 € / year (est.) Home office (partial)
Redgate

At a Glance

  • Tasks: Embed security into software development and help teams build secure applications.
  • Company: Join a forward-thinking tech company focused on product security.
  • Benefits: Competitive salary, flexible hybrid working, and opportunities for professional growth.
  • Other info: Dynamic work environment with excellent career advancement opportunities.
  • Why this job: Make a real impact on software security while collaborating with innovative teams.
  • Qualifications: Experience in application security and knowledge of SAST/DAST processes.

The predicted salary is between 60000 - 75000 € per year.

The Role

As a Product Security Engineer, you’ll embed security into the software development lifecycle across multiple product teams. You’ll help teams build, ship, and operate secure software by defining requirements, improving detection and prevention (SAST/DAST), assisting teams with application security governance, and running threat modelling.

Your Work at Redgate

  • Partner with engineering and product teams to define and operationalise security requirements across the SDLC (from design to release).
  • Audit application code for weaknesses and vulnerabilities.
  • Own or co-own application security governance practices: secure-by-default standards, patterns, guardrails, and exceptions/risk acceptance.
  • Drive SAST/DAST adoption and quality: tool tuning, triage workflows, severity calibration, and “fix-forward” enablement.
  • Support adoption of threat modelling for new features, architectural changes, and high-risk services—turning findings into actionable engineering work.
  • Provide product security guidance for cloud-native environments (AWS + containerised workloads), with an emphasis on secure service design and deployment practices.
  • Build strong relationships with product teams through clear communication, coaching, and security enablement.
  • Review and assist in the development of engineering policies aligned with security best practices.
  • Contribute secure shared libraries/paved-road components or perform targeted security testing/pentesting to validate controls.
  • Work with product teams to support implementation of AI, including LLMs, SLMs, and MCP.

What you bring to the table

  • Hands-on product/application security experience supporting engineering teams in a modern SDLC (requirements, design review, secure coding guidance, release support).
  • Strong knowledge of the OWASP Top 10 and practical mitigation patterns; familiarity with OWASP ASVS is a plus.
  • Experience implementing or improving SAST/DAST processes: tool selection/tuning, signal-to-noise reduction, and scalable remediation workflows.
  • Working understanding of cloud and container security fundamentals in an environment using AWS and Docker (and related CI/CD practices).
  • Comfort working across a primarily C# ecosystem (with some Java/Python), including the ability to review code and explain security issues clearly to developers.
  • Ability to translate security risk into actionable engineering priorities—balancing risk, delivery timelines, and operational realities.

Who you are

  • You’re pragmatic: you care about real risk reduction, not checkbox compliance or perfect theoretical security.
  • You communicate clearly and respectfully, able to influence without authority and build trust across multiple product teams.
  • You’re structured and evidence-driven: you document decisions, measure outcomes, and iterate based on what’s working.
  • You’re comfortable in ambiguity and can shape an approach when requirements, tooling, or ownership aren’t fully defined yet.

Salary and ways of working

£60,000 to £75,000 subject to experience. Flexible-hybrid working model (1 day every two weeks).

Tech / tool stack

  • C# / .NET (primary engineering ecosystem), React, Java (J2EE), TypeScript, and Python.
  • AWS (cloud infrastructure and services), Docker (containerised workloads).
  • SAST/DAST tooling (specific products may vary; you’ll help tune and operationalise them).

Impact plan

  • 30 Days: Onboard into Redgate’s products, SDLC, and delivery rhythms (how work moves from idea → code → deploy). Get access to core systems and security tooling; understand what’s in place today (SAST/DAST coverage, alert volumes, current processes). Shadow the Product Security Architect and sit in on a handful of ceremonies (planning/refinement/retro) to understand team dynamics and where security naturally fits. Triage a small set of findings with guidance (e.g., top recurring SAST issues), focusing on learning severity expectations and remediation patterns. Start building a knowledge base: common app patterns, approved controls, “how we do security here,” and where to find the right people.
  • 60 Days: Begin owning a defined slice of AppSec work with supervision (e.g., one product area or a specific SDLC initiative like SAST tuning or DAST onboarding). Build working relationships with a small set of partner teams and establish a predictable engagement model (intake path, review checklist). Start contributing to security reviews for new features or higher-risk changes—initially as a second set of eyes, then independently for scoped areas. Help improve signal-to-noise in SAST/DAST: tune rules, reduce duplicates, and document triage guidance that developers can follow. Support lightweight threat modelling sessions alongside the Architect (prep, note-taking, translating outcomes into engineering actions).
  • 90 Days: Independently handle routine AppSec support for agreed scope (e.g., first-pass triage, basic secure design guidance, follow-ups with teams), escalating appropriately. Deliver tangible process improvements that reduce friction (e.g., clearer severity rubric, a repeatable intake template, a “common findings” fix guide). Demonstrate steady throughput on findings: consistent triage quality, meaningful developer support, and reduced turnaround time for the scoped area. Contribute to a secure-by-default library/SDK.

Product Security Engineer in Cambridge employer: Redgate

At Redgate, we pride ourselves on fostering a collaborative and innovative work culture that empowers our employees to thrive. As a Product Security Engineer, you'll benefit from flexible hybrid working arrangements, competitive salaries, and opportunities for professional growth while working with cutting-edge technologies in a supportive environment. Join us to make a meaningful impact on software security and be part of a team that values clear communication, trust, and continuous improvement.

Redgate

Contact Detail:

Redgate Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Product Security Engineer in Cambridge

Tip Number 1

Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who’s already in the role you want. Building relationships can open doors that a CV just can’t.

Tip Number 2

Show off your skills! If you’ve got a portfolio or any projects that highlight your product security expertise, make sure to share them during interviews. Real-world examples of your work can really impress hiring managers.

Tip Number 3

Prepare for those tricky questions! Brush up on common interview questions related to application security, SAST/DAST processes, and cloud security. Practising your responses will help you feel more confident and articulate during the actual interview.

Tip Number 4

Don’t forget to apply through our website! We’re always on the lookout for passionate individuals who want to make a difference in product security. Plus, applying directly can sometimes give you an edge over other candidates.

We think you need these skills to ace Product Security Engineer in Cambridge

Application Security
SAST/DAST Processes
Threat Modelling
Cloud Security
Container Security
C# Programming
Java Programming

Some tips for your application 🫡

Tailor Your CV:Make sure your CV speaks directly to the role of Product Security Engineer. Highlight your hands-on experience with application security, SAST/DAST processes, and any relevant cloud security knowledge. We want to see how your skills align with what we’re looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about security and how you can contribute to our team. Be sure to mention specific experiences that relate to the job description—this will help us see your fit for the role.

Showcase Your Communication Skills:Since this role involves working closely with product teams, it’s important to demonstrate your ability to communicate clearly and effectively. In your application, include examples of how you've influenced others or built trust in previous roles. We love a good communicator!

Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy and ensures your application goes straight to us. Plus, you’ll get to see more about our culture and values while you’re at it!

How to prepare for a job interview at Redgate

Know Your Stuff

Make sure you brush up on your knowledge of the OWASP Top 10 and SAST/DAST processes. Be ready to discuss how you've applied these in past roles, as well as any specific tools you've used. This will show that you’re not just familiar with the concepts but have practical experience too.

Showcase Your Communication Skills

As a Product Security Engineer, you'll need to communicate complex security issues clearly to developers. Prepare examples of how you've successfully influenced teams or built trust in previous roles. This will demonstrate your ability to work collaboratively across product teams.

Be Pragmatic About Security

Highlight your approach to balancing risk reduction with operational realities. Share specific instances where you’ve prioritised actionable engineering tasks over theoretical compliance. This will resonate well with the interviewers who value real-world impact over checkbox compliance.

Prepare for Ambiguity

Expect questions about how you handle situations where requirements or tooling are unclear. Think of examples from your experience where you shaped an approach in ambiguous scenarios. This will showcase your adaptability and problem-solving skills, which are crucial for this role.