At a Glance
- Tasks: Embed security into software development and enhance DevSecOps practices.
- Company: Fast-growing fintech company focused on secure, cloud-native platforms.
- Benefits: Competitive salary, remote work, and a chance to shape security in tech.
- Other info: Collaborate globally in a hybrid model with excellent career growth.
- Why this job: Join a dynamic team where security is integral to engineering and innovation.
- Qualifications: Experience in application security and familiarity with AWS and Python.
The predicted salary is between 120000 - 150000 £ per year.
We’re partnering with a fast-growing financial technology business building secure, cloud-native platforms in the digital asset space. The organisation operates globally and develops high-value systems where security, reliability, and engineering quality are critical. They’re now hiring a Senior Product Security Engineer to embed security deeper into their software development lifecycle.
This is not a pure penetration testing role. It’s for someone who enjoys working directly with engineers, improving secure design, and building scalable DevSecOps guardrails.
What You’ll Be Doing
- Embedding security into the SDLC and CI/CD pipelines
- Implementing and tuning SAST, SCA, and DAST tooling
- Performing code-level security reviews (Python-heavy backend environment)
- Leading threat modelling and secure design discussions
- Strengthening AWS cloud security controls
- Partnering with engineering teams to triage and remediate vulnerabilities
- Improving automation and reducing security bottlenecks across product teams
- Collaborating with an international security team in a hybrid working model
What We’re Looking For
- Strong experience in application / product security engineering
- Hands-on delivery of Secure SDLC and DevSecOps practices
- Experience embedding SAST / SCA / DAST into GitHub or GitLab pipelines
- Solid understanding of AWS cloud security
- Comfortable reviewing and writing Python
- Experience in fintech, regulated environments, or digital platforms preferred
- Engineering mindset — enabling teams rather than blocking them
This is an opportunity to join a technically strong team where security is treated as part of engineering, not an afterthought. If you’re interested in building secure systems in a modern financial technology environment, feel free to reach out.
Senior Product Security Engineer in Derby employer: TechShack
Contact Detail:
TechShack Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Product Security Engineer in Derby
✨Tip Number 1
Network like a pro! Reach out to folks in the fintech space, especially those working on security. LinkedIn is your best mate here; drop them a message and ask about their experiences or any tips they might have.
✨Tip Number 2
Show off your skills! If you’ve got a GitHub or GitLab profile, make sure it’s up to date with your projects. Highlight any work related to SAST, DAST, or secure coding practices. This is your chance to demonstrate your hands-on experience!
✨Tip Number 3
Prepare for those interviews! Brush up on your knowledge of AWS cloud security and be ready to discuss how you’ve embedded security into SDLCs before. They’ll want to see that engineering mindset, so think about how you can enable teams rather than block them.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step to connect directly with us.
We think you need these skills to ace Senior Product Security Engineer in Derby
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the Senior Product Security Engineer role. Highlight your experience in application security, DevSecOps practices, and any relevant projects you've worked on.
Craft a Compelling Cover Letter: Use your cover letter to tell us why you're passionate about security in fintech. Share specific examples of how you've embedded security into the SDLC and collaborated with engineering teams to improve secure design.
Showcase Your Technical Skills: Don’t forget to mention your hands-on experience with SAST, SCA, and DAST tools, especially in a Python-heavy environment. We want to see how you’ve applied these skills in real-world scenarios.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity in our growing team!
How to prepare for a job interview at TechShack
✨Know Your Stuff
Make sure you brush up on your application and product security engineering knowledge. Familiarise yourself with Secure SDLC and DevSecOps practices, especially how to embed SAST, SCA, and DAST into GitHub or GitLab pipelines. Being able to discuss these topics confidently will show that you're the right fit for the role.
✨Showcase Your Collaboration Skills
Since this role involves working closely with engineering teams, be prepared to share examples of how you've partnered with others in the past. Highlight any experiences where you triaged vulnerabilities or improved security processes without being a bottleneck. This will demonstrate your engineering mindset and ability to enable teams.
✨Get Hands-On with Python
As the role requires reviewing and writing Python code, make sure you can talk about your experience with it. Bring along examples of code-level security reviews you've conducted or any projects where you've implemented secure design principles. This will help you stand out as a candidate who can hit the ground running.
✨Understand AWS Security Controls
Since strengthening AWS cloud security controls is part of the job, ensure you have a solid understanding of AWS security best practices. Be ready to discuss specific tools or strategies you've used in the past to enhance cloud security. This will show that you’re not just familiar with the concepts but have practical experience applying them.