At a Glance
- Tasks: Own security architecture and lead technical security initiatives at XYZ Reality.
- Company: Join a pioneering tech company revolutionising construction with Augmented Reality.
- Benefits: Enjoy hybrid working, 25 days leave, private healthcare, and regular salary reviews.
- Other info: Collaborative environment with opportunities for growth and innovation.
- Why this job: Be the first dedicated security expert and shape the future of security in tech.
- Qualifications: Hands-on security experience with cloud, application, and infrastructure security.
The predicted salary is between 75600 - 92400 £ per year.
Build the security foundations behind cutting-edge construction technology At XYZ Reality, we’ve created the world’s first engineering-grade Augmented Reality solution for construction.
Our product, The Atom, is used on major projects worldwide to bring designs to life on-site and help teams build more accurately, efficiently and with fewer mistakes.
As a Series B business scaling across the UK, US and Europe, our technology – and the security environment supporting it – is becoming increasingly sophisticated.
Our stack spans Kubernetes on Azure, mobile and embedded AR, REST APIs, real-time collaboration and AI-powered data pipelines.
We already hold SOC 2 Type II and ISO 27001, but as our product, customers and use of AI continue to evolve, we now need dedicated security expertise within the business.
The Role
We’re looking for an experienced Senior Security & Compliance Engineer to take ownership of security across XYZ Reality and help build a security capability that can scale with us.
This is a critical hire and an opportunity to become our first dedicated security specialist, with genuine ownership and influence across the business.
While we already have established compliance activity and SOC 2 Type II and ISO 27001 certifications, security responsibilities currently sit across different teams.
We’re now looking for someone who can bring that together, identify where we need to strengthen our approach and provide dedicated technical security leadership as we scale.
This is first and foremost a technical security role.
You’ll sit within Engineering and work directly alongside the teams building our technology, participating in architecture discussions, development workflows and technical decision-making rather than operating as a separate security function reviewing work after the fact.
You’ll take ownership of security architecture across our technology stack, embed shift-left security practices into how we build, strengthen our cloud and application security, and ensure we remain ahead of both established and emerging threats.
As our use of AI continues to develop, you’ll also help us understand and respond to new AI-related security risks and attack vectors, ensuring our security approach evolves alongside our technology.
Compliance remains an important part of the role.
You’ll help strengthen our SOC 2 Type II and ISO 27001 posture and support areas including GDPR, data residency and enterprise customer requirements.
However, we’re looking for someone who brings strong hands-on security expertise first, alongside the governance and compliance knowledge needed to operate effectively across both areas.
You won’t simply inherit a security playbook, you’ll have the opportunity to help build one.
The role is based in London on a hybrid basis, with a minimum of 3 days per week in the office, enabling you to work closely with our Engineering, Product and wider business teams.
- What You’ll Be Doing
- Take ownership of security architecture and technical security across XYZ Reality’s technology environment.
- Assess our current security posture, identify vulnerabilities and control gaps, and develop pragmatic remediation plans.
- Architect and strengthen security across our Azure cloud environment, including Kubernetes clusters, databases and data pipelines.
- Own and improve areas including IAM, zero-trust networking, secrets management, RBAC, pod security and encryption.
- Embed shift-left security into engineering workflows, integrating SAST, DAST, dependency scanning and SCA into our CI/CD pipelines.
- Partner directly with Engineering and Product teams on architectural decisions, technical trade-offs and secure-by-design development.
- Run threat-modelling exercises and support developers with secure coding practices across Node. js, React Native and C++ environments.
- Own vulnerability management, including triage, risk prioritisation, remediation tracking and incident response where required.
- Develop and improve the logging, monitoring and alerting capabilities needed to identify and respond to security threats.
- Assess emerging threats, including those associated with AI-enabled products, tooling and new attack methodologies, and ensure our security approach continues to evolve.
- Strengthen our SOC 2 Type II and ISO 27001 controls, identifying gaps and improving implementation where needed.
- Support compliance cycles including controls testing, evidence gathering and auditor coordination.
- Support GDPR and data residency requirements across our infrastructure and data pipelines.
- Engage with enterprise customers and prospects on XYZ Reality’s security posture when required.
- Automate security controls and processes wherever possible rather than relying on manual intervention.
- Help establish the standards, tooling and operating model for a security capability that can scale with the business.
- What We’re Looking For
- Demonstrable in-depth hands‑on technical security experience, ideally spanning application, cloud and/or infrastructure security.
- Strong technical security capability and the confidence to own security decisions end‑to‑end rather than operating purely in an advisory or governance capacity.
- Strong cloud security experience, ideally Azure, although significant AWS or GCP expertise with the ability to transition quickly to Azure would also be considered.
- Hands‑on experience securing Kubernetes/containerised environments, including IAM, RBAC, network segmentation, secrets management, image scanning and pod security.
- Experience integrating security tooling into CI/CD environments, including SAST, DAST, SCA and dependency scanning.
- Experience with infrastructure‑as‑code security and technologies such as Terraform, Helm or Git Ops.
- Understanding of application and API security, including OAuth 2.0, JWT, m TLS and secure development practices.
- Experience identifying vulnerabilities, assessing technical risk and driving remediation.
- Comfortable writing automation using Python, Go, Bash or similar to operationalise security controls.
- Practical experience working with SOC 2 Type II and/or ISO 27001, including identifying gaps and strengthening controls.
- Current knowledge of the evolving cybersecurity landscape and an interest in emerging threats, particularly those associated with AI.
- Strong communication skills and the ability to translate security requirements for both technical and non‑technical stakeholders.
- A pragmatic, collaborative approach, you understand that great security enables engineering teams rather than creating unnecessary barriers.
- Experience building or scaling security capability within a high‑growth or Series A/B technology business would be particularly valuable.
You’ll understand the balance between addressing today’s risks and building security foundations capable of supporting where the business is heading next.
- Above all, we’re looking for someone who is technically strong, curious and proactive, someone engineers want to work with, who can bring credibility to security conversations while remaining pragmatic about how we build and ship great technology.
- What You Could Be Working On
- From the outset, you’ll have the opportunity to make an impact across areas including:
- Azure and Kubernetes security architecture
- Application and API security
- Secure software development and shift-left security
- Vulnerability management and incident response
- AI-related security and emerging threat management
- SOC 2 Type II and ISO 27001 maturity
- Security automation and CI/CD integration
- Enterprise customer security requirements
- Building XYZ Reality’s longer‑term security capability and roadmap
- Why Join Us
- Become our first dedicated security hire and have genuine ownership over how security develops at XYZ Reality
- Hybrid working from our London office
- 25 days annual leave + public holidays
- Private healthcare with Vitality
- Additional Christmas shutdown days
- Biannual salary reviews
- Summer & Christmas company events
- Free Thursday lunch and after‑work gatherings
- Employee referral scheme
- Cycle to Work scheme
If you’re an experienced security engineer who wants more than maintaining an established security programme, and you’re excited by the opportunity to build, influence and own security within a growing technology business, we’d love to hear from you.
#J-18808-Ljbffr
Senior Security & Compliance Engineer employer: XYZ Reality
XYZ Reality is an exceptional employer, offering a dynamic work environment in London where innovation thrives. With a strong emphasis on employee growth, you will have access to professional development opportunities and a collaborative culture that values your insights. Enjoy comprehensive benefits including private healthcare and generous annual leave, making it a rewarding place to advance your career in the construction data field.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Security & Compliance Engineer
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including XYZ Reality, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through XYZ Reality
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at XYZ Reality. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Security & Compliance Engineer
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at XYZ Reality insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to XYZ Reality that you’re committed to staying ahead in the game.
How to prepare for a job interview at XYZ Reality
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at XYZ Reality to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at XYZ Reality.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.