Product Security Engineer

Product Security Engineer

Full-Time 60000 - 80000 £ / year (est.) No working from home possible
Zopa Bank Limited

At a Glance

  • Tasks: Champion product security while collaborating with engineers and product owners on innovative projects.
  • Company: Join Zopa, a diverse fintech company committed to inclusivity and innovation.
  • Benefits: Enjoy a supportive work environment, competitive salary, and opportunities for professional growth.
  • Other info: Be part of a vibrant team with nearly 50 nationalities and a strong focus on diversity.
  • Why this job: Make a real impact by ensuring security is integrated into cutting-edge products from the start.
  • Qualifications: Experience in offensive security and a passion for learning new technologies.

The predicted salary is between 60000 - 80000 £ per year.

Responsibilities

  • Being an advocate of security for product owners and engineers, with whom you'll build a working relationship.
  • Performing web, mobile, and backend security assessments directly.
  • Orchestrating web, mobile, and backend security assessments between our product teams and third-party assessors when the situation calls for it.
  • Weighing in on technical architecture discussions, ensuring security is considered from the very inception of new features.
  • Threat modelling upcoming features, providing a more technical and hands-on steer when necessary to illustrate security concerns with proposed feature implementations.
  • Overseeing secure engineering training programmes, keeping our engineers aware of secure engineering practices, and abreast of the common security pitfalls to avoid.
  • Integrating security tooling, stitching together CI steps, scripts, and small tools to automate security controls and visualise their results in a helpful manner. This could include SAST, SCA, DAST, secrets scanning, vulnerability scanning, or other tooling.
  • Being guardians of our Secure Development Lifecycle, ensuring security controls are baked in and “pushed left” as much as reasonably possible.
  • Triaging incoming reports and findings from bug bounties, automated tools, and more.
  • Being comfortable doing “Just-in-Time” learning around technologies and frameworks as required to understand emerging technologies in the company, and the security concerns they raise – with appropriate time allocated by the company, of course.
  • Advising engineers on security patching, and ensuring our team does as we say by keeping our own tools patched too.
  • Staying cognizant of the balance required between security and productivity, and how to manage stakeholders' concerns around such trade-offs.

Qualifications

  • You have experience in offensive security, such as performing security assessments via tools like BurpSuite, nmap, Kali Linux, etc.
  • Strong experience in at least web or a mobile OS, with a willingness to learn the other too.
  • Fundamental networking and OS knowledge – you should know how to debug a failing DNS connection, be comfortable with command line tools, and broader computing principles.
  • Comfortable threat modelling, assessing the balance between features and security. Being able to explain the trade-offs to less technical stakeholders.
  • Basic scripting knowledge – we have some in-house tools we maintain ourselves.
  • A willingness to learn basic software engineering principles to ensure said tools stay maintainable. Being confident in at least one language such as Python, JavaScript, or Go.
  • Secure coding practices – being able to not just spot a SQL injection but provide detailed guidance about how to fix it and prevent it for future queries.
  • Providing security advice during architectural design phases of new products. Spotting fundamental security flaws in designs early on, before code is even written.
  • Basic cloud infrastructure knowledge, such as understanding the fundamentals of cloud compute instances (VMs), software-defined networks, and defining infrastructure in code.
  • Having experience in fintech, especially banks with mobile apps.
  • Able to read common tech stack languages not commonly used in InfoSec, e.g. Java and C#. This can assist whitebox assessments.
  • On top of knowing security skills, knowing fundamental software engineering practices to ensure modifications to our internal tools stay maintainable.

Subject to having the right to work in the country of choice. Zopa is proud to offer a workplace free from discrimination. Diversity of experience, perspectives, and backgrounds leads to better products for our customers and a unique company culture for our people. We are made up of nearly 50 nationalities, have a DE&I forum made up of Zopians wanting to make a difference, and we are proud of our culture where everyone can bring their full self to work. Our approach to DE&I is reflected in our hiring process so please let us know if you require any reasonable adjustments.

Product Security Engineer employer: Zopa Bank Limited

Zopa is an exceptional employer for a Product Security Engineer, offering a vibrant work culture that champions diversity and inclusion, with nearly 50 nationalities represented. Employees benefit from continuous learning opportunities, hands-on training in secure engineering practices, and the chance to influence security from the ground up in a collaborative environment. Located in a dynamic fintech sector, Zopa provides a unique platform for professional growth while ensuring a balance between security and productivity.

Zopa Bank Limited

Contact Details:

Zopa Bank Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Product Security Engineer

Tip Number 1

Network like a pro! Reach out to current employees in the company you're eyeing, especially those in product security roles. A friendly chat can give you insider info and might just get your foot in the door.

Tip Number 2

Show off your skills! If you've got experience with tools like BurpSuite or nmap, consider doing a mini-project or write-up showcasing your expertise. Share it on platforms like LinkedIn to catch the eye of recruiters.

Tip Number 3

Prepare for the interview by brushing up on your threat modelling and secure coding practices. Be ready to discuss how you’d balance security with productivity – it’s a hot topic that’ll show you understand the role's nuances.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step!

We think you need these skills to ace Product Security Engineer

Offensive Security
Security Assessments
BurpSuite
nmap
Kali Linux
Web Security
Mobile OS Security

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Product Security Engineer role. Highlight your experience with security assessments and any relevant tools you've used, like BurpSuite or nmap. We want to see how your skills align with our needs!

Show Off Your Technical Skills:Don’t shy away from showcasing your technical prowess! Mention your experience in threat modelling, secure coding practices, and any scripting knowledge you have. We love seeing candidates who can bridge the gap between security and software engineering.

Be Clear and Concise:When writing your application, keep it clear and to the point. Use straightforward language to explain your experiences and how they relate to the responsibilities listed in the job description. We appreciate clarity as much as we appreciate security!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows us you’re keen on joining our team at StudySmarter!

How to prepare for a job interview at Zopa Bank Limited

Know Your Tools

Familiarise yourself with the security tools mentioned in the job description, like BurpSuite and nmap. Be ready to discuss your experience using these tools in real-world scenarios, as this will show your practical knowledge and readiness for the role.

Understand Threat Modelling

Brush up on threat modelling techniques and be prepared to explain how you would assess the balance between new features and security. Think of examples where you've had to communicate these trade-offs to non-technical stakeholders, as this is crucial for the role.

Showcase Your Coding Skills

Since basic scripting knowledge is required, be ready to demonstrate your coding skills in languages like Python or JavaScript. Prepare a small project or example that highlights your ability to maintain and improve internal tools, as this will set you apart from other candidates.

Emphasise Continuous Learning

Highlight your willingness to learn about emerging technologies and frameworks. Share instances where you've quickly adapted to new tech or security concerns, as this shows your proactive approach and commitment to staying current in the field.