We’re looking for an experienced and hands-on Head of Security Engineering to own and elevate the security of our products and the engineering practices that build them. As a file protection company, security isn’t a feature for us, it’s the heart of what we do, and our customers trust us with their most sensitive environments. In this role you’ll be accountable for our product security posture and the security engineering strategy that underpins it, spanning application security, software assurance and DevSecOps: the tooling, resourcing, processes and culture that embed security into every stage of the software lifecycle. You’ll lead a small, high-calibre team of DevSecOps and Software Assurance Engineers, setting direction while staying close enough to the detail to make sound technical calls. You’ll own threat modelling, security assessment and penetration testing, supply chain security and SBOM-based reporting, and you’ll be a key person in our incident response. You’ll bring an agentic-first mindset, which is central to how we work: championing the responsible adoption of agentic AI across security engineering to raise the speed, coverage and quality of our security work, while making sure it’s adopted safely and with appropriate guardrails. You’ll be an excellent communicator, comfortable engaging customers, auditors and executives as readily as your own engineers, and you’ll keep us ahead of an ever-evolving threat landscape. Reporting to the CTO, this is a role for a security leader who wants real ownership, real impact, and the chance to shape how a security-first company builds secure software. If that sounds like you, we’d love to hear from you. Responsibilities Own and be accountable for our overall product security posture, including a clear security metrics scorecard (such as mean time to remediate, critical-application coverage, exploitability and security-debt backlog) and the regular reporting, analysis and communication of security risk to engineering leadership, executives and the CTO. Define, own and drive the DevSecOps strategy, covering tooling, resourcing and organisation-wide adoption, embedding security throughout the software development lifecycle rather than bolting it on at the end. Lead, manage, mentor and grow a team of DevSecOps and Software Assurance Engineers, setting clear objectives, raising the technical bar, and building a high-performing, security-first culture. Own threat modelling, security assessment and penetration testing across our products and platforms, prioritising findings by risk and driving them through to remediation. Own product vulnerability management end to end, from identification and triage through prioritisation, tracking and remediation, holding the business to compliance-driven remediation SLAs and reporting clearly against them. Own supply chain security, including the generation, maintenance and reporting of Software Bills of Materials (SBOMs) and the management of third-party and open-source dependency risk. Select, integrate and operate the security tooling pipeline (SAST, DAST and SCA), making sure results are actionable, automated within CI/CD, and continuously improving in coverage and signal-to-noise. Own the security of the AI and agentic systems we build, including defences against prompt injection, model and AI supply-chain risk, governance of agents and Model Context Protocol (MCP) integrations, and discovery and control of shadow AI across the SDLC. Own the secure use of AI-generated code, putting in place the controls, review and testing that keep AI-authored output safe as the team scales its use of coding assistants. Champion and govern the responsible adoption of agentic AI in security engineering, identifying high-value use cases, defining safe-usage guardrails, and using agentic tooling to increase the speed, breadth and depth of security work. Act as a key person in incident response, helping to prepare, detect, coordinate and lead the response to security incidents, and driving post-incident reviews and lasting improvements. Define and maintain secure development standards and secure coding guidance, favouring guardrails over gates: hardened templates, trusted components and secure-by-default practices that help engineering teams build securely rather than slowing them down. Partner with engineering, product, platform and delivery teams to balance security with delivery pace, providing pragmatic, risk-based guidance. Engage confidently with external stakeholders such as customers, auditors, partners and researchers, representing our security posture and supporting assurance, compliance and trust activities. Manage relationships with security vendors and external testers and oversee coordinated vulnerability disclosure and responsible reporting processes. Keep abreast of the latest developments in DevSecOps, emerging vulnerabilities, attack techniques and tooling, translating them into improvements to our practices and products. Work agentic-first: default to AI-assisted and agent-based workflows in your own work and across the team, continuously raising productivity and quality across the security engineering lifecycle. Required Knowledge, experience and values An agentic-first mindset, which is essential: you embrace agentic AI, default to AI-assisted and agent-based workflows, and have hands-on experience using modern agentic AI tooling (e.g. Claude Code, CoPilot or similar) in security and engineering work. 5+ years leading an AppSec or DevSecOps team, with a track record of building and maturing security engineering practices in a software product environment. A strong academic and technical background, typically a degree in computer science, engineering, cybersecurity or a related discipline. Demonstrable experience leading, managing and developing security professionals, setting direction and growing high-performing teams. Strong hands-on expertise across the core security tooling categories (SAST, DAST and SCA), including selecting, integrating and operating them within CI/CD pipelines. Deep, practical knowledge of threat modelling, security assessment and penetration testing, and the ability to translate findings into prioritised, actionable remediation. Proven experience running product vulnerability management at scale, including triage, prioritisation and meeting compliance-driven remediation SLAs. Solid understanding of supply chain security and SBOMs, including dependency and open-source risk management. Working knowledge of securing AI and agentic systems, including prompt injection, model and AI supply-chain risk, and the secure use of AI-generated code. A metrics-driven approach to security leadership, comfortable defining and reporting on a posture scorecard to drive measurable risk reduction. Experience as a key contributor to incident response, including detection, coordination, containment and post-incident improvement. Excellent internal and external communication skills, with the ability to tailor messaging to engineers, executives, customers and auditors alike. Strong stakeholder management skills, with the credibility and influence to drive secure practices across teams without owning every team. Sound, risk-based decision-making that balances security, delivery pace, cost and maintainability in a commercial environment. Maintains confidentiality and operates with integrity, following all Glasswall policies and demonstrating exemplary security awareness. We encourage you to apply even if your experience is not a 100% match with the position. Beneficial Knowledge, experience, and values Relevant security certifications (e.g. CISSP, CSSLP, OSCP, CCSP, GIAC) demonstrating breadth and depth of security expertise. Hands-on experience building agentic security workflows or integrating LLMs/agents into security tooling, testing and analysis. Experience with cloud security across a major provider (Azure, AWS or GCP), including cloud-native security services and posture management. Familiarity with containerisation and orchestration security (Docker, Kubernetes, Helm) and Infrastructure-as-Code security (e.g. Terraform). Experience securing CI/CD pipelines, ideally with Azure DevOps, and embedding automated security controls. Knowledge of relevant standards and frameworks (e.g. OWASP SAMM/ASVS, NIST SSDF, MITRE ATT&CK, ISO 27001, SLSA). Familiarity with Application Security Posture Management (ASPM) and risk-based prioritisation that factors in exploitability, reachability and business criticality. Experience governing AI usage and agent/MCP integrations, including shadow-AI discovery and AI security governance policy. Experience supporting compliance, audit and customer assurance activities (e.g. SOC 2, FedRAMP, government security requirements). Experience with secure development in C# and/or other languages relevant to our products. Familiarity with vulnerability management and coordinated disclosure processes. Active engagement with the security community through research, publications, conferences or open-source contribution. About Us We didn’t start out as a traditional security product. In the beginning, Glasswall was one of only two file sanitization filters in the US Intelligence Community’s highly classified networks. We are rated #1 by the National Security Agency. We designed Glasswall CDR to protect businesses against the most advanced file-based threats. Today, we’re trusted by commercial and government organisations around the world. In June 2025 Glasswall officially entered a new era of growth and innovation having been acquired by the leading private equity firm, PSG Equity. This marks a significant milestone for our company and one that underscores the strength of our business, the dedication of our team, and the exciting potential that lies ahead. With PSG’s strong track record of scaling high-growth cybersecurity and technology businesses, we are better positioned than ever to accelerate innovation, expand into new markets, and deliver even greater value to our clients, employees, and stakeholders. Cybersecurity is a mission-critical field, and we’ve always believed that staying ahead means moving faster, continually adapting to meet new challenges and investing more boldly in the future. This partnership empowers us to do exactly that while maintaining the same leadership, values, and commitment to excellence that have brought us this far We’re excited for what’s to come so now is a great time for you to join us on our journey. Inclusion At Glasswall we believe that diversity of people and thought are central to our purpose. We are committed to making Glasswall a company that is attractive to people of many different backgrounds. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under-represented in our workforce. One of our corporate objectives is to ensure that the organisational health of the firm is highly rated by our employees. We believe that this is only possible if we promote a culture of inclusion and respect across our business. Every six months we survey employees on a range of questions relating to our organisational health. This holds a mirror-up to a business and ensures that we can focus on where we need to do better. We have an Organisational Health Committee, which is chaired by a non-executive position. The panel has been formed to guide the leadership in taking positive action that supports a good work-life balance, family friendly relations and to be inviting to a diverse range of potential employees. We also have a Women in Technology Group which has been formed to promote balance in the way that we communicate with, promote, encourage, and support people across our business. Work/Life Balance Our team puts a high value on work-life balance. It isn’t about how many hours you spend at home or at work; it’s about the flow you establish that brings energy to both parts of your life. We believe striking the right balance between your personal and professional life is critical to lifelong happiness and fulfilment. We offer flexibility in working hours and encourage you to find your own balance between your work and personal lives. Salary and Benefits Glasswall offers a competitive salary and incentives package. We offer flexible and remote working options, with hybrid working from our office in the Central London area. Office travel and incidental WFH expense coverage. 25 days holiday (plus public holidays). Private Medical Insurance including mental health support and cancer care. Enhanced sick pay. Company sponsored life, critical illness, and income protection insurance. Contributory pension scheme. Access to ‘salary sacrifice’ benefits such as Cycle to Work and Tech Schemes. A successful candidate will live in the United Kingdom and be comfortable working from home with some meetings being held in the London office. We are looking for someone with relevant skills and experience, not a checklist that exactly matches the job description. We want to help you grow, and in return, you help us grow into a stronger, more inclusive organisation. Glasswall is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, disability, age, or other legally protected status.
Information Security Manager with Network Engineering Skills
Free-Work UK
Information Security Manager with Network Engineering Skills (IT) / Contractor
Free-Work UK
Senior Manager - Application Security Engineering EMEA
Black Duck Software, Inc.
Principal Security Architect & Engineering Lead
Nhbc
Security Engineering Delivery Manager
Amach
Head of Engineering Profession - Telecommunications & OT Cyber Security
Tfl