Product Security Engineer; office locations
Listed on 2026-07-14
-
Security
Cybersecurity
Product Security Engineer (we have office locations in Cambridge, Leeds & London)
- Full-time
- Office:
London
Genomics England is a global leader in enabling genomic medicine and research, focused on creating a world where everyone benefits from genomic healthcare. Building on the 100,000 Genomes Project, we support the NHS’s world-first national whole genome sequencing service and run the growing National Genomic Research Library, alongside delivering numerous major genomics initiatives. By connecting research and clinical care at national scale, we enable immediate healthcare benefits and advances for the future.
Our mission is to provide the evidence and digital systems so that by 2035 genomics could play a role in up to half of all healthcare interactions, whilst securing the UK’s position as the best place to discover, prove and benefit from genomic innovations.
We are accelerating our impact and working with patients, doctors, scientists, government and industry to improve genomic testing, and help researchers access the health data and technology they need to make new medical discoveries and create more effective, targeted medicines for everybody.
Behind the Healthcare and Research outcomes, Genomics England delivers through designing, developing and operating complex healthcare software systems.
We're on the cusp of big changes with the real prospect of genomics becoming the fabric of everyday healthcare through the lifetime - from birth to old age.
As a Product Security Engineer, you will work as part of the Cyber Security team at Genomics England, partnering closely with engineering squads and product teams to integrate security into day-to-day delivery.
The purpose of this role is to bring security closer to where engineering decisions are made, enabling teams to adopt Genomics England’s security standards in a practical and scalable way. You will work directly with squads as a trusted partner, helping them build and deliver secure systems rather than acting as a central gatekeeper.
You will support teams to shift security left by contributing to secure design and development from the outset. This includes helping teams implement security testing in CI/CD pipelines, improving vulnerability management within squads, and ensuring security issues are addressed as part of normal delivery.
Acting as a bridge between central security and delivery teams, you will translate security policies and risk expectations into clear, actionable engineering practices. You will contribute to threat modelling, design discussions, and security reviews, helping teams break down complex security challenges into pragmatic technical solutions.
This is a hands‑on, product‑embedded security role. While it is not a platform or site reliability engineering position, it requires strong practical familiarity with cloud‑native systems, CI/CD pipelines and infrastructure‑as‑code to credibly influence design and implementation decisions within squads.
A key part of the role is enabling and scaling security capability through the Security Champions programme. You will support and grow this community, helping champions build security knowledge and embed good practices within their teams.
Through this role, you will help evolve Genomics England towards a model where security is owned by engineering teams, with Cyber Security providing guidance, expertise, and enablement.
Skills and Experience for Success:
A strong foundation in cyber security engineering, including secure design principles and risk‑based decision making.
Practical experience embedding security into software development, including supporting shift‑left practices across design, development, and delivery.
Experience working hands‑on with engineering teams, with the ability to understand application architectures, review code or designs, and help troubleshoot security issues.
Experience integrating security controls into CI/CD pipelines, including code, dependency, and infrastructure‑as‑code scanning, with an emphasis on automation and developer experience.
Practical familiarity with public cloud environments, particularly AWS, including common security patterns and risks.
Ex…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: