More jobs:
Senior Security Engineer
Job in
Derry, County Derry, BT47, Northern Ireland, UK
Listed on 2026-06-26
Listing for:
Semble
Full Time
position Listed on 2026-06-26
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
About the role
You will report directly to the Head of Information Security and work alongside a Senior Technical Support Engineer to form the senior core of the IT Delivery and Security Services team. You will own a broad portfolio of security responsibilities, from application security and secure SDLC enablement to AI governance and security programmes, with significant autonomy to shape how that work gets done.
The role is hybrid within the UK, with occasional travel to our London office for collaboration and workshops.
- Embed security into Agile development by partnering with engineering squads during planning, refinement, and delivery, and be the security voice in the room.
- Define, roll out, and continuously improve secure coding standards, secure design patterns, and developer-friendly guidance that scales across the engineering team.
- Run threat modelling for new features and major architectural changes, capturing abuse cases and security requirements early, and apply emerging frameworks to model and mitigate new threat surfaces, especially for AI-powered features.
- Own SAST, SCA, DAST, container, and IaC scanning pipelines, using Snyk as the primary platform. Integrate with CI/CD, manage policies, and focus on developer experience and false-positive reduction.
- Triage and manage vulnerabilities end-to-end: classification, SLAs, fix validation, and reporting.
- Build frictionless guardrails such as pre-commit hooks, secure templates, reference code, and paved paths that make doing the right thing easy.
- Deliver targeted training and just-in-time enablement based on findings and stack specifics.
- Advise on architecture choices for key product feature developments, including authorisation, secrets and key management, data protection, and zero-trust-aligned designs.
- Guide secure API and microservice patterns, including input validation, rate limiting, secure session handling, and token-based security (OAuth 2.0/OIDC).
- Review designs for cloud-native services and edge components, ensuring sensible security trade-offs aligned to product goals.
- Advise on the security architecture of agent orchestration, tool integrations, memory handling, and MCP server deployments as agentic AI capabilities expand.
- Apply and evolve Semble's approach to AI‑specific threats: prompt injection, excessive agent autonomy, tool and plugin abuse, AI supply‑chain risks, and context manipulation, using OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications.
- Work with the Head of Information Security to develop and maintain AI governance posture, aligned with ISO 42001 and evolving AI regulatory landscape in healthcare.
- Assess risks from third‑party AI integrations, AI‑assisted development tooling, and agentic workflows, and implement appropriate mitigations.
- Monitor, investigate, and respond to security alerts, incidents, and anomalous behaviour across Semble's environment.
- Develop and mature threat intelligence capabilities, including vulnerability management, penetration testing coordination, and incident response processes.
- Maintain and improve security tooling, logging, and detection capabilities with an automation‑first mindset.
- Contribute to incident response runbooks for application‑layer and AI‑related incidents, and support blameless post‑incident reviews to embed learning back into the SDLC.
- Identify and address security gaps proactively, improving the overall security posture.
- Own or co‑own delivery of compliance programmes, including ISO 27001, Cyber Essentials+, NHS DSPT, and the journey toward SOC 2 readiness.
- Support and contribute to ISO 42001 implementation as AI governance matures.
- Define and track pragmatic security KPIs such as time‑to‑remediate, coverage, critical resolutions within SLA, threat model coverage, and audit readiness indicators.
- Maintain audit‑quality documentation, evidence, and records at all times.
- Support the sales process by responding to customer security…
Position Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×