Principal, Quality Eng:, IT Security
Listed on 2026-07-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Select how often (in days) to receive an alert:
The Principal, Quality Engineering leads the quality engineering strategy for a business-aligned capability or a technology-aligned practice, including tooling, resourcing, CoP engagement, operational resilience, automation and ensuring security standards are maintained for the capability which helps in ensuring and maintaining the quality of EBRD's platforms and technology solutions.
The Principal acts as the quality authority to multi-disciplinary platform or software engineering capabilities, with direct responsibility for setting the overall quality direction and design approaches for one or more squads, ensuring adherence to best practices, EBRD standards, and quality requirements.
This position provides leadership and direction for a team of internal and external Quality Engineering professionals, ensuring the effective governance, assurance, and delivery of quality outcomes across EBRD enterprise platform programmes. The role drives quality standards, test strategy, automation, assurance, and continuous improvement to support the secure, resilient, and successful delivery of business-critical technology solutions.
They will manage the quality activities for multiple assigned projects or programs, responsible for the strategic guidance of quality and the associated quality planning activities and ensuring that key stakeholders are engaged and informed with accurate, targeted, and timely information.
They will work closely with the project resourcing managers in order to effectively manage project resourcing plans in an efficient and lean group.
Accountabilities and Responsibilities- Requirements and Analysis
- Collaborates with Cyber Security Architects, Product Owners, and Business Analysts to ensure security considerations are embedded in user stories and acceptance criteria. This includes authentication flows, data encryption requirements, and regulatory compliance.
- Conducts and oversees comprehensive risk assessments to identify potential security threats – both functional (e.g. role-based access issues) and non-functional (e.g. performance under attack simulations). Prioritises risk mitigation and remediation activities accordingly.
- Test Planning and Strategy
- Defines and owns the security testing strategy for products or domains under the cyber security capability, ensuring alignment with organisational risk appetite. Incorporates both functional security tests (e.g. role-based access checks) and non-functional security tests (e.g. penetration testing, threat modelling).
- Oversees and coordinates integration of security testing into CI/CD pipelines. This includes static and dynamic code analysis, dependency checks, and container scanning, ensuring teams catch vulnerabilities early.
- Test Design and Execution
- Participates in solution design discussions with cyber architects and senior engineers to ensure secure coding standards, encryption protocols, and identity management solutions are testable and robust.
- Drives adoption and standardisation of security testing frameworks – covering areas like penetration testing, vulnerability scanning, and threat simulation – across squads within the cyber security remit.
- Identifies and champions automation projects that detect vulnerabilities in near real-time (e.g. automated vulnerability scanning, container integrity checks), reducing attack surfaces and accelerating feedback loops.
- Collaboration and Agile Ceremonies
- Advocates for the inclusion of explicit security acceptance criteria in sprint planning and backlog refinement. Ensures squads incorporate security-related user stories, threat models, and test cases.
- Works with security governance, risk and compliance teams, as well as broader IT stakeholders, to align on security standards, share best practices, and coordinates enterprise-wide security initiatives.
- Implements structured processes for categorising and prioritising security vulnerabilities (e.g. CVSS scoring, regulatory compliance impact). Ensures timely fixes for high-severity issues, balancing business priorities with risk exposure.
- Facilitates post-incident reviews for security breaches or near-miss…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).