×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security & Compliance Engineer

Job in London, Greater London, W1B, England, UK
Listing for: XYZ Reality
Part Time position
Listed on 2026-09-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below

Build the security foundations behind cutting-edge construction technology

At XYZ Reality weve created the worlds first engineering-grade Augmented Reality solution for construction. Our product The Atom is used on major projects worldwide to bring designs to life on-site and help teams build more accurately efficiently and with fewer mistakes.

As a Series B business scaling across the UK US and Europe our technology and the security environment supporting it is becoming increasingly sophisticated.

Our stack spans Kubernetes on Azure mobile and embedded AR REST APIs real-time collaboration and AI-powered data pipelines. We already hold SOC 2 Type II and ISO 27001 but as our product customers and use of AI continue to evolve we now need dedicated security expertise within the business.

Were looking for an experienced Senior Security & Compliance Engineer to take ownership of security across XYZ Reality and help build a security capability that can scale with us.

The Role

This is a critical hire and an opportunity to become our first dedicated security specialist with genuine ownership and influence across the business.

While we already have established compliance activity and SOC 2 Type II and ISO 27001 certifications security responsibilities currently sit across different teams. Were now looking for someone who can bring that together identify where we need to strengthen our approach and provide dedicated technical security leadership as we scale.

This is first and foremost a technical security role. Youll sit within Engineering and work directly alongside the teams building our technology participating in architecture discussions development workflows and technical decision-making rather than operating as a separate security function reviewing work after the fact.

Youll take ownership of security architecture across our technology stack embed shift-left security practices into how we build strengthen our cloud and application security and ensure we remain ahead of both established and emerging threats.

As our use of AI continues to develop youll also help us understand and respond to new AI-related security risks and attack vectors ensuring our security approach evolves alongside our technology.

Compliance remains an important part of the role. Youll help strengthen our SOC 2 Type II and ISO 27001 posture and support areas including GDPR data residency and enterprise customer requirements. However were looking for someone who brings strong hands-on security expertise first alongside the governance and compliance knowledge needed to operate effectively across both areas.

You wont simply inherit a security playbook youll have the opportunity to help build one.

The role is based in London on a hybrid basis with a minimum of 3 days per week in the office enabling you to work closely with our Engineering Product and wider business teams.

What Youll Be Doing

  • Take ownership of security architecture and technical security across XYZ Realitys technology environment.

  • Assess our current security posture identify vulnerabilities and control gaps and develop pragmatic remediation plans.

  • Architect and strengthen security across our Azure cloud environment including Kubernetes clusters databases and data pipelines.

  • Own and improve areas including IAM zero-trust networking secrets management RBAC pod security and encryption.

  • Embed shift-left security into engineering workflows integrating SAST DAST dependency scanning and SCA into our CI/CD pipelines.

  • Partner directly with Engineering and Product teams on architectural decisions technical trade-offs and secure-by-design development.

  • Run threat-modelling exercises and support developers with secure coding practices across React Native and C environments.

  • Own vulnerability management including triage risk prioritisation remediation tracking and incident response where required.

  • Develop and improve the logging monitoring and alerting capabilities needed to identify and respond to security threats.

  • Assess emerging threats including those associated with AI-enabled products tooling and new attack methodologies and ensure our security approach continues to evolve.

  • Strengthen our SOC 2 Type II and ISO 27001 controls identifying gaps and improving implementation where needed.

  • Support compliance cycles including controls testing evidence gathering and auditor coordination.

  • Support GDPR and data residency requirements across our infrastructure and data pipelines.

  • Engage with enterprise customers and prospects on XYZ Realitys security posture when required.

  • Automate security controls and processes wherever possible rather than relying on manual intervention.

  • Help establish the standards tooling and operating model for a security capability that can scale with the business.

What Were Looking For

  • Demonstrable in-depth hands-on technical security experience ideally spanning application cloud and/or infrastructure security.

  • Strong technical security capability and the confidence to own security decisions end-to-end…

Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary