Product Security Engineer Software Security Enablement
Listed on 2026-09-12
-
Software Development
Product Security Engineer - Software Security Enablement
Location
London
Business Area
Legal Compliance and Risk
#
Description & Requirements
Our Team:
Bloomberg is building the worlds most trusted information network for financial professionals. We protect Bloomberg. We partner with internal departments to ensure the confidentiality integrity and availability of Bloomberg systems and the data we process. We aim to ensure that our clients see us as a trusted partner.
Our Chief Information Security Office (CISO) owns the technical aspects of this mission by ensuring Bloomberg products systems networks and commercial applications are built and maintained with security in mind.
Whats the role
We are seeking a Product Security Engineer to help ensure that Bloomberg software is built securely. You will be responsible for building and maintaining automated security capabilities across the software development lifecycle. You will also engage with engineering partners to provide remediation guidance and enhance security testing to deliver high-fidelity actionable results.
As a member of the Product Security Enablement team you will help provide automated security testing solutions for Bloomberg including SAST DAST SCA Secret searching and LLM-based assessments. Our teams goal is to create preventative security capabilities that integrate into development pipelines and help detect issues early in the software development lifecycle.
An engineering skillset is required for this role. You will be responsible for prototyping new tools integrating security testing tools and capabilities into the software development lifecycle and developing custom security capabilities to deliver scalable testing solutions to our engineering teams. This role will routinely challenge your technical background and critical thinking. You will be expected to collaborate with different stakeholders in a fast-paced environment across many technology stacks and services.
Well trust you to:
- Partner with engineering stakeholders to understand Bloombergs development landscape and security needs. Develop automated security solutions that integrate into development pipelines.
- Maintain and enhance existing security automation processes and security capabilities.
- Understand and research technical details of core technology stacks and develop or enhance custom code analysis queries.
- Communicate vulnerability landscape and work on mitigations with stakeholders across the business.
- Actively monitor the latest news and trends in automated security capabilities secure development and AI-assisted security workflows.
- Develop and enhance operational run books
- Perform ad-hoc vulnerability discovery including code review and static analysis for key engineering teams applications and services.
- Build or adopt new security capabilities to address issues at scale such as Software Composition Analysis Secret searching and other automated security testing techniques.
- Use LLMs and AI-assisted workflows as part of security assessments vulnerability research secure code review developer enablement and security automation.
- Explore evaluate and build automation using modern LLM tooling and integration patterns including custom skills MCP servers agentic workflows retrieval-augmented workflows and integrations with development and security tooling.
- A strong core engineering background with a proven track record.
- 3 years of experience in software development.
- Strong programming experience with working knowledge of at least one of: C/C Python JavaScript/Type Script.
- Knowledge and experience with Dev Ops and software used in development pipelines (e.g. Github Jenkins).
- Working knowledge of build systems package managers and development tooling (such as cmake npm maven gradle etc).
- A core understanding of common security vulnerabilities such as OWASP Top 10 issues and language-specific vulnerabilities.
- Experience using evaluating or building with LLMs or AI-assisted tooling in technical workflows.
- Ability to combine technical knowledge with an understanding of core aspects of an information security program.
- Motivation to keep up with latest trends and techniques in the information security community.
- Excellent written and verbal communication skills.
Wed love to see (not required but nice to have!):
- Experience or familiarity with running maintaining and customizing static analysis security testing tools such as CodeQL and Semgrep.
- Broad familiarity with programming language ecosystems and frameworks…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).