Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Principal Security Engineer

Orgvue
Greater London
1 month ago
Applications closed

Related Jobs

View all jobs

Principal Security Engineer

Principal Security Engineer, Autonomous Security

▷ [3 Days Left] Principal Security Engineer...

Principal Cyber Security Engineer

Cyber Security Engineering Principal

Principal OT Cyber Security Engineer

Orgvue is a leading organizational design and planning software platform that captures the power of data visualization and modelling to build more adaptable, and better performing organizations. HR, finance and business leaders use Orgvue for actionable insight and analysis that helps them make faster workforce decisions in a constantly changing world.

Orgvue is used by the world’s largest and best-known enterprises and management consulting firms to visualize and confidently build the businesses they want tomorrow, today. The company is headquartered in London, with offices in Philadelphia, The Hague, Toronto, and Sydney.

We are seeking a strategic Principal Security Engineer with hands-on leader experience responsible for evaluating, evolving, and executing Orgvue’s security engineering strategy across our entire application development and cloud-hosting estate.

Role

In this role you will be partnering closely with Information Security, Engineering, and Product teams, you will embed secure-by-design principles throughout the software-development lifecycle (SDLC), champion modern DevSecOps practices, and ensure that security is a first-class citizen in everything we build and operate.

This role reports directly to the Chief Technology Officer (CTO) and maintains a dotted-line relationship with the VP of TechOps.

Responsibilities

Security Strategy & Governance – Define and continuously refine the technical security roadmap that aligns with business objectives, industry best practice (, NIST CSF, OWASP SAMM), and compliance frameworks (SOC 2, ISO 27001, GDPR). Secure SDLC & DevSecOps – Build and maintain guardrails for static/dynamic analysis, container and IaC scanning, SBOM management, and supply-chain security; automate enforcement through CI/CD pipelines. Cloud & Infrastructure Security – Design and implement robust controls for AWS (primary) and Azure/GCP (secondary): IAM, network segmentation, KMS, secrets management, WAF, EDR, and zero-trust patterns. Identity & Access Management (IAM) – Own enterprise IAM strategy, including RBAC, least-privilege provisioning, SSO, federation (OIDC/SAML), and privileged-access workflows. Monitoring, Detection & Response – Define audit logging, metrics, and telemetry requirements; integrate with SIEM/SOAR to deliver actionable alerts and playbooks for engineering-led incident response. Threat Modeling & Risk Assessment – Conduct regular architecture and code-level reviews, drive remediation plans, and present risk posture to leadership. Tooling & Automation – Evaluate, select, and integrate security tooling (SAST, DAST, SCA, container scanners, CSPM, CWPP) and champion IaC/Terraform modules for reusable controls. Collaboration & Mentorship – Act as a trusted advisor to engineering squads, provide security training, and mentor senior engineers on emerging attack vectors and defensive techniques. Compliance & Audits – Partner with InfoSec and Legal to prepare evidence, manage technical controls, and remediate audit findings. InfoSec Partnership – Collaborate proactively with the Information Security team on policy development, threat intelligence sharing, incident response, and compliance initiatives, ensuring organisation-wide alignment. Engineering Partnership & Enablement – Work hand-in-hand with engineering squads to raise security awareness, improve secure coding practices, and foster a culture of shared security ownership. Architecture Alignment – Partner closely with Orgvue’s Principal Architect to ensure security patterns, controls, and roadmaps align with overall system architecture and future technical strategy.

We are unable to offer Sponsorship for this position and are we not engaging with agencies.

Requirements

Extensive experience in security engineering and/or software engineering with a strong security focus, including demonstrated leadership of complex security initiatives Expert-level knowledge of at least one major cloud platform (AWS preferred) and its native security services. Proven success embedding security within modern microservice, container, and serverless architectures. Proficiency with Infrastructure-as-Code (Terraform, CloudFormation) and Kubernetes security hardening (admission controllers, network policies). Strong understanding of and practical experience of software engineering and how security can be an enabler to success as an engineer. Experience working within high-sensitivity data environments Strong awareness of compliance standards and the requirements on software teams, especially for ISO27001 and SOC2. FedRAMP experience advantageous. Demonstrated experience performing threat modelling, penetration test scoping, and vulnerability management. Deep understanding of IAM concepts, encryption/key-management, and secure network design. Excellent communication skills with ability to translate technical risk to non-technical stakeholders. Ideally you will have certifications such as CISSP, CSSLP, AWS Certified Security. Familiarity with data privacy controls (tokenization, field-level encryption, data mesh) would be a bonus. Experience implementing security and governance programs for emergent AI tooling and capabilities.

Benefits

Hybrid working - 1+ days a week in the London office Wellbeing: Sanctus Coaching, Virtual fitness sessions, Wellbeing webinars, Annual Wellbeing day Subsidised Gym Membership Private Medical Insurance (including Dental and Vision) and Life Assurance 25 days holiday (increasing to 30 days at a rate of 1 extra day per year) Summer Fridays (half-day Fridays for the months of July and August) Employer pension contribution of 5% of your gross salary, if you contribute a minimum of 3% Season ticket Loan Cycle to Work Scheme Annual Discretionary Bonus

'Here at Orgvue we promote individualism and a diverse workforce to build on our future success'

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Top 10 Skills in Cyber sScurity According to LinkedIn & Indeed Job Postings

In today’s digital age, cyber security is no longer optional—it’s mission-critical. From financial institutions to healthcare providers, government departments to tech startups, every sector in the UK is under rising cyber threats. As a result, employers are constantly on the hunt for skilled professionals who can defend, detect, and respond effectively. But with cyber threats evolving at pace, what exactly are employers seeking? By analysing job postings on LinkedIn and Indeed, this article reveals the Top 10 cyber security skills UK organisations are demanding in 2025. Read on to discover how to present these skills effectively on your CV, in interviews, and through practical proof of experience.

The Future of Cybersecurity Jobs: Careers That Don’t Exist Yet

Cyber security has become one of the most critical issues of our age. Once regarded as a technical problem confined to IT departments, it is now a board-level priority, a government mandate, and a daily necessity for individuals. The shift towards cloud services, remote working, connected devices, and artificial intelligence has dramatically increased the risks of digital attacks. In the UK, cyber security is central to national resilience. The government has identified cyber as a “tier one” threat to national security, alongside terrorism and pandemics. The private sector, from banks to retailers, now sees data breaches and ransomware as existential risks. Global spending on cyber security is projected to exceed $250 billion by 2030, with the UK already home to a thriving cyber industry employing tens of thousands. Yet, as powerful as the industry already is, we are only at the beginning. The technologies shaping the next two decades—AI, quantum computing, edge computing, extended reality, and biotechnology—will radically reshape cyber security. Many of the most vital cyber security jobs of the future don’t exist yet. This article explores why new roles will emerge, the careers likely to appear, how today’s jobs will evolve, why the UK is well-positioned, and how professionals can prepare now.

Seasonal Hiring Peaks for Cybersecurity Jobs: The Best Months to Apply & Why

The UK's cybersecurity sector has emerged as one of the most critical and lucrative technology markets, with roles spanning from security analysts to penetration testers and chief information security officers. With cybersecurity positions commanding salaries from £28,000 for junior security analysts to £140,000+ for senior security architects, understanding when organisations actively recruit can dramatically impact your career trajectory in this essential field. Unlike traditional IT sectors, cybersecurity hiring follows distinct patterns influenced by threat landscapes, regulatory compliance cycles, and incident response requirements. The sector's unique combination of perpetual threat evolution, regulatory pressures, and skills shortages creates predictable hiring windows that strategic professionals can leverage to advance their careers in protecting Britain's digital infrastructure. This comprehensive guide explores the optimal timing for cybersecurity job applications in the UK, examining how cyber threat cycles, compliance deadlines, and government initiatives influence recruitment patterns, and why strategic timing can determine whether you join a cutting-edge security consultancy or miss the opportunity to defend against tomorrow's cyber threats.