Engineer the Quantum RevolutionYour expertise can help us shape the future of quantum computing at Oxford Ionics.

View Open Roles

Principal Security Engineer

Orgvue
London
1 month ago
Create job alert

Join to apply for the Principal Security Engineer role at Orgvue

1 week ago Be among the first 25 applicants

Join to apply for the Principal Security Engineer role at Orgvue

Orgvue is an organisational design and planning platform that empowers your business to transform its workforce by understanding the work people do and the skills they have. Our platform connects strategy to structure, providing clarity of vision, so you can build a more adaptable, better performing organisation that thrives in a constantly changing world of work.

The world's largest and best-known enterprises and consulting firms use Orgvue to visualise and model current and future states of the organisation and make faster, more informed decisions. The company is headquartered in London, with offices in Philadelphia, The Hague, Toronto, and Sydney.

Role

The Principal Security Engineer is a strategic, hands-on leader responsible for evaluating, evolving, and executing Orgvue's security engineering strategy across our entire application development and cloud-hosting estate. Partnering closely with Information Security, Engineering, and Product teams, you will embed secure-by-design principles throughout the software-development lifecycle (SDLC), champion modern DevSecOps practices, and ensure that security is a first-class citizen in everything we build and operate.

This role reports directly to the Chief Technology Officer (CTO) and maintains a dotted-line relationship with the VP of TechOps.

Responsibilities

  • Security Strategy & Governance - Define and continuously refine the technical security roadmap that aligns with business objectives, industry best practice (e.g., NIST CSF, OWASP SAMM), and compliance frameworks (SOC 2, ISO 27001, GDPR)
  • Secure SDLC & DevSecOps - Build and maintain guardrails for static/dynamic analysis, container and IaC scanning, SBOM management, and supply-chain security; automate enforcement through CI/CD pipelines
  • Cloud & Infrastructure Security - Design and implement robust controls for AWS (primary) and Azure/GCP (secondary): IAM, network segmentation, KMS, secrets management, WAF, EDR, and zero-trust patterns
  • Identity & Access Management (IAM) - Own enterprise IAM strategy, including RBAC, least-privilege provisioning, SSO, federation (OIDC/SAML), and privileged-access workflows
  • Monitoring, Detection & Response - Define audit logging, metrics, and telemetry requirements; integrate with SIEM/SOAR to deliver actionable alerts and playbooks for engineering-led incident response
  • Threat Modeling & Risk Assessment - Conduct regular architecture and code-level reviews, drive remediation plans, and present risk posture to leadership
  • Tooling & Automation - Evaluate, select, and integrate security tooling (SAST, DAST, SCA, container scanners, CSPM, CWPP) and champion IaC/Terraform modules for reusable controls
  • Collaboration & Mentorship - Act as a trusted advisor to engineering squads, provide security training, and mentor senior engineers on emerging attack vectors and defensive techniques
  • Compliance & Audits - Partner with InfoSec and Legal to prepare evidence, manage technical controls, and remediate audit findings
  • InfoSec Partnership - Collaborate proactively with the Information Security team on policy development, threat intelligence sharing, incident response, and compliance initiatives, ensuring organisation-wide alignment
  • Engineering Partnership & Enablement - Work hand-in-hand with engineering squads to raise security awareness, improve secure coding practices, and foster a culture of shared security ownership
  • Architecture Alignment - Partner closely with Orgvue's Principal Architect to ensure security patterns, controls, and roadmaps align with overall system architecture and future technical strategy

We are unable to offer Sponsorship for this position and are we not engaging with agencies.

Requirements

  • Extensive experience in security engineering and/or software engineering with a strong security focus, including demonstrated leadership of complex security initiatives
  • Expert-level knowledge of at least one major cloud platform (AWS preferred) and its native security services
  • Proven success embedding security within modern microservice, container, and serverless architectures
  • Proficiency with Infrastructure-as-Code (Terraform, CloudFormation) and Kubernetes security hardening (admission controllers, network policies)
  • Strong understanding of and practical experience of software engineering and how security can be an enabler to success as an engineer
  • Experience working within high-sensitivity data environments
  • Strong awareness of compliance standards and the requirements on software teams, especially for ISO27001 and SOC2. FedRAMP experience advantageous
  • Demonstrated experience performing threat modelling, penetration test scoping, and vulnerability management
  • Deep understanding of IAM concepts, encryption/key-management, and secure network design
  • Excellent communication skills with ability to translate technical risk to non-technical stakeholders

Preferred, But Not Essential

  • Certifications such as CISSP, CSSLP, AWS Certified Security
  • Familiarity with data privacy controls (tokenization, field-level encryption, data mesh)
  • Experience implementing security and governance programs for emergent AI tooling and capabilities

Benefits

  • Hybrid working - 1+ days a week in the London office
  • Wellbeing: Sanctus Coaching, Virtual fitness sessions, Wellbeing webinars, Annual Wellbeing day
  • Subsidised Gym Membership
  • Private Medical Insurance (including Dental and Vision) and Life Assurance
  • 25 days holiday (increasing to 30 days at a rate of 1 extra day per year)
  • Summer Fridays (half-day Fridays for the months of July and August)
  • Employer pension contribution of 5% of your gross salary, if you contribute a minimum of 3%
  • Season ticket Loan
  • Cycle to Work Scheme
  • Annual Discretionary Bonus

'Here at Orgvue we promote individualism and a diverse workforce to build on our future success'Seniority level

  • Seniority levelMid-Senior level

Employment type

  • Employment typeFull-time

Job function

  • IndustriesIT Services and IT Consulting

Referrals increase your chances of interviewing at Orgvue by 2x

Get notified about new Principal Security Engineer jobs in London, England, United Kingdom.

Security Architects (DV Security Clearance)

London, England, United Kingdom 2 weeks ago

London, England, United Kingdom 3 weeks ago

London, England, United Kingdom 2 months ago

Cloud Security Architect, UK Security Operations

London, England, United Kingdom 5 days ago

Security Engineer/Architect - Hedge Fund - up to £185,000 + bonusSenior Security Engineer - Automation - £850 per day

London, England, United Kingdom 1 week ago

London, England, United Kingdom 3 weeks ago

London, England, United Kingdom 13 hours ago

London, England, United Kingdom 1 month ago

Technical Architect (DV Security Clearance)

London, England, United Kingdom 2 weeks ago

London, England, United Kingdom 2 weeks ago

London, England, United Kingdom 1 week ago

London, England, United Kingdom 1 day ago

London, England, United Kingdom 4 weeks ago

Principal Infrastructure Security Engineer - Platform

London, England, United Kingdom 3 weeks ago

Senior Security Engineer, Detection and Response

London, England, United Kingdom 3 days ago

Mandiant Cloud Security Architect, Mandiant, Google Cloud

London, England, United Kingdom 4 days ago

London, England, United Kingdom 1 week ago

Senior Consultant or Manager, Security Engineer - Financial Services, Enterprise Security

Greater London, England, United Kingdom 1 week ago

London, England, United Kingdom 1 week ago

London, England, United Kingdom 3 weeks ago

Senior Security Engineer - Security Technology Delivery

Greater London, England, United Kingdom 2 weeks ago

Senior Security and Infrastructure Engineer

London Area, United Kingdom £70,000.00-£80,000.00 21 hours ago

London, England, United Kingdom 1 month ago

London, England, United Kingdom 2 weeks ago

London, England, United Kingdom 1 week ago

London, England, United Kingdom 1 week ago

Senior Security Engineer - Ecommerce – 6 Month Contract

London, England, United Kingdom 1 week ago

London, England, United Kingdom 3 months ago

Senior Physical Security System Engineer

London, England, United Kingdom 4 days ago

Sr. Security Engineer, AppSec - Amazon Stores Security

London, England, United Kingdom 1 week ago

London, England, United Kingdom 2 months ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.


#J-18808-Ljbffr

Related Jobs

View all jobs

Principal Security Engineer...

Principal Security Engineer

Principal Security Engineer

Principal Security Engineer

Principal Security Engineer, Autonomous Security

Principal Security Engineer

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Pre-Employment Checks for Cyber Security Jobs: DBS, References & Right-to-Work and more Explained

The cyber security sector in the UK stands at the forefront of protecting national infrastructure, business operations, and personal data from increasingly sophisticated cyber threats. As organisations across all sectors recognise cyber security as a critical business function, employers are implementing the most rigorous pre-employment screening processes in the technology industry to ensure they recruit professionals capable of defending against advanced persistent threats and maintaining the highest standards of security and trustworthiness. Whether you're a penetration tester, security analyst, incident response specialist, or chief information security officer, understanding the comprehensive vetting requirements is essential for successfully advancing your career in this security-critical field. This detailed guide explores the extensive background checks and screening processes you'll encounter when applying for cyber security positions in the UK, from fundamental eligibility verification to the most stringent security clearance requirements and specialised threat intelligence assessments.

Why Now Is the Perfect Time to Launch Your Career in Cyber Security: The UK's Digital Defence Revolution

The United Kingdom faces an unprecedented cyber security challenge that presents an extraordinary career opportunity. With cyber attacks increasing by 300% year-on-year and the average cost of a data breach reaching £4.24 million, Britain urgently needs skilled cyber security professionals to defend its digital infrastructure, protect citizens' data, and maintain national security in an increasingly connected world. If you've been considering a career change or seeking to future-proof your professional trajectory, cyber security represents one of the most secure, well-compensated, and socially impactful career choices available. The convergence of escalating threats, skills shortage, government investment, and regulatory requirements has created a perfect storm of opportunity that shows no signs of abating.

Automate Your Cyber Security Jobs Search: Using ChatGPT, RSS & Alerts to Save Hours Each Week

Cyber roles drop across consultancies, MSSPs, hyperscalers, banks, gov & start-ups every day—often buried in ATS portals or duplicated across boards. The fix is simple: put discovery on autopilot with keyword-rich alerts, RSS feeds & a reusable ChatGPT workflow that triages listings, ranks fit, & tailors your CV in minutes. This copy-paste playbook is built for www.cybersecurityjobs.tech readers. It’s UK-centric, practical, & designed to save you hours each week. What You’ll Have Working In 30 Minutes A role & keyword map spanning SecOps/Detection, DFIR, AppSec, Cloud Security, GRC, Red Team, Threat Intel, IAM/PAM, OT/ICS & Vulnerability Management. Shareable Boolean search strings for Google & job boards to cut noise fast. Always-on alerts & RSS feeds delivering fresh roles to your inbox/reader. A ChatGPT “Cyber Job Scout” prompt that deduplicates, scores fit & outputs tailored actions. A simple pipeline tracker so deadlines & follow-ups never slip.