National AI Awards 2025Discover AI's trailblazers! Join us to celebrate innovation and nominate industry leaders.

Nominate & Attend

Software Security Engineer

Aurora Energy Research
Oxford
5 days ago
Create job alert

Software Security Engineer

Department: Tech - Security

Employment Type: Permanent - Full Time

Location: Oxford, UK

Reporting To: Head of Information Security

Description

Are you ready to raise the bar on cyber security and contribute to making our flagship products cyber resilient?

We are looking for a Security Engineer to join our Information Security team at our Oxford headquarters. You will be working across software engineering, modelling, and data science bringing your full self, including your security knowledge and expertise to the business.

As a Security Engineer at Aurora Energy Research, you will enable our colleagues to improve our secure software development lifecycle, ensure secure operational practices, and support compliance. You have a curious mindset, thrive in collaboration, and are passionate about new technology. You are solution oriented and focus on getting smart ideas into the hands of your colleagues. You enjoy working simultaneously on various initiatives and moving between teams.

You will become part of a top-notch information security team who love solving difficult problems. By joining our Information Security team, you will be part of something big and meaningful: help protect our brand and our company so that we can continue to provide vital support to the global energy transformation.

Key Responsibilities
Cultivate security culture. Work with product and engineering colleagues, be the security champion that strives to prioritize sustainable controls and drives real risk reduction outcomes.
Build secure products. Ensure security is considered throughout the product and software development life cycle. Provide security best practice, build security design patterns, complete security architecture reviews, threat models and risk assessments. Help solve engineering problems by implementing technical controls to mitigate risk.
Ensure we are deploying solutions into a secure environment . Ensure we build solutions in alignment with our control requirements. Support on-going business-as-usual and champion vulnerability management. Provide internal security consultancy and lead on audit engagements, risk activities and project initiatives. Work closely with colleagues to ensure effective technology risk management.
Work together . Collaborate and work with product and engineering teams. Help to solve problems and not just calling out issues. Take ownership of operational duties. Operate across the business to create alignment with security objectives.
Ensure security thought leadership. Keep up on security best practice and be a continuous learner. Guide and define our security policies, procedures, and standards end-to-end, be recognized as a point of escalation and subject matter expert for software and data risk.

What we are looking for

Required qualifications, capabilities, and skills:
Degree in a computer science related subject or comparable working experience related to the role.
Working knowledge of best-practices for securing micro-service architectures.
Working knowledge of modern secure SDLC practices with a focus on embedding security into CI/CD pipelines.
Working experience of the above concepts in the context of at least one major public cloud provider (AWS, GCP, or Azure).
Understanding of global security standards (like SOC2 or ISO 27001) and regulatory requirements and experience in maintaining compliance with these.
A desire to teach others and share knowledge. We want you to coach other team members on secure coding practices, design principles, and implementation patterns.
Comfortable in uncharted waters. We are building something new. Things change quickly. We need you to learn technologies and patterns quickly.
Ability to see the long term. We don't want you to sacrifice the future for the present.
Clarity of thought. We operate quickly and efficiently, and we value people who are economical with their time and clear with their opinions.

Desirable qualifications, capabilities, and skills:
Experience in a software engineering role, ideally with focus on security.
Working knowledge of offensive security, Application and Infrastructure penetration testing (OWASP top 10, OWASP ASVS).
Understanding of security vulnerabilities and remediation options in codebases & containers.
Working knowledge of methods for authentication and authorization (ODIC, OAuth 2, FIDO 2, etc)

Don't worry if you don't meet all the criteria - your unique skills and experiences are valued, and we encourage you to apply!

What we offer

Some of the benefits we include are:
Private Medical Insurance
Dental Insurance
Parental Support
Salary-Exchange Pension
Employee Assistance Programme (EAP)
Local Oxford Discounts
Cycle-to-work Scheme
Flu Jabs

At Aurora we will consider all requests for flexible working. For most roles, the following types of flexibility are usually possible: a hybrid model of remote and in-office working and flexible start and finish times. Please talk to us during the interview about the flexibility we could offer and we will be happy to explore the best available option for you.

The Company is committed to the principle that no employee or job applicant shall receive unfavourable treatment on grounds of age, disability, gender reassignment, race, religion or belief, sex, sexual orientation, marriage or civil partnership, pregnancy and maternity.

The successful candidate would start as soon as possible. The team will review applications as they are received. Salary will be competitive with experience.

To apply, please submit your Résumé / CV, a personal summary, your salary expectations and please inform us of your notice period.

#LI-OD1
#J-18808-Ljbffr

Related Jobs

View all jobs

Software Security Engineer

Software Security Engineer

Software Security Engineer

Lead Software Security Engineer (Remote)

Lead Software Security Engineer (Remote)

Lead Software Security Engineer (Remote)

National AI Awards 2025

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

How to Present Cyber Security Solutions to Non-Technical Audiences: A Public Speaking Guide for Job Seekers

Cyber security is no longer just an IT issue—it’s a board-level priority. Whether you’re applying for a role in penetration testing, security operations, risk management, or compliance, your ability to clearly explain cyber threats and solutions to non-technical stakeholders is vital. This guide will help cyber security job seekers develop one of the most in-demand soft skills in the industry: public speaking. You’ll learn how to simplify complex concepts, structure effective presentations, use storytelling and analogies, and handle common stakeholder questions with confidence.

Cyber Security Jobs Employer Hotlist 2025: 50 UK Companies Actively Hiring Right Now

Bookmark this guide—refreshed every quarter—so you always know who’s really expanding their cyber security teams. Ransomware payouts broke records in 2024, the UK’s new Cyber Security Bill imposed mandatory breach disclosure, and the National Cyber Force’s move to Samlesbury has super‑charged the northern skills market. Result? Demand for security architects, SOC analysts, penetration testers, cloud‑security engineers, threat hunters & GRC specialists is at an all‑time high in 2025. Below you’ll find 50 organisations that have posted UK‑based cyber security vacancies or announced head‑count growth during the past eight weeks. They’re organised into five quick‑scan categories. For every employer you’ll see: Main UK hub Example live or recent vacancy Why it’s worth a look (tech stack, culture, mission) Search any company on CyberSecurityJobs.tech to view current ads, or set a free alert so fresh openings land straight in your inbox.

Return-to-Work Pathways: Relaunch Your Cyber Security Career with Returnships, Flexible & Hybrid Roles

Re-entering the workforce after a career break can feel especially challenging in a fast-moving field like cyber security. Whether you stepped away for parenting, caregiving or another life chapter, the UK’s cyber security sector now offers a range of return-to-work pathways—from structured returnships to flexible and hybrid roles. These programmes value the transferable skills and resilience you’ve developed during your break, pairing you with mentorship, upskilling opportunities and supportive networks to ease your transition back into cyber security. In this article, tailored for parents and carers, you’ll discover how to: Understand the growing demand for cyber security talent in the UK Translate your organisational, communication and problem-solving skills into cyber security roles Tackle common re-entry challenges with practical solutions Refresh your technical knowledge through targeted learning Access returnship and re-entry programmes specific to cyber security Find roles that accommodate family commitments—whether hybrid, flexible or full-time Balance your career relaunch with caring responsibilities Master applications, interviews and networking in cyber security Draw inspiration from real returner success stories Whether you aim to return as an analyst, penetration tester, security engineer or compliance specialist, this guide will equip you with the steps and resources to reignite your cyber security career.