CFC Logo

CFC

Principal Product Security Engineer

Posted 8 Days Ago
Be an Early Applicant
Hybrid
London, England, GBR
Entry level
Hybrid
London, England, GBR
Entry level
Lead the strategy and hands-on delivery of product security across cloud platforms, applications, code, and CI/CD pipelines. Build and operate security tooling, secure software supply chains, develop policy-as-code controls, lead threat modeling, and create reusable secure-by-default patterns. Diagnose vulnerabilities, improve remediation, measure control effectiveness, and establish safeguards for AI-assisted and agentic engineering workflows. Serve as a principal technical authority while advising stakeholders and coaching engineering teams.
The summary above was generated by AI
At CFC, technology is at the heart of everything we do. We are looking for a Principal Product Security Engineer to lead the strategy and hands-on delivery of security across cloud platforms, code and CI/CD pipelines. 

This is a lead individual contributor role for an engineer who solves unique, high-impact problems, advises across disciplines and helps shape functional strategy. You will lead the build and operation of the product-security toolchain, create secure-by-default patterns and influence how security is embedded across engineering. 
You will also help CFC adopt AI-assisted and agentic product engineering safely. As these practices develop, you will use proportionate guardrails, controlled experimentation and evidence-led assurance rather than assume settled industry practice.

About the role
  • Design, implement and operate the product-security toolchain across source control, CI/CD, cloud and runtime environments 
  • Integrate and tune code, dependency, secrets, infrastructure-as-code, container and cloud security testing 
  •  Build policy-as-code, pipeline controls and automation that prevent material weaknesses reaching production 
  • Secure the software supply chain through trusted dependencies, SBOMs, artefact signing, provenance and workload identity 
  • Lead threat modelling and security design reviews for complex products and platforms 
  • Diagnose vulnerabilities and misconfigurations, reduce false positives and work directly with engineers on prevention, remediation and recoverability
  • Create reusable secure cloud, application and pipeline patterns that engineering teams can adopt by default 
  • Define and test guardrails for AI-assisted coding and agentic workflows, including identity, delegated authority, data, tools and auditability 
  • Measure security coverage, control effectiveness, developer experience and remediation velocity
  • Act as a senior technical authority, advising stakeholders and coaching engineers setting the standard for security and data protection excellence across the wider technology organisation

About you
We are interested in engineers who combine principal-level judgement with sustained hands-on delivery. You'll likely bring: 
  • Deep experience in product, application, cloud and DevOps security 
  • Proven experience implementing security tooling in production engineering environments 
  • Strong knowledge of CI/CD, cloud-native architecture, Infrastructure as Code and software supply-chain security 
  • Practical experience with application testing, dependency analysis, secrets detection, container and cloud posture tooling 
  • Ability to write maintainable code, scripts, integrations and policy-as-code 
  • Experience leading threat modelling and resolving complex security design trade-offs 
  • Ability to assess emerging AI and agentic engineering practices pragmatically and establish proportionate controls 
  • Ability to influence senior technical and non-technical stakeholders through evidence and technical credibility 


Core Values
Love what you do:
We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.
Challenge everything:
We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.
Have fun, be good:
Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.

About
CFC is a specialist insurance provider, pioneering emerging risk and market leader in cyber. Our global insurance platform uses cutting-edge technology and data science to deliver smarter, faster underwriting and protect customers from today's most critical business risk.Headquartered in London with offices in New York, Melbourne, Sydney, Austin, Madrid, Brussels and Brisbane, CFC has over 1200 staff and is trusted by more than 100,000 businesses across 90 countries.At CFC, insurance isn't just about underwriting. From data science to software development, and digital marketing design, we've got something for everyone. We're passionate about pushing boundaries, thinking differently and building the insurance company of the future.CFC is committed to the principles of equal opportunities and creating an environment in which all individuals are always treated with dignity and respect. We encourage a diverse corporate culture of openness and appreciation to create an environment in which your talent can be developed in the best possible way. Should you require any reasonable adjustments at any stage of the recruitment process please let us know.Feeling like you need to tick every box before applying? We see things differently. In a rapidly scaling company like ours, ambition and the drive to learn count for more than a 'perfect' checklist. We're building the future of insurance, and that requires diverse talent eager to grow with us. If this role excites you and you're ready to make a significant impact, bring your unique background and let's build something great together.
HQ

CFC London, England Office

London, United Kingdom

Similar Jobs

9 Days Ago
Hybrid
Expert/Leader
Expert/Leader
Aerospace • Security • Software
Leads product and systems security engineering for complex, safety-critical airborne mission systems within the GCAP defence programme. Responsibilities include owning security architecture, defining secure-by-design strategies and requirements, leading threat modelling and vulnerability analysis, assessing risks, supporting accreditation, reviewing security evidence, advising multidisciplinary engineering teams, engaging customers and assurance stakeholders, and coaching security engineers. The role requires technical authority in defence or other regulated, safety-critical environments.
Top Skills: Ai/MlCryptographyModel-Based Systems Engineering (Mbse)Requirements Management Tools
Expert/Leader
Greentech • Professional Services • Software • Analytics
Leads product and systems security engineering for complex, safety-critical airborne mission systems. Responsibilities include owning security architecture, defining secure-by-design strategies and requirements, leading threat modeling and risk assessments, guiding accreditation activities, advising multidisciplinary engineering teams, reviewing security evidence, engaging assurance stakeholders, and coaching security engineers across a major defence programme.
Top Skills: Ai/Ml ModelsCryptographyDigital EngineeringEmbedded SystemsModel-Based Systems EngineeringRequirements-Management ToolsThreat ModelingVulnerability Analysis
29 Days Ago
In-Office or Remote
London, Greater London, England, GBR
Senior level
Senior level
Software
Own Pigment’s product, infrastructure, and CI/CD security roadmap as a hands-on technical leader. Responsibilities include threat modeling, secure architecture and code reviews, vulnerability management, assurance testing, detection engineering, incident response, and secure SDLC guidance. The role partners closely with product, engineering, and SRE teams, designs security for AI features and agent identities, strengthens least privilege, and builds automation across cloud and production environments.
Top Skills: .Net CoreArgocdC#CircleCICloudflare ZtnaDatadogFalcoGCPGitGoGoogle WorkspaceHackeroneHashicorp VaultHibobJumpcloudJwtKubernetesMcp ServerOauthOidcOktaPostgresPythonReactRiotSastScaSinglestoreSlackTerraformTrufflehogTypescriptVantaWiz

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account