Principal Security Engineer
Orgvue is an organisational design and planning platform that empowers your business to transform its workforce by understanding the work people do and the skills they have. Our platform connects strategy to structure, providing clarity of vision, so you can build a more adaptable, better performing organisation that thrives in a constantly changing world of work.
The world’s largest and best-known enterprises and consulting firms use Orgvue to visualise and model current and future states of the organisation and make faster, more informed decisions. The company is headquartered in London, with offices in Philadelphia, The Hague, Toronto, and Sydney.
Role
The Principal Security Engineer is a strategic, hands-on leader responsible for evaluating, evolving, and executing Orgvue’s security engineering strategy across our entire application development and cloud-hosting estate. Partnering closely with Information Security, Engineering, and Product teams, you will embed secure-by-design principles throughout the software-development lifecycle (SDLC), champion modern DevSecOps practices, and ensure that security is a first-class citizen in everything we build and operate.
This role reports directly to the Chief Technology Officer (CTO) and maintains a dotted-line relationship with the VP of TechOps.
Responsibilities
- Security Strategy & Governance – Define and continuously refine the technical security roadmap that aligns with business objectives, industry best practice (e.g., NIST CSF, OWASP SAMM), and compliance frameworks (SOC 2, ISO 27001, GDPR).
- Secure SDLC & DevSecOps – Build and maintain guardrails for static/dynamic analysis, container and IaC scanning, SBOM management, and supply-chain security; automate enforcement through CI/CD pipelines.
- Cloud & Infrastructure Security – Design and implement robust controls for AWS (primary) and Azure/GCP (secondary): IAM, network segmentation, KMS, secrets management, WAF, EDR, and zero-trust patterns.
- Identity & Access Management (IAM) – Own enterprise IAM strategy, including RBAC, least-privilege provisioning, SSO, federation (OIDC/SAML), and privileged-access workflows.
- Monitoring, Detection & Response – Define audit logging, metrics, and telemetry requirements; integrate with SIEM/SOAR to deliver actionable alerts and playbooks for engineering-led incident response.
- Threat Modeling & Risk Assessment – Conduct regular architecture and code-level reviews, drive remediation plans, and present risk posture to leadership.
- Tooling & Automation – Evaluate, select, and integrate security tooling (SAST, DAST, SCA, container scanners, CSPM, CWPP) and champion IaC/Terraform modules for reusable controls.
- Collaboration & Mentorship – Act as a trusted advisor to engineering squads, provide security training, and mentor senior engineers on emerging attack vectors and defensive techniques.
- Compliance & Audits – Partner with InfoSec and Legal to prepare evidence, manage technical controls, and remediate audit findings.
- InfoSec Partnership – Collaborate proactively with the Information Security team on policy development, threat intelligence sharing, incident response, and compliance initiatives, ensuring organisation-wide alignment.
- Engineering Partnership & Enablement – Work hand-in-hand with engineering squads to raise security awareness, improve secure coding practices, and foster a culture of shared security ownership.
- Architecture Alignment – Partner closely with Orgvue’s Principal Architect to ensure security patterns, controls, and roadmaps align with overall system architecture and future technical strategy.
We are unable to offer Sponsorship for this position and are we not engaging with agencies.
Requirements
- Extensive experience in security engineering and/or software engineering with a strong security focus, including demonstrated leadership of complex security initiatives
- Expert-level knowledge of at least one major cloud platform (AWS preferred) and its native security services.
- Proven success embedding security within modern microservice, container, and serverless architectures.
- Proficiency with Infrastructure-as-Code (Terraform, CloudFormation) and Kubernetes security hardening (admission controllers, network policies).
- Strong understanding of and practical experience of software engineering and how security can be an enabler to success as an engineer.
- Experience working within high-sensitivity data environments
- Strong awareness of compliance standards and the requirements on software teams, especially for ISO27001 and SOC2. FedRAMP experience advantageous.
- Demonstrated experience performing threat modelling, penetration test scoping, and vulnerability management.
- Deep understanding of IAM concepts, encryption/key-management, and secure network design.
- Excellent communication skills with ability to translate technical risk to non-technical stakeholders.
Preferred, but not essential
- Certifications such as CISSP, CSSLP, AWS Certified Security.
- Familiarity with data privacy controls (tokenization, field-level encryption, data mesh).
- Experience implementing security and governance programs for emergent AI tooling and capabilities.
Benefits
- Hybrid working - 1+ days a week in the London office
- Wellbeing: Sanctus Coaching, Virtual fitness sessions, Wellbeing webinars, Annual Wellbeing day
- Subsidised Gym Membership
- Private Medical Insurance (including Dental and Vision) and Life Assurance
- 25 days holiday (increasing to 30 days at a rate of 1 extra day per year)
- Summer Fridays (half-day Fridays for the months of July and August)
- Employer pension contribution of 5% of your gross salary, if you contribute a minimum of 3%
- Season ticket Loan
- Cycle to Work Scheme
- Annual Discretionary Bonus
'Here at Orgvue we promote individualism and a diverse workforce to build on our future success'
Recommended Jobs
Junior Sys Admin / Developer
Junior Sys Admin / Developer Quant Capital is urgently looking for a Junior Sys Admin / Developer to join our high profile client. Our client is the leading provider of advisory, anal…
Organic Creative Lead
About Uncovered Uncovered is a London based social first creative agency founded in 2017. Social sits at the heart of everything that we do. From strategy to production, our team is fluent i…
Group Finance Income Manager
Own the management of all financial aspects of service charge, ensuring accuracy, compliance and efficiency Act as a strategic advisor to service charge teams, offering dedicated business partneri…
Construction Lawyer
THE FIRM A West End law firm THE ROLE Construction lawyer 5-6PQE with England and Wales jurisdiction non-contentious previous experience; ABOUT YOU Ideal candidates will have good organisationa…
Senior Quantity Surveyor
Senior Quantity Surveyor RC Frame/Groundworks London £80k-£100k About the Client: Our client is a specialist subcontractor undertaking RC Frame/Groundworks schemes. Built on decades of experience a…
Temporary Finance Manager!
&##127775; Join Our Team as a Finance Manager! &##127775; Are you a passionate finance professional looking for a new opportunity? We are seeking a dedicated Finance Manager to support our charity's…
Electrical Tester (Berlin, Germany)
The On-Site Group Global are looking for Electrical Testers for a project in Frankfurt, Germany starting ASAP. Applicants must have a passport that allows them to work in Europe- UK passports no lo…
Personal Assistant
What’s the role about? We are currently recruiting for a highly organised and proactive Personal Assistant to support our Womenswear Director, Trading Director and senior leadership team across th…
Venture Capital Partner / Legal Director
Job Details Join a top 50 law firm who have increased profits and turnover each year over the last 4 years and made strong strategic decisions assisting growth Venture Capital Partner / Legal D…
Revit Technician - CAD + Revit Building Structures
Structural Revit/CAD technician Permanent London £42,000 + 10% pension + Benefits This consultancy based in London are urgently seeking an experienced revit technician on a permanent basis.…