Principal Product Security Engineer

Posted 4 Days Ago
Be an Early Applicant
London, England, GBR
Hybrid
Entry level
Insurance • Cybersecurity
The Role
Lead the strategy and hands-on delivery of product security across cloud platforms, applications, code, and CI/CD pipelines. Build and operate security tooling, secure software supply chains, develop policy-as-code controls, lead threat modeling, and create reusable secure-by-default patterns. Diagnose vulnerabilities, improve remediation, measure control effectiveness, and establish safeguards for AI-assisted and agentic engineering workflows. Serve as a principal technical authority while advising stakeholders and coaching engineering teams.
Summary Generated by Built In
At CFC, technology is at the heart of everything we do. We are looking for a Principal Product Security Engineer to lead the strategy and hands-on delivery of security across cloud platforms, code and CI/CD pipelines. 

This is a lead individual contributor role for an engineer who solves unique, high-impact problems, advises across disciplines and helps shape functional strategy. You will lead the build and operation of the product-security toolchain, create secure-by-default patterns and influence how security is embedded across engineering. 
You will also help CFC adopt AI-assisted and agentic product engineering safely. As these practices develop, you will use proportionate guardrails, controlled experimentation and evidence-led assurance rather than assume settled industry practice.

About the role
  • Design, implement and operate the product-security toolchain across source control, CI/CD, cloud and runtime environments 
  • Integrate and tune code, dependency, secrets, infrastructure-as-code, container and cloud security testing 
  •  Build policy-as-code, pipeline controls and automation that prevent material weaknesses reaching production 
  • Secure the software supply chain through trusted dependencies, SBOMs, artefact signing, provenance and workload identity 
  • Lead threat modelling and security design reviews for complex products and platforms 
  • Diagnose vulnerabilities and misconfigurations, reduce false positives and work directly with engineers on prevention, remediation and recoverability
  • Create reusable secure cloud, application and pipeline patterns that engineering teams can adopt by default 
  • Define and test guardrails for AI-assisted coding and agentic workflows, including identity, delegated authority, data, tools and auditability 
  • Measure security coverage, control effectiveness, developer experience and remediation velocity
  • Act as a senior technical authority, advising stakeholders and coaching engineers setting the standard for security and data protection excellence across the wider technology organisation

About you
We are interested in engineers who combine principal-level judgement with sustained hands-on delivery. You'll likely bring: 
  • Deep experience in product, application, cloud and DevOps security 
  • Proven experience implementing security tooling in production engineering environments 
  • Strong knowledge of CI/CD, cloud-native architecture, Infrastructure as Code and software supply-chain security 
  • Practical experience with application testing, dependency analysis, secrets detection, container and cloud posture tooling 
  • Ability to write maintainable code, scripts, integrations and policy-as-code 
  • Experience leading threat modelling and resolving complex security design trade-offs 
  • Ability to assess emerging AI and agentic engineering practices pragmatically and establish proportionate controls 
  • Ability to influence senior technical and non-technical stakeholders through evidence and technical credibility 


Core Values
Love what you do:
We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.
Challenge everything:
We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.
Have fun, be good:
Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.

About
CFC is a specialist insurance provider, pioneering emerging risk and market leader in cyber. Our global insurance platform uses cutting-edge technology and data science to deliver smarter, faster underwriting and protect customers from today's most critical business risk.Headquartered in London with offices in New York, Melbourne, Sydney, Austin, Madrid, Brussels and Brisbane, CFC has over 1200 staff and is trusted by more than 100,000 businesses across 90 countries.At CFC, insurance isn't just about underwriting. From data science to software development, and digital marketing design, we've got something for everyone. We're passionate about pushing boundaries, thinking differently and building the insurance company of the future.CFC is committed to the principles of equal opportunities and creating an environment in which all individuals are always treated with dignity and respect. We encourage a diverse corporate culture of openness and appreciation to create an environment in which your talent can be developed in the best possible way. Should you require any reasonable adjustments at any stage of the recruitment process please let us know.Feeling like you need to tick every box before applying? We see things differently. In a rapidly scaling company like ours, ambition and the drive to learn count for more than a 'perfect' checklist. We're building the future of insurance, and that requires diverse talent eager to grow with us. If this role excites you and you're ready to make a significant impact, bring your unique background and let's build something great together.

Skills Required

  • Deep experience in product, application, cloud, and DevOps security
  • Experience implementing security tooling in production engineering environments
  • Strong knowledge of CI/CD, cloud-native architecture, Infrastructure as Code, and software supply-chain security
  • Practical experience with application testing, dependency analysis, secrets detection, container security, and cloud posture tooling
  • Ability to write maintainable code, scripts, integrations, and policy-as-code
  • Experience leading threat modeling and resolving complex security design trade-offs
  • Ability to assess emerging AI and agentic engineering practices and establish proportionate controls
  • Ability to influence senior technical and non-technical stakeholders through evidence and technical credibility

CFC Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CFC and has not been reviewed or approved by CFC.

  • Strong & Reliable Incentives — Variable pay is positioned as a core part of total compensation, with a group‑wide annual bonus highlighted as a consistent feature. Expanding employee share ownership is described as enhancing overall rewards alongside bonuses.
  • Healthcare Strength — Private medical insurance is provided, complemented by dental and optical cashback and a 24/7 employee assistance programme. These elements indicate comprehensive health coverage beyond standard medical plans.
  • Leave & Time Off Breadth — Time away provisions include 25 days of holiday and paid volunteer time, signaling a broad approach to time off. Additional practices such as company social events support overall work–life rhythm, though they are not leave per se.

CFC Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
Year Founded: 1999

What We Do

CFC is a specialist insurance provider, pioneer in emerging risk and market leader in cyber. Their global insurance platform uses cutting-edge technology and data science to deliver smarter, faster underwriting and protect customers from today’s most critical business risks.

Similar Jobs

General Dynamics Mission Systems Logo General Dynamics Mission Systems

Security Engineer

Aerospace • Security • Software
Hybrid
Hastings, East Sussex, England, GBR
8438 Employees
59K-80K Annually

Groundwater Modelling Decision Support Initiative (GMDSI) Logo Groundwater Modelling Decision Support Initiative (GMDSI)

Security Engineer

Greentech • Professional Services • Software • Analytics
Hybrid
Hastings, East Sussex, England, GBR
12000 Employees
59K-80K Annually
In-Office or Remote
2 Locations
187 Employees
80K-120K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account