- Location
- UK - London
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Source
- Pinpoint
Description
Principal Product Security Engineer
Department: CISO
Employment Type: Permanent - Full Time
Location: UK - London
Reporting To: CISO
Description
This is a lead individual contributor role for an engineer who solves unique, high-impact problems, advises across disciplines and helps shape functional strategy. You will lead the build and operation of the product-security toolchain, create secure-by-default patterns and influence how security is embedded across engineering.
About the role
- Design, implement and operate the product-security toolchain across source control, CI/CD, cloud and runtime environments
- Integrate and tune code, dependency, secrets, infrastructure-as-code, container and cloud security testing
- Build policy-as-code, pipeline controls and automation that prevent material weaknesses reaching production
- Secure the software supply chain through trusted dependencies, SBOMs, artefact signing, provenance and workload identity
- Lead threat modelling and security design reviews for complex products and platforms
- Diagnose vulnerabilities and misconfigurations, reduce false positives and work directly with engineers on prevention, remediation and recoverability
- Create reusable secure cloud, application and pipeline patterns that engineering teams can adopt by default
- Define and test guardrails for AI-assisted coding and agentic workflows, including identity, delegated authority, data, tools and auditability
- Measure security coverage, control effectiveness, developer experience and remediation velocity
- Act as a senior technical authority, advising stakeholders and coaching engineers setting the standard for security and data protection excellence across the wider technology organisation
About you
- Deep experience in product, application, cloud and DevOps security
- Proven experience implementing security tooling in production engineering environments
- Strong knowledge of CI/CD, cloud-native architecture, Infrastructure as Code and software supply-chain security
- Practical experience with application testing, dependency analysis, secrets detection, container and cloud posture tooling
- Ability to write maintainable code, scripts, integrations and policy-as-code
- Experience leading threat modelling and resolving complex security design trade-offs
- Ability to assess emerging AI and agentic engineering practices pragmatically and establish proportionate controls
- Ability to influence senior technical and non-technical stakeholders through evidence and technical credibility
Core Values
We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.
Challenge everything:
We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.
Have fun, be good:
Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.