One Big Circle Ltd
Product Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Product Security Engineer
One Big Circle – Bristol
Full-Time 37.5 hours, over 5 days (minimum 4 days per week in the office)
£70,000 - £90,000 dependent on experience
About One Big Circle
Be part of an award-winning workplace: The Sunday Times Best Medium-sized Technology Company 2025
Formed in 2017, One Big Circle is a fast-growing Bristol technology company that provides “Intelligent Video” solutions. We focus entirely on solving real-world industry problems by fusing new technology in the field of Video, IOT, Cloud and AI providing end to end solutions which allow our customers to dramatically improve their operational efficiency and safety. Our culture is one of high-quality technical delivery and we work at a speed that many industries are unaccustomed to; we have done this by building a team dynamic that challenges and empowers our people and creating an environment where everyone contributes and learns. We are growing, profitable and have ambitious plans to continue expansion in and beyond our existing markets. We are looking for a proactive and motivated individual to join our team to support the business in further growing our flagship award-winning product: AIVR. AIVR (Automated Intelligent Video Review) is a state-of-the-art video technology system used by thousands of people in the rail industry. AIVR has won dozens of awards and is recognised as the market leading solution, but we are building many more opportunities both in existing and new markets which will further accelerate our growth. We have built a culture where people feel supported, included, and empowered to do their best work. Our team is growing, and we’d love for you to be part of the journey.
Role Summary
We are looking for a senior, hands-on security engineer to own the security of our AIVR product stack end to end. You will spend your time thinking like an attacker, finding weaknesses in our systems before anyone else does, and then coordinating with the engineering teams to remediate. You will pull the architecture apart, work out the realistic attack paths, test them, prove what's exploitable, explain the impact to the engineers who own them, help them work out a sensible fix, and then verify the fix.
This is a technical role in a team that likes getting things done. It is not a compliance or GRC position.
Your job is to make the product secure by continuously scouting for vulnerabilities and red teaming the AIVR product.
What You'll Be Securing
- Edge devices on trains. Embedded Linux devices with cameras and other sensors, fitted to in-service rolling stock. They are remote, physically outside our control, and connect back to us over 4G/5G.
- AWS cloud platform. A comprehensive and complex data processing platform, including serverless and containerised services developed predominantly in Python and hosting 7+ PB of Data.
- Web applications. The AIVR web applications used across the rail industry, with multi-tenant workspaces, sharing tools and integrations.
- Machine learning infrastructure. Training and inference workloads running in a 3rd party datacentre.
Responsibilities
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
- Continuously red team our product stack: threat modelling, penetration testing, code and configuration review, and adversarial thinking applied across devices, cloud, applications and ML infrastructure.
- Highlight findings and their impact. Work with the team that owns the system to explain findings and validate fixes.
- Input into AWS security architecture with the Platform team: IAM, organisation and account structure, networking, encryption, logging and detection.
- Evaluate device-side security with the Device team: secure boot and update signing, credential and certificate lifecycle, remote access, tamper and theft scenarios.
- Harden the software supply chain: dependency and container vulnerability management, SBOMs, CI/CD pipeline integrity, and CVE exposure.
- Build security into the way we ship: static and dynamic analysis, IaC and container scanning, secrets detection, and secure coding guidance that engineers will actually use.
- Improve detection and response: make sure the right things are logged and alerted on and contribute hands-on when there is an incident. Incident response here is an all-hands affair; depending on the incident you may lead it or support whoever does.
- Scope, run and challenge third party penetration tests, and triage reports that arrive through our vulnerability disclosure policy.
- Document what you find and what you change in clear technical writing that engineers can act on and that feeds naturally into our ISO 27001 evidence and customer security assurance, without you having to run that process.
- Raise the bar across the team through code review, threat modelling sessions and mentoring, so that security knowledge spreads rather than bottlenecking on you
We want someone who is comfortable ranging across cloud, embedded, web and infrastructure in a single week. Nobody will have depth in every area below; we would rather have real depth in two or three and the curiosity to pick up the rest.
Essentials
- Substantial hands-on security engineering experience (five or more years) in teams that ship software, with a strong offensive mindset.
- Real software engineering ability. Comfortable in Python, and able to read and reason about C/C++ and JavaScript/TypeScript.
- Deep, practical AWS security knowledge: IAM and Organizations, S3, VPC networking, CloudTrail, and infrastructure as code.
- Strong Linux fundamentals, on both servers and embedded devices.
- The ability to explain risk to developers, prioritise pragmatically, and be persistent when it matters.
Capability Areas
These describe the kinds of problems you will work on.
Cloud & Platform Security
AWS IAM design and review, permissions, SSO, credentials, secrets management, account segmentation, VPC and network controls, S3 data protection at scale, WAF, container and serverless security, infrastructure as code, CI/CD security, ransomware resilience and recovery testing.
Edge Device & Embedded Security
Embedded Linux hardening (Yocto or similar), secure boot, over-the-air updates, disk encryption, device identity and PKI, certificate lifecycle, VPN and remote access design, cellular connectivity, edge API security, physical attack and tamper scenarios, firmware analysis, OT security principles, secure device provisioning and decommissioning.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Application Security
OWASP Top 10 and beyond, authentication and session management, authorisation and multi-tenant isolation, API security, share link and token design, secure code review, browser security controls,SSO/OIDC integration.
Supply Chain & ML Infrastructure
Dependency and container vulnerability management, SBOM generation and tracking, CVE triage and prioritisation, artifact signing and provenance, pipeline integrity, datacentre network segmentation, ML framework exposure, data flows between datacentre and cloud.
Detection & Response
Logging strategy, alerting and SIEM concepts, threat hunting, incident response, forensics fundamentals, tabletop exercises, backup and recovery testing.
Nice to Have
- Certifications such as OSCP, OSWE, CRTO or AWS Certified Security Specialty are welcome, but we care far more about demonstrable work than certifications.
- Experience in rail, transport, utilities or other national infrastructure, and familiarity with the NCSC Cyber Assessment Framework, NIS regulations, ISO 27001 or IEC 62443.
- Public evidence of your craft: CVEs, write-ups, open source tooling, bug bounty history or conference talks.
Personal Attributes
- Curious and persistent: you enjoy working out how something can be made to misbehave.
- Practical and delivery-focused, balancing security rigour with the reality of a relatively small team shipping frequent product updates.
- Direct and constructive: you can tell an engineer their design is broken in a way that makes them want to fix it with you.
- Self-motivated, comfortable owning an area without close supervision, and happy to flex across responsibilities in a growing company.
- Strong written communication, able to produce findings and documentation that stand on their own.
Company Benefits Include:
- Auto enrolment Pension Scheme
- 25 Days Holiday plus bank holidays
- Life Assurance
- Private Healthcare Cover
- Work related training courses as required
- Complimentary snacks and refreshments including fresh fruit
- Office-Centric role
- Access to Bike to Work Scheme
- Secure bike storage and shower facilities
- Social events
How to Apply
Join an award-winning team, named ‘The Sunday Times Best Medium-sized Technology Company 2025’. At One Big Circle, you’ll be part of a fast-growing team where your ideas and contributions are truly valued.
Please send your CV and covering letter to jobs@onebigcircle.co.uk
Please visit our careers page at onebigcircle.co.uk/careers to view our full list of current vacancies, including similar roles that may be of interest.
By applying for this role, you understand that we will process your personal information in accordance with our privacy policy, accessible at https://onebigcircle.co.uk/privacy-policy/
Successful applicants will be required to pass a BPSS (Baseline Personnel Security Standard) check.
Find out more about us at www.onebigcircle.co.uk
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London