Rodeo
Get started

Nothing

Senior Engineer, Software Security

London
Posted about 16 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About Nothing

Nothing exists to make tech feel exciting again.

We’re building a different kind of technology company, one that puts design, emotion, and human creativity at the heart of everything we do. From the way our products look and feel to how we communicate and show up in culture, we believe technology should make you feel something.

Founded in London in 2020, we’ve grown from idea to global challenger in just a few years. Backed by GV (Google Ventures), EQT Ventures, and C Ventures, and investors like Tony Fadell (iPod), Casey Neistat, and Kevin Lin (Twitch), we’re now sold in 40+ markets with millions of users worldwide.

About the Team

Nothing builds phones, audio products and an operating system used by millions of people. Behind all of it sits Technology & Data in London: the backend services, cloud platforms and data infrastructure that make our products work. That stack runs across cloud platforms such as AWS, GCP, Azure, and various other global hyperscalers. You'll be the engineer who defines how we secure the stack. Standards, tooling, strategies, tactics, architecture: you set them, and the hard part is doing it without slowing anyone down.

What You'll Do

  • Own security lifecycle and secure architecture for Nothing's backend services and cloud platforms, from first design to live operations across all our CI/CD pipelines
  • Define our secure development standards and wire SAST, DAST and SBOM tooling into how we ship.
  • Own vulnerability management end to end: find issues, triage findings, and drive engineering teams to closure.
  • Design our security testing, from penetration testing to fuzzing, and build tools other engineers can run without you.
  • Ship network and server-side and data protection: API security, WAF, gateways, runtime defences, encryption in transit and at rest.
  • Partner with our mobile, OS and desktop teams on client-side security tactics and strategy.
  • Collaborate with our privacy and legal functions to help us engineer solutions to our global regulatory requirements focusing on emergent technologies such as AI
  • Lead threat modelling across authentication, data protection and input handling. Use AI and LLMs to simulate attacks before they happen, then collaborate with the various teams to build the defences.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What We're Looking For

  • 6+ years in application security, including security architecture you've designed for commercial products and services and have managed the posture of ongoing production.
  • Deep threat modelling expertise. You can define the methodology for a company, not just follow one.
  • Hands-on cloud security across AWS, GCP, Azure, and other global hyperscalers. You've secured backend services at real scale and depth of complexity.
  • Command of the secure SDLC: SAST, DAST, SBOM and the judgement to know which findings matter.
  • Experience applying AI or LLMs to security: simulating threats, probing defences, building countermeasures.
  • Solid cryptography and identity fundamentals, including TLS, OAuth 2.0, SSO and token management. You write production-quality code in Python, Go, Java, and C++.
  • You own a domain end to end, hold a high bar, and cut through ambiguity, whether the person across the table is an engineer or a lawyer.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

How We Work

  • Location: London (Kings Cross & Farringdon offices)
  • Working Pattern: Full-time in our London office, five days a week. Occasional home working for personal needs is fine, but this isn't a hybrid role.
  • Commute: We ask that you live within a 60-minute commute of your office.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this