Copello Global
Senior Software Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Senior Software Cybersecurity Engineer - Uxbridge or Edinburgh (Hybrid)
The Opportunity
We are looking for a Senior Software Cybersecurity Engineer to join a high-performing security engineering team supporting the development of secure, resilient software and cloud-based products.
This is a hands-on security engineering position. You will work closely with software, cloud and infrastructure engineering teams to identify security risks, implement security controls and embed security throughout the Software Development Life Cycle.
The successful candidate will be comfortable moving between security architecture, threat modelling, secure coding, vulnerability management and DevSecOps, with a proven track record of personally delivering security improvements and implementations.
Key Responsibilities
Security Engineering & Secure Design
- Perform threat modelling, security risk assessments and architecture reviews across software, cloud and containerised environments.
- Identify security vulnerabilities and work with engineering teams to design and implement appropriate mitigations.
- Define security requirements and secure design principles for new and existing products.
- Conduct secure code reviews and provide practical security guidance to software engineering teams.
- Support IAM, cryptography and key-management controls.
- Act as a technical security SME for engineering and compliance stakeholders.
DevSecOps & Security Testing
- Implement and maintain security tooling within CI/CD pipelines.
- Integrate and manage SAST, DAST, SCA, SBOM and secret-scanning capabilities.
- Develop automation and scripts to improve security testing and vulnerability detection.
- Apply manual application and network security testing where required.
- Develop security-focused unit and integration tests to validate security controls.
- Continuously improve secure coding standards, security tooling and DevSecOps processes.
Cloud & Container Security
- Secure cloud environments across AWS, Azure and/or GCP.
- Assess and improve the security of Kubernetes, Docker and containerised workloads.
- Manage the vulnerability lifecycle of container images and cloud workloads.
- Identify security weaknesses across cloud infrastructure and applications and drive remediation.
- Help engineering teams adopt secure-by-design cloud and container architectures.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Vulnerability Management
- Lead the identification, triage and prioritisation of software and infrastructure vulnerabilities.
- Validate security findings and, where appropriate, develop proof-of-concepts to demonstrate exploitability.
- Assess vulnerabilities across applications, APIs, cloud infrastructure and container environments.
- Work directly with engineering teams to manage vulnerabilities through to remediation.
- Track emerging threats and vulnerabilities and assess their relevance to products and technology estates.
Incident Response & Security Improvement
- Support product security incident response and technical investigations.
- Perform root-cause analysis and develop mitigation strategies.
- Produce technical runbooks and contribute to incident response processes.
- Apply detection engineering principles to establish appropriate security baselines and monitoring.
- Conduct post-incident reviews and implement lessons learned.
- Monitor emerging threats and proactively recommend new security controls.
Essential Experience
- 7+ years' experience in software security, application security, product security or security engineering.
- Proven experience personally delivering security implementations, rather than purely providing advisory or governance support.
- Strong experience with Secure SDLC and DevSecOps practices.
- Hands-on experience implementing security tooling such as:
- SAST
- DAST
- SCA
- SBOM
- Secret scanning
- Strong understanding of threat modelling, including STRIDE or equivalent methodologies.
- Experience performing security risk assessments and architecture reviews.
- Strong cloud security experience across AWS, Azure and/or GCP.
- Hands-on experience securing Kubernetes, Docker and containerised environments.
- Experience with vulnerability management, including assessing, validating and prioritising vulnerabilities.
- Strong software engineering experience with Go and/or C#.
- Experience with secure code review and secure software development.
- Strong understanding of IAM, cryptography and key management.
- Good knowledge of HTTP, REST, TLS and TCP/IP.
- Experience working closely with software engineering and development teams.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Security Standards & Frameworks
- Good knowledge of relevant security standards and frameworks, including:
- OWASP
- OWASP ASVS / Testing Guide
- NIS
- TIS ISO 27001
- CIS
Desirable Experience
- Vulnerability research and exploit development.
- Manual penetration testing across cloud, web, embedded or mobile environments.
- Experience writing PoCs to validate vulnerabilities.
- SIEM and security monitoring technologies such as Splunk or OSQuery.
- Detection engineering.
- Embedded or IoT security.
- AI/ML security.
- Distributed systems.
- Experience within a high-growth SaaS or product engineering environment.
- Security certifications such as OSCP, CISSP, CCSP, AWS Security Specialty or GIAC certifications.
- Master's degree in Cybersecurity, Computer Science or a related discipline.
What We're Looking For
We're particularly interested in engineers who can demonstrate real-world ownership of security projects and implementations. You should be able to talk confidently about projects where you have:
- Implemented security tooling into a CI/CD pipeline.
- Built or improved a secure SDLC.
- Performed threat modelling on a real product or application.
- Secured Kubernetes or container environments.
- Discovered and remediated vulnerabilities.
- Conducted security architecture reviews.
- Worked directly with developers to resolve security issues.
- Automated security processes using code or infrastructure-as-code.
- Improved an organisation's security posture through measurable technical change.
This is an opportunity for someone who wants to be hands-on and technically influential, working directly with engineering teams to build security into products rather than simply identifying problems after the fact.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills