Sepura
Software Security Architect

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role
You will provide the technical leadership that turns security objectives into practical architecture, engineering standards and secure products.
Working throughout the product lifecycle, you will collaborate with engineering teams to ensure security is considered from initial concept and design through development, verification, release and ongoing maintenance.
If you have a strong background in secure device architecture and enjoy combining strategic ownership with hands-on technical influence, this is an opportunity to make a significant impact within an innovative technology company based in Waterbeach, Cambridge.
Due to the nature of our UK customer base, the successful candidate may be expected to complete UK Security Clearance (SC) vetting.
Key Accountabilities
Own product-line software security
- Create and maintain the software security strategy, target state and prioritized roadmap for the product line.
- Be accountable for security architecture decisions and for the consistent application of security requirements across products, platforms and shared components.
- Maintain a product-line view of software security risk, technical debt, dependencies and remediation commitments, escalating material gaps with clear options and recommendations.
- Define what good looks like through measurable controls, assurance evidence and acceptance criteria.
Embed security into delivery
- Integrate security requirements and threat modelling into product planning, architecture, design and backlog refinement.
- Establish proportionate security gates across implementation, code review, build, test, release and maintenance activities.
- Partner with engineering teams to ensure vulnerabilities are triaged, owned and resolved according to risk, with exceptions explicitly documented and approved.
- Ensure security is planned and delivered as part of normal product development rather than treated as a separate compliance activity.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Lead secure architecture and engineering practice
- Provide authoritative guidance on secure design, trust boundaries, identity, authentication, authorization, cryptography, data protection, secure communications and platform hardening.
- Define reusable patterns, reference architectures, coding standards and engineering guardrails that enable teams to deliver securely and efficiently.
- Review significant designs and changes, challenging assumptions and driving decisions to resolution.
- Guide the selection and effective use of security tooling within development and CI/CD workflows.
Assure releases and the product lifecycle
- Define the security evidence required to support release decisions and product assurance.
- Coordinate security testing, vulnerability assessment and remediation across products and releases.
- Ensure software security considerations are addressed through deployment, update, support, incident response and end-of-life activities.
- Provide a clear security position for major releases, including residual risks, approved exceptions and recommended actions.
- Ensure product security architecture, engineering controls and lifecycle processes support compliance with the EU Cyber Resilience Act (CRA).
Influence, govern and improve
- Act as the software security authority for product and engineering stakeholders, translating risk into clear delivery decisions.
- Build security capability across engineering through coaching, design reviews, practical guidance and communities of practice.
- Work with product, systems, quality, compliance and operational stakeholders to align software security with wider product obligations.
- Use lessons from vulnerabilities, incidents, testing and assurance activity to improve standards, controls and engineering practice.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What you need to succeed:
Qualifications
- A relevant technical degree.
Experience and Skills
- Demonstrable experience owning software or product security across multiple teams, products or platforms.
- Strong software architecture and engineering background, with practical experience delivering security controls in complex products.
- Deep understanding of secure development lifecycle practices, threat modelling, secure design, vulnerability management and security testing.
- Experience embedding automated security controls and evidence into build, test and CI/CD workflows.
- Ability to assess technical risk, make proportionate decisions and communicate trade-offs to engineering and business stakeholders.
- Credibility to influence senior technical leaders while remaining hands-on enough to guide teams through difficult design and delivery decisions.
- Clear written and verbal communication, with a pragmatic approach that enables delivery while protecting the organisation and its customers.
Nice to have
- Experience with embedded, connected, mobile or mission-critical products.
- Knowledge of relevant product security standards, regulatory expectations or assurance frameworks.
- Experience of incident response coordinated vulnerability disclosure and security maintenance across supported product versions.
- Relevant security or architecture certification, supported by substantial practical experience.
- Experience of Android and/or Embedded Linux system architecture.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London