Arctic Research and Development - Product Security Engineer
Requirements
• Time spent in or around regulated, high-assurance, or defence-adjacent settings where security demands are intricate and failure carries real weight • Practical offensive security background — red teaming, penetration testing, or adversarial simulation — that shapes how you think about defensive design and threat modelling • Awareness of security issues unique to AI or machine learning systems, such as model integrity, data pipeline security, or adversarial ML • A hand in building security programmes at scale — security champions networks, secure development lifecycle tooling, or company-wide risk frameworks • A background in cloud-native security engineering, especially across AWS, GCP, or Azure, spanning infrastructure-as-code, container security, and cloud identity patterns • Some exposure to supply chain security issues, such as dependency management, build pipeline integrity, or third-party component assurance • Experience working with classified data, government security frameworks, or cross-domain security requirements
Responsibilities
• Spot, evaluate, and rank security risks across our physical products, systems and infrastructure — separating hypothetical worries from genuine threats to the business • Build and roll out practical security controls across cloud platforms, applications, products, and data, and help engineering teams do likewise • Build and use threat models to catch architectural weak points, trust boundary gaps, and failure modes before they turn into incidents • Own secure-by-design evidence, EN 18031/CRA Annex I assessments, fuzzing/pen-test programmes, the vulnerability register and advisories • Work alongside engineering, product, and operations teams as a trusted security partner — offering patterns, guidance, and guardrails rather than acting as a gatekeeper • Play a part in detecting, investigating, and containing security incidents, and push for lasting fixes based on what we learn • Cut down on manual, reactive security work through automation, better tooling, and secure-by-default habits built into how we develop and run systems • WHAT WE VALUE • Deep, hands-on skill in one or two security domains — application security, cloud security, identity and access management, cryptography, detection and response, or platform security — backed by real evidence of impact • An instinct for trust boundaries, failure modes, blast radius, and attacker behaviour, rather than viewing vulnerabilities in isolation • A knack for turning complex security risk into terms that land with engineers, product managers, and senior leadership alike, and for shaping outcomes through persuasion rather than title • A risk-based approach — weighing decisions proportionately under uncertainty, and always asking whether the work cuts real risk rather than just checking a compliance box • Comfort juggling multiple teams and technical domains at once without losing quality or judgement • A history of finding gaps and pushing security fixes through to completion, even in messy or loosely defined problem spaces
Benefits
• Equity — meaningful options as an early employee at an early-stage company • Private healthcare, dental & optician • Real field exposure — travel to Arctic sites and Outposts when needed (genuinely, not as a gimmick) • Mission-driven culture — focus on impact, not hours logged • Small team, real ownership — what you build matters and ships
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT