Security Engineer
London, England, United Kingdom Full-time Posted 53 minutes ago
Why Conduct
The world's largest companies are slowed down by the software they run on. We're building the AI operating system that absorbs IT complexity and unlocks entirely new levels of speed, output, and ambition. We believe this is a generation-defining mission. Major enterprises already trust us with their most critical systems, we just closed a $60M+ Series A from top-tier funds, and we're still early enough that what you build here defines the company. We're a small, talent-dense team doing our life's work at Conduct - we value extreme ownership, high velocity, and low-ego collaboration. If you bring that same drive, we will make sure this is the place you do yours too.
Who We Hire
We work with some of the largest enterprises in the world, and security is core to earning and keeping that trust. We're looking for someone who takes real ownership of our security posture and genuinely cares about getting it right. This is a builder's role as much as an operator's: you'll design and ship the security features our enterprise customers need, not just run controls and tooling.
You'll stand out if you:
You'll own our security posture end to end: the day-to-day operational work of keeping us secure, the security capabilities our enterprise customers demand, and the bigger initiatives on our security roadmap as we build out the function. This is as much a software engineering role as a security ops one - expect to spend real time in our codebase building features, alongside hands-on investigation, remediation, and shaping how security scales as we grow from 20 to 40+ engineers.
Day to day, you'll:
The world's largest companies are slowed down by the software they run on. We're building the AI operating system that absorbs IT complexity and unlocks entirely new levels of speed, output, and ambition. We believe this is a generation-defining mission. Major enterprises already trust us with their most critical systems, we just closed a $60M+ Series A from top-tier funds, and we're still early enough that what you build here defines the company. We're a small, talent-dense team doing our life's work at Conduct - we value extreme ownership, high velocity, and low-ego collaboration. If you bring that same drive, we will make sure this is the place you do yours too.
Who We Hire
We work with some of the largest enterprises in the world, and security is core to earning and keeping that trust. We're looking for someone who takes real ownership of our security posture and genuinely cares about getting it right. This is a builder's role as much as an operator's: you'll design and ship the security features our enterprise customers need, not just run controls and tooling.
You'll stand out if you:
- Have shipped security features as a software engineer - things like BYOK per tenant, SSO/SCIM, or SIEM-compatible audit logging - not just configured or audited them
- Have hands-on experience with enterprise security requirements - completing security questionnaires, navigating customer requirements around data handling and contractual agreements
- Are confident acting as the technical point of contact for developers, CISOs, and clients during security due diligence conversations
- Bring pragmatic judgement - you know how to balance security rigour against the speed a startup needs to move at
- Are genuinely excited about InfoSec and motivated to keep growing; we're open to less experience if the drive and aptitude are clearly there
You'll own our security posture end to end: the day-to-day operational work of keeping us secure, the security capabilities our enterprise customers demand, and the bigger initiatives on our security roadmap as we build out the function. This is as much a software engineering role as a security ops one - expect to spend real time in our codebase building features, alongside hands-on investigation, remediation, and shaping how security scales as we grow from 20 to 40+ engineers.
Day to day, you'll:
- Design and build security features that ship in our product - like BYOK per tenant, SIEM-compatible audit logs, and SSO/SCIM - working directly in the codebase alongside product engineers
- Own enterprise security end to end - completing customer security questionnaires, working through requirements around data handling and contractual agreements, and acting as the technical point of contact for our clients’ CISOs and security teams
- Monitor and harden our cloud environment - tracking security recommendations, driving remediation, and making pragmatic risk-acceptance calls where they're justified
- Investigate and respond to security alerts across our endpoint, cloud, and application stack
- Build out our detection and monitoring capabilities, evolving our SIEM with alerting that cuts through the noise
- Own vulnerability management end to end - triaging, tracking, and driving issues through to resolution
- Proactively hunt for threats, from unusual behaviour in our environment to emerging risks like package and supply chain compromises
- Run and refine security scanning across our infrastructure, applications, and dependencies
- 3-7 years in a security engineering role
- Background can come from any type of security engineering; what matters most is that you're comfortable reading and writing code - you'll be building product features and tooling, not just operating them
- Experience working with enterprise customers is a plus, not a requirement