Skip to main content

Senior Security Engineer

Licensed sponsor United Kingdom Full-time Posted 1 hour ago

Position Title: Senior Security Engineer

Reports to: VP Engineering

Location: UK, Remote

Contract Type: Full-Time, Permanent

About BibliU

BibliU is an award-winning, technology-led B2B company transforming the $65bn educational content industry. With a 90% CAGR the past 5 years, we are just getting started. We've cracked the code on Day 1 access to affordable digital course materials for students, while delivering comprehensive campus store solutions that foster human relationships, and increase our stickiness in the world of AI.

The result? Measurable impact: 10% higher student retention, 1-point GPA increases, and partnerships with 170 universities serving 600,000 students each year.

We've fundamentally changed how universities procure, distribute, and manage learning content. We partner with 4,000+ publishers, including Pearson, Oxford University Press, and Wiley to deliver content to universities, and provide rich engagement data and interactive tools like quizzes that help students actually learn.

Here's what makes our story compelling

Founded in late 2015 as an Oxford University spin out, we've grown explosively with 90% CAGR over the last five years, including 65% in FY25, reaching $100m in annual revenue. Our Series B raised $23m led by Nesta Impact Investments (with Guinness Asset Management, Stonehage Fleming, and Oxford Sciences Enterprises). In late 2023, we acquired Texas Book Company (now 'BibliU Campus') to become the only fully vertically integrated player in the market, driving US organic growth which now represents 90% of our business.

We're hungry for more. We're actively building our M&A pipeline as we compete head-to-head against legacy bricks-and-mortar providers to improve the faculty and student experience while boosting the financial sustainability of universities.

Our culture is collaborative, high-growth, and agile. You’ll join an experienced and motivated executive team with backgrounds from Instructure (Canvas) and other successful edtech companies with exit experience. We operate as a distributed team across the UK and US, with offices in London.

Position Overview

We're hiring a Security Engineer to own the security posture of our platform and production workloads. This is a hands-on engineering role sitting at the intersection of architecture, engineering and security. You’ll make sure security is designed into systems rather than bolted on afterwards, test whether our security assumptions and controls actually work, and help teams build systems that remain secure and resilient when things go wrong. Your role will include running offensive testing against our own infrastructure.

A significant part of the role is securing how we build and ship AI products. As teams move faster with AI-assisted development, you'll define the sandboxing, isolation, permissions and guardrail patterns that let that happen safely, and tune them as the tooling and threat landscape change.

You'll work in close partnership with Engineering and our AI practice, embedded in design reviews and delivery work rather than reviewing from the outside. Our IT function leads compliance administration, you’ll provide the engineering expertise and technical controls needed to support SOC 2, GDPR and PCI DSS obligations. We value evidence over assumptions - we want to know whether security measures work in practice, not simply whether they exist.

What you will be doing

  • Own the engineering implementation and continuous improvement of security controls supporting SOC 2 Type II, working with IT on evidence collection and external audits
  • Act as the security partner in architecture and design reviews, setting secure-by-default patterns for new services, data flows, and integrations, while making pragmatic trade-offs between risk and delivery
  • Design, propose, and tune sandboxing and isolation models for AI-assisted and AI-generated code, including execution boundaries, secrets handling, permissions, dependency controls, and output validation
  • Own our offensive security testing, combining internal application, cloud and infrastructure testing with third-party penetration testing where useful; test whether important security assumptions actually hold, and verify remediation
  • Maintain and extend our GDPR and PCI DSS control posture, working with Legal, Finance, and Engineering on data mapping, retention, cardholder-data scope, and DPIAs
  • Work with Platform Engineering to tune security tooling and automation across the SDLC: SAST, DAST, dependency and container scanning, IaC policy checks, and CI/CD gates - focussing on high-signal, actionable checks and removing controls or gates that create friction without materially reducing risk
  • Lead threat modelling for high-risk services and AI features, and translate findings into prioritised, actionable engineering work
  • Work with Engineering to improve detection and response capability: logging coverage, alerting quality, runbooks, and participation in incident response
  • Support customer and prospect security reviews, questionnaires, and due diligence with accurate, evidence-backed responses
  • Raise the security baseline across engineering through guidance, tooling, and enablement rather than gatekeeping

What we are looking for

Must have

  • 5+ years in a security engineering, application security, or cloud security role, with meaningful time spent hands-on rather than purely advisory
  • Direct experience operating or contributing to SOC 2 Type II controls in a live environment, not just preparing for an initial audit, but sustaining and evidencing controls over time
  • Practical penetration testing skills: web application, API, and cloud infrastructure testing, with the ability to run assessments internally and validate third-party findings
  • Strong cloud security background (AWS): IAM design, network segmentation, encryption, secrets management, and workload isolation
  • Working knowledge of PCI DSS requirements and how to scope, segment, and evidence a cardholder-data environment
  • Solid grasp of GDPR as it applies to engineering: lawful basis, data minimisation, retention, subject rights, cross-border transfers, and sub-processor management
  • Secure architecture and threat modelling experience across distributed, service-based systems
  • Strong hands-on engineering ability: able to read and reason about application code, write scripts and automation, and integrate security checks into CI/CD
  • Experience securing containerised workloads and infrastructure-as-code (Kubernetes, OpenTofu, or equivalents)
  • Ability to influence engineers and product teams without authority, make pragmatic risk trade-offs rather than absolutist ones, and challenge security controls that create cost or friction without proportionate benefit
  • Clear written communication: you'll be producing control documentation, findings, and customer-facing security responses
  • Experience securing AI/LLM systems: prompt injection, tool-use and agent permissions, model and data exfiltration risks, RAG pipeline security, and evaluation of AI-generated code

Good to have

  • Exposure to ISO 27001, or experience running a multi-framework compliance programme
  • Offensive security certifications (OSCP, OSWE, GWAPT) or equivalent demonstrable experience
  • Detection engineering and SIEM experience, including writing and tuning detections
  • Familiarity with AI security frameworks such as the OWASP Top 10 for LLM Applications, NIST AI RMF, or ISO/IEC 42001
  • Experience in a high-growth SaaS environment, particularly one handling sensitive personal data at scale
  • Background in EdTech, or experience with sector-specific requirements such as accessibility, student data privacy (FERPA), or institutional procurement security reviews
  • Experience using controlled security experiments, incident simulations, chaos engineering, or similar techniques to test how systems behave when assumptions or safeguards fail
  • Prior involvement in incident response for a real production incident, including post-incident review

Benefits

Our benefits are all aimed at supporting a healthy work-life balance and cultivating a company culture where you can bring your whole, human self to work.

Here's what we offer

  • 🌴 35 days holiday per year (excluding public holidays!) - yep, that’s not a typo!
  • 🎂 Your birthday off
  • 🌱 12 scheduled company wellness Fridays off per year
  • ❤️ Enhanced maternity & paternity allowance
  • ⏰ Flexible working hours - we’re a remote team spread across the US and UK
  • 💻 Work-from-home allowance to help you set up your dream WFH station
  • 🚴 Cycle-to-work scheme (UK)
  • 🛟 Life Insurance up to 4 x salary
  • ❤️ Private health insurance
  • 👁️ Annual eye test and up to £100 towards frames for glasses required for DSE work

We strongly encourage candidates of all different backgrounds, experiences and identities to apply. Each new hire is an opportunity for us to bring in a different perspective and BibliU is committed to building an inclusive and supportive workplace where everyone can do rewarding work.

Please note: We do not work with external recruiters/recruitment agencies. This position will be filled directly by BibliU and we kindly request that external recruiters/recruitment agencies refrain from submitting candidates for this role.

Similar sponsor-licensed roles

More roles in United Kingdom with active sponsor licences.