NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United Kingdom
28 days ago
Apply with autofill
Apply with autofill
RE
Renesas Electronics·28 days ago
28 days ago

Staff Product Security Engineer

Cambridge, United KingdomFull-timeSenior · 8-12 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at Renesas Electronics

How you compare FREE

?
Your scoreYour score: not yet known
→
45
Top 10%Top 10%: 45 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United Kingdom.

Must-have skills for this role

  • application security
  • product security
  • web application security
  • threat modeling

PDF or DOCX · no account needed

Apply faster with autofill FREERenesas Electronics uses SmartRecruiters - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Building and executing security regression testing
  • Driving threat modeling across existing and new functionality
  • Conducting targeted offensive security activities (Red Team–style testing)
  • Identifying real vulnerabilities based on a deep understanding of our platform and the OWASP Top 10 Web Application Security Risks
  • Design and maintain security regression test suites covering critical application flows
  • Integrate security regression into CI/CD pipelines
  • Lead structured threat modeling sessions for existing system components and new features
  • Perform manual and automated security testing simulating real attacker behavior
  • Continuously assess the platform against OWASP Top 10 categories
  • Review new features and changes for security risks
  • Work closely with Engineering, Architecture, and SRE / Platform teams

What they're looking for

  • 5+ years in Application / Product Security
  • Bachelor's Degree or equivalent of 12 years of work experience
  • Strong hands-on experience in: Web application security testing, API security, Threat modeling methodologies
  • Deep understanding of OWASP Top 10
  • Experience with: Manual penetration testing, Security regression testing, CI/CD security integration
  • Ability to identify business logic vulnerabilities
  • Strong understanding of: Authentication, authorization, and session management, Multi-tenant architectures, Cloud-native systems

Nice to have

  • Experience in SaaS / multi-tenant platforms
  • Familiarity with: Bug bounty programs, Red teaming, Security automation frameworks
  • Knowledge of: AWS, Identity systems and federation (SSO, MFA)
  • Background in software engineering (ability to read/write code)

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Job Description

Why A365 Software Engineering?

Build the cloud platform that’s transforming electronics design. Altium 365 for cloud lets design engineers communicate, collaborate and bring their ideas to market more efficiently than any platform in the industry.

 

We are looking for a Senior Product Security Engineer to extend our Product Security capability with a strong focus on continuous vulnerability discovery and prevention.

This role is responsible for:

  • Building and executing security regression testing
  • Driving threat modeling across existing and new functionality
  • Conducting targeted offensive security activities (Red Team–style testing)
  • Identifying real vulnerabilities based on a deep understanding of our platform and the OWASP Top 10 Web Application Security Risks

The goal is simple: ensure that both existing functionality and new changes remain secure over time, and that real vulnerabilities are discovered before customers do.

 

Key Responsibilities

  • Security Regression Testing
    • Design and maintain security regression test suites covering critical application flows
    • Ensure vulnerabilities, once fixed, are permanently prevented from recurring
    • Integrate security regression into CI/CD pipelines
    • Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
  • Threat Modeling
    • Lead structured threat modeling sessions for:
      • Existing system components
      • New features and architectural changes
    • Identify attack surfaces, abuse cases, and trust boundaries
    • Translate threats into:
      • Test cases
      • Security requirements
      • Mitigation plans
    • Ensure threat modeling becomes a continuous lifecycle activity
  • Offensive Security / Red Team Activities
    • Perform manual and automated security testing simulating real attacker behavior
    • Focus on high-impact vulnerabilities, not theoretical findings
    • Validate exploitability and business impact
    • Partner with engineering teams to:
      • Reproduce issues
      • Prioritize fixes
      • Validate remediation
  • OWASP Top 10–Driven Vulnerability Discovery
    • Continuously assess the platform against OWASP Top 10 categories
    • Use deep product knowledge to find non-obvious, context-specific vulnerabilities
    • Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
  • Security Assurance for Product Changes
    • Review new features and changes for security risks
    • Ensure all changes are:
      • Threat-modeled
      • Covered by regression tests
    • Act as a security gatekeeper without becoming a bottleneck:
      • Enable teams with guidance and tooling
      • Avoid heavy process overhead
  • Collaboration & Enablement
    • Work closely with:
      • Engineering teams
      • Architecture
      • SRE / Platform teams
    • Contribute to secure-by-design practices
    • Support developers in understanding and fixing vulnerabilities
    • Help scale security through:
      • Reusable patterns
      • Automation
      • Security guidance

Qualifications

Required Qualifications

  • 5+ years in Application / Product Security
  • Bachelor's Degree or equivalent of 12 years of work experience 
  • Strong hands-on experience in:
    • Web application security testing
    • API security
    • Threat modeling methodologies
  • Deep understanding of OWASP Top 10
  • Experience with:
    • Manual penetration testing
    • Security regression testing
    • CI/CD security integration
  • Ability to identify business logic vulnerabilities
  • Strong understanding of:
    • Authentication, authorization, and session management
    • Multi-tenant architectures
    • Cloud-native systems

Preferred Qualifications

  • Experience in SaaS / multi-tenant platforms
  • Familiarity with:
    • Bug bounty programs
    • Red teaming
    • Security automation frameworks
  • Knowledge of:
    • AWS
    • Identity systems and federation (SSO, MFA)
  • Background in software engineering (ability to read/write code)

 

Additional Information

Altium Limited, a part of the Renesas Group and headquartered in San Diego, California, is a global software company accelerating the pace of electronics innovation. We are redefining electronic product creation in a software-defined world with our industry-first cloud-based platform that unites every stakeholder and phase of electronics development.

From startups to world’s technology giants, our digital platforms give more power to PCB designers, supply chain, and manufacturing, letting them collaborate as never before. At Altium, our teams are empowered to innovate, collaborate globally, and help create the future of electronics development.

We believe in rewarding our employees with a competitive benefits package alongside their salary. More information will be provided during the hiring process.

Company

RE
Renesas Electronics
Cambridge, United Kingdom

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Renesas Electronics's careers site·first seen 22 Sept 2026·last verified 22 Sept 2026·How we source jobs

Similar jobs

  • Senior Security Engineer - Detection & Response at KlaviyoLondon, United Kingdom–match not yet calculated
  • Security Engineer (Contractor) at gdmsiOakdale, United Kingdom–match not yet calculated
  • Senior AI Compliance, Risk & Security Engineer at DanaherCambridge, United Kingdom–match not yet calculated
  • Senior Application Security Engineer, AI at KiLondon, United Kingdom–match not yet calculated
  • Senior Application Security Engineer at Hackajob LtdCambridge, United Kingdom–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United Kingdom
  • Security Analyst jobs in United Kingdom
  • Penetration Tester jobs in United Kingdom
  • Cloud Security Engineer jobs in United Kingdom
  • Security Engineer jobs in United States
  • Security Engineer jobs in India